The buyer and seller can cancel any user order and execute it in batches.

Source: Internet
Author: User

I have mentioned this kind of questions many times, but it is still quite influential. register two accounts, place two orders, place orders for user a, place orders for user B, and then cancel orders for order 2, when an http request is intercepted and the post data is changed to the key Order Number of Order 1, the last five digits are used. You just need to change the data and find a rule again. You don't have time to traverse the numbers, use a tool similar to burp to parameterize the order number and run it directly. OK. The danger is that the result has been canceled. Submit the request and check the order status.
Solution:Malicious script execution is still very harmful. Permission control is very important. Determine whether the current user has the permission and pass another parameter.

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.