As I am a loyal user of China Unicom, I saw you dig xss before, and I went to China Unicom's mailbox to check it. After a rough look, I found that the calendar management agenda can be xss, however, I can only use the xss myself. I gave up my leave and watched it in csrf in the last two days. So I went back and checked it again. Now this xss took effect on myself. test email content , you can test the connection to open the email to see the image. csrf2. so you can find a get connection and add the whitelist connection antiTrash. action? ActionType = addBWwithQuery & type = 1 & emails = 1341413415% 40qq.com
Click Open email to add the whitelist. 3. if you want to use csrf to add a calendar, haha, if the mailbox owner clicks schedule management, which cookie is not sent, the xss sends csrf emails, and the email calendar is automatically added. check whether the cookie is received. csrf can be used in many other places. This mailbox is made in Java. I think many methods are get and post. If this is the case, add 6. this is the most tragic time for me. I can get xss directly. I don't want to understand it. I didn't even filter it. I thought it would usually be filtered here, which surprised me so much.
Oh, my mom, my little heart. After digging for half a day, I can use xss. I want to die.