Mallbuilder (multi-user mall) Storage XSS refers to where to pack (5)
First came to the demo address: http://cn.mall-builder.com/main.php
This demo address has stopped Registration
It should be the reason for this hole = haha
WooYun: Mallbuilder (multi-user mall) storage type XSS blind playing background, with a detailed explanation
But fortunately, I have enough mechanisms. If I have a registered account, I will continue to test it with my previous account.
Use the previous account
XSS exists in the seller center. First, go to the seller center and set a store.
Click in the shop settings and there is a slide. Fill in the URL and insert all: "/> <svg onload = alert (/1/)>
Prompt operation successful
Five rows are displayed after the return result is returned ~
To prove that not self-xss, we can use other accounts to view, first find the shop address: http://cn.mall-builder.com/shop.php? Uid = 965. There is no logon here. You can see a successful pop-up window. The same is true for Logon. Kill it ~
Solution:
Filter parameters