Affected Versions:
Discuz! NNT 3.6
Vulnerability description:
Discuz! In NT3.6, the user space log editing does not perform security filtering on the data submitted by the user, resulting in malicious code insertion.
Attackers can exploit this vulnerability to obtain sensitive data in cookies of normal users, shield specific page information, forge page information, initiate Denial-of-service attacks, break through different security settings on the Internet Intranet, and combine with other vulnerabilities, modify system settings, view system files, and execute system commands!
Bug experience address:
Aspx? Postid = 3770 & spaceid = 1882 "> http://nt.discuz.net/space/viewspacepost.aspx? Postid = 3770 & spaceid = 1882
Test method:
Enter the following test statement in the content box of the new log.
<Iframe src = "http://www.bkjia.com">
Security suggestions:
Wait for updates from the official website