Vulnerability Author: phantom spring [B .S.N]
Source code downloadHttp://www.dvbbs.net/products.asp
Official WebsiteHttp://www.dvbbs.net
Vulnerability level: high
Vulnerability description:
If you register on the internet, you will be given a default homepage, which is similar to Baidu's blog.
There is a custom setting on the personal homepage, and there is a style template setting.
Similar to Baidu's blog, so his vulnerability is similar to Baidu. If you know about the xss vulnerability in Baidu before, you will also know about the current mobile network vulnerability.
The vulnerability occurs in css. A Cross-Site vulnerability exists because the mobile network allows users to edit css styles by themselves without filtering.
Enter the following code:
Xss: expression (alert (hacked by hacker line ));
Information Source: Hacker defenseHttp://www.hacker.com.cn;) 09.03.10
If you are interested in Cross-Site worms, or you can teach me how to write them. I am stuck in the worms, which is depressing.
I hope you can give me some advice and appreciate it. You can add my qq: 271174530 or reply.