### 简要描述: 求高rank 这是打包了-。- ### 详细说明: ``` http://bbs.jeecms.com/ ``` 发起投票都木有过滤 各种插 [<img src="https://images.seebug.org/upload/201503/22125315d4f96a636f7136b6813b1e433faa44ba.png" alt="xss1.png" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201503/22125315d4f96a636f7136b6813b1e433faa44ba.png) 超级链接和邮件都存在为过滤 [<img src="https://images.seebug.org/upload/201503/22125400556019eb88809517a626596270d85e74.png" alt="xss2.png" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201503/22125400556019eb88809517a626596270d85e74.png) 插入代码 duang!!duang!!duang!! [<img src="https://images.seebug.org/upload/201503/22125409e747f3991d40f51081250ba01601a679.png" alt="xss.png" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201503/22125409e747f3991d40f51081250ba01601a679.png) 在编辑下 又存在一个 [<img src="https://images.seebug.org/upload/201503/2212560601cb3bcc47460011dab7ca84a1a99dee.png" alt="xss3.png" width="600"...
### 简要描述: 求高rank 这是打包了-。- ### 详细说明: ``` http://bbs.jeecms.com/ ``` 发起投票都木有过滤 各种插 [<img src="https://images.seebug.org/upload/201503/22125315d4f96a636f7136b6813b1e433faa44ba.png" alt="xss1.png" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201503/22125315d4f96a636f7136b6813b1e433faa44ba.png) 超级链接和邮件都存在为过滤 [<img src="https://images.seebug.org/upload/201503/22125400556019eb88809517a626596270d85e74.png" alt="xss2.png" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201503/22125400556019eb88809517a626596270d85e74.png) 插入代码 duang!!duang!!duang!! [<img src="https://images.seebug.org/upload/201503/22125409e747f3991d40f51081250ba01601a679.png" alt="xss.png" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201503/22125409e747f3991d40f51081250ba01601a679.png) 在编辑下 又存在一个 [<img src="https://images.seebug.org/upload/201503/2212560601cb3bcc47460011dab7ca84a1a99dee.png" alt="xss3.png" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201503/2212560601cb3bcc47460011dab7ca84a1a99dee.png) 看看源代码 [<img src="https://images.seebug.org/upload/201503/22125616c57be60ce95a0922b82d03d9e7f1acd5.png" alt="xss4.png" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201503/22125616c57be60ce95a0922b82d03d9e7f1acd5.png) 就不钓COOKIE了 ### 漏洞证明: ``` http://bbs.jeecms.com/ ``` 发起投票都木有过滤 各种插 [<img src="https://images.seebug.org/upload/201503/22125315d4f96a636f7136b6813b1e433faa44ba.png" alt="xss1.png" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201503/22125315d4f96a636f7136b6813b1e433faa44ba.png) 超级链接和邮件都存在为过滤 [<img src="https://images.seebug.org/upload/201503/22125400556019eb88809517a626596270d85e74.png" alt="xss2.png" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201503/22125400556019eb88809517a626596270d85e74.png) 插入代码 duang!!duang!!duang!! [<img src="https://images.seebug.org/upload/201503/22125409e747f3991d40f51081250ba01601a679.png" alt="xss.png" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201503/22125409e747f3991d40f51081250ba01601a679.png) 在编辑下 又存在一个 [<img src="https://images.seebug.org/upload/201503/2212560601cb3bcc47460011dab7ca84a1a99dee.png" alt="xss3.png" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201503/2212560601cb3bcc47460011dab7ca84a1a99dee.png) 看看源代码 [<img src="https://images.seebug.org/upload/201503/22125616c57be60ce95a0922b82d03d9e7f1acd5.png" alt="xss4.png" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201503/22125616c57be60ce95a0922b82d03d9e7f1acd5.png) 就不钓COOKIE了