Brief description: XSS filtering is not strict and there are problems with the design. By the way, we will celebrate the re-opening of wooyun and congratulate you in advance for a pleasant spring festival!
Details: multiple,
Proof of vulnerability: storage-oriented structure:
First condition: the img tag in the CKEDITOR editor is not filtered. Writing directly is not acceptable, but javascript can be used for filling and writing!
The second condition: Use the xss of the third "Music Publishing" item to complete the operation and execute any js automatically (the automation is good !)
Third condition: for compatibility issues in IE6, click "Text Publishing" and then "Music Publishing" to make the two appear at the same layer (to reduce the construction difficulty !)
Then run the following command in "Music Publishing:
<Script> window. CKEDITOR. instances. editor. insertHtml ("
Fill the script in the CKEDITOR editing box to complete the variation to the storage type (the word "mutates", as if a high endpoint )!
Solution:
Design problems! Poor compatibility! Ajax abuse! Increase experience and sacrifice security! Happy spring festival!
Author: shine @ wooyun