Denglu social comment box xss

Source: Internet
Author: User

I. Agreed word explanation and description Lamu social comment box: http://www.denglu.cc/demo.html 2. Description of Lamu social comment box in the direct input script is invalid. Currently, the code that allows image insertion is supported in html mode. Therefore, you can use a variety of on to xss. Currently, you can log on to the front-end user's cookies (no experiment can be accessed from a non-same-source ip address). However, because you are not good at the front-end, therefore, cookies embedded on pages cannot be found. Iii. rating based on social login embedding multiple websites may affect the website to be embedded, and the rating is medium because it is too difficult. 1. Find any website that uses the lighting heron social comment box. 2. Enter the following code: for quick results, two or more URLs are not allowed. Otherwise, the URLs are listed in the spam comments for review. 3. The result front-end (embedded page) does not support cookies embedded on the page: open. denglu. cc Comment management background. Can I use this cookie to log on to the background? Too late to test:
 Solution:


Change UBB and restrict available attributes in img

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.