xpshop商城管理系统储存型XSS,可盲打后台(demo演示+浏览器通杀)

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: xss ### 详细说明: [WooYun: xpshop商城管理系统储存型XSS,可盲打后台](http://www.wooyun.org/bugs/wooyun-2014-083740) 继续来~ 首先来到demo演示地址注册个账号:http://etp.xpshop.cn/ [<img src="https://images.seebug.org/upload/201503/15212228ede8870d00d09309267ae86ce0ead10b.png" alt="11.png" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201503/15212228ede8870d00d09309267ae86ce0ead10b.png) 然后随便选个东西加入购物车 [<img src="https://images.seebug.org/upload/201503/15212258f79f683106c325017b6687534fa5a3bb.png" alt="22.png" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201503/15212258f79f683106c325017b6687534fa5a3bb.png) 这里有个订单附言,我们插入XSS语句:`"/><svg onload=alert(/1/)>` [<img src="https://images.seebug.org/upload/201503/152123126a2f3ec409db04ba80d6bf060d170578.png" alt="33.png" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201503/152123126a2f3ec409db04ba80d6bf060d170578.png) 然后提交,提示提交成功 [<img...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息