# Title: BingSNS Social Interaction Platform 2.3 Vulnerability
Team: 90sec Author: network www.2cto.com
{
Var uploadurl = '.../../upload_photo.asp? Nid = ', ext =' image file (*. jpg ;*. jpeg ;*. gif ;*. png) ', size = '1 mb', count = 100, useget = 0, params = {} // Default Value
Uploadurl = getQuery ('uploadurl') | uploadurl; ext = getQuery ('text') | ext; size = getQuery ('SIZE') | size; count = getQuery ('Count') | count; useget = getQuery ('useget') | useget;
Var tmpParams = getQuery ('params ');
If (tmpParams)
{
Try {eval ("tmpParams =" + tmpParams);} catch (ex ){};
Params = $. extend ({}, params, tmpParams );
}
Click this filter.
Test method: http:// I .bingsns.com/Editor/xheditor_plugins/multiupload/multiupload_photo.asp? Ext = image file (*.*)
Http:// I .bingsns.com/Editor/xheditor_plugins/multiupload/multiupload_photo.asp? Ext = image file (*. asp; *. jpeg; *. gif; *. png)
Source code: http://www.cnzz.cc/code/11266.html
Www.2cto.com fix: Filter