Baidu record store-type XSS (no exception for anyone who hits it)

Source: Internet
Author: User

Baidu record store-type XSS (no exception for anyone who hits it)

This storage-type XSS appears on the bar service blocking reason (so the premise is that you must have the bar master or have the seal permission)


Below I will demonstrate it with my own post and Baidu account



First, log on to our account (master or master)



Let's just enter a post (Here we write our own post)


 





After seeing a block, click and write our test code on the block reason.


 

"/> <Script> alert (/wooyun test/) </script>




 




 




 





At this time, a notification will be displayed in my notification. After we click it, our test statement will pop up at the click of the main notification.


 

 


The cookie that XSS calls.


 

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.