Brief description:
Modify a function to get for submission.
Detailed description:
Set the blog permission to GET and submit. you can insert a link image in the blog, so that the target user can open the permission.
Proof of vulnerability:
For example, you can set the permission on the page http://control.blog.sina.com.cn/blogprofile/profilepower.php.
1. Insert in blog
Http://control.blog.sina.com.cn/riaapi/conf/update_user_private.php? Uid = *** & privatekey = cms % 2 Cpageset % 2 Cinvitationset % 2 Cspamcms % 2 Cquote % 2 Cfoot % 2 Cisprivate & privatevalue = 4% 2C0% 2C0% 2C1% 2C0% 2C0% 2C0% 2C0 image Link
2. When a user logs on, the user is tempted to click on this blog, so that the user ID is *** (the blog directory address is exposed) and the blog is open to all users.
Solution:
1. Modify get to post for submission
2. token Mechanism