dedecms referer xss跨站

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

简要描述: dedecms 全版本!xss跨站一枚! referer构造触发! 详细说明: 文件:/plus/vote.php code 区域 $ENV_GOBACK_URL = empty($_SERVER['HTTP_REFERER']) ? '':$_SERVER['HTTP_REFERER']; ............................................ //判断是否允许被查看 $admin = new userLogin; if($dopost == 'view') { if($row['view'] == 1 && empty($admin->userName)) { ShowMsg('此投票项不允许查看结果',$ENV_GOBACK_URL); exit(); } } ......................... ShowMsg 函数 code 区域 function ShowMsg($msg, $gourl, $onlymsg=0, $limittime=0) { if(empty($GLOBALS['cfg_plus_dir'])) $GLOBALS['cfg_plus_dir'] = '..'; ..................................................... $func .= "var pgo=0; function JumpUrl(){if(pgo==0){ location='$gourl'; pgo=1; }}\r\n"; $rmsg = $func; $rmsg .= "document.write(\"<br /><div style='width:450px;padding:0px;border:1px solid #DADADA;'>"; $rmsg .= "<div style='padding:6px;font-size:12px;border-bottom:1px solid #DADADA;background:#DBEEBD url({$GLOBALS['cfg_plus_dir']}/img/wbg.gif)';'><b>DedeCMS 提示信息!</b></div>\");\r\n"; $rmsg .=...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息