Baidu news url Processing bug, which can cause xss Or url jump Vulnerability

Source: Internet
Author: User

Author: nuclear attack
When browsing news yesterday, Baidu news found the following defects:

Normal page:

Http://news.baidu.com/n? Cmd = 2 & am... m & cls = civilnews



Bug page ("% 23" is submitted after the url (in hexadecimal format ):

Http://news.baidu.com/n? Cmd = 2 & am... 3 & cls = civilnews

Effect: A dual-frame page is generated. The previous one is normal and the last one is removed.



Error Page ("% 22" after url is submitted, that is, "of Url encoding (hexadecimal ):

Http://news.baidu.com/n? Cmd = 2 & am... 2 & cls = civilnews

Result: A dual-frame page is generated. The previous one is normal, and the last one directly reports the "[an error occurred while processing this directive]" error (an error occurred when processing this command ).



Other exploitation methods:

In its "forward to friends" --> "forward to space", Baidu directly reprinted the wrong url without verification after the artificially modified url.

For example:Http://apps.hi.baidu.com/share? ... T & cls = civilnews



Due to time, I found these. We have not yet continued to dig deep. We can dig out vulnerabilities such as xss or url redirection.

Note: "#" is used to pass values in the url and jump to the tag, without affecting the normal page.

This article is from: html "target = _ blank>Http://lcx.cc /? Foxnews0000358.htmlPseudo-original reprinted chicken ~

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.