XSS risks exist after a substation on the 19th floor does not strictly filter js Reconstruction

Source: Internet
Author: User

 

Brief description: filtering is not strict. Although XSS is not directly caused, re-constructing the js region may cause XSS!

For more information, see test on Jiaxing station! Other sub-stations did not look at it. When posting in the 'talking short' post, there will be a 'description' input box after the attachment is uploaded. This output is not strictly filtered. After the input </script> forces the js domain to end, as a result, it cannot be edited again.

 

 

 

 

 

Proof of vulnerability:

 

 

 

 

 

 

 

Although it will not run on the page. However, malicious code is displayed normally in the js running domain.

 


 

 

 

 

We first shield the js Code behind it, and then fill in the code in the 'code-filling region' to change the original program structure and run properly, this may lead to xss (if you are interested, you can test the CAPTCHA complement Construction by yourself)

 

 

Oh! There is another small problem. The java exception is not good,

 

 

 

Author shine @ wooyun

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.