I. Agreed word explanation and description Lamu social comment box: http://www.denglu.cc/demo.html 2. Description of Lamu social comment box in the direct input script is invalid. Currently, the code that allows image insertion is supported in html mode. Therefore, you can use a variety of on to xss. Currently, you can log on to the front-end user's cookies (no experiment can be accessed from a non-same-source ip address). However, because you are not good at the front-end, therefore, cookies embedded on pages cannot be found. Iii. rating based on social login embedding multiple websites may affect the website to be embedded, and the rating is medium because it is too difficult. 1. Find any website that uses the lighting heron social comment box. 2. Enter the following code: for quick results, two or more URLs are not allowed. Otherwise, the URLs are listed in the spam comments for review. 3. The result front-end (embedded page) does not support cookies embedded on the page: open. denglu. cc Comment management background. Can I use this cookie to log on to the background? Too late to test:
Solution:
Change UBB and restrict available attributes in img