/**
* Title: Discuz Small set of Xss vulnerabilities in series X
* Author: sogili @ 0 xsec
* From: 0xsec.org
* Website: 0xsec.org & sogili.com
**/
DiscuzMinor Product Version X SeriesXssVulnerability set.
InvolvedDiscuz x1.0&X1.5Version. PlusQQBookmarksXssOne.
SogiliA small result of whining.
Discuz x1.0 personal space template custom content Xss
Similar to the previous times, they are all img labels.
After logging in, go to personal space, and select "Dress up space"> "add template"> select "Free TEMPLATE 1">
However, this time it may not be as effective as the previous several times, because it is in the personal space, but one thing better than the previous ones is (support for IMG code, up to 1000 words ), in this way, we don't need to Reduce the length so much.
Discuz! X1.5 post Xss
Input when posting
[Img] javascript: alert (/sogili/) [/img]
Discuz X1.5 personal homepage storage type XSS
Go to the personal homepage
Message submission [img] javascript: alert (/sogili/) [/img]
QQ bookmarks (Xss)
Http://shuqian.qq.com/login/auth? Jump = 1 & sURL = javascript: alert (0)