金蝶商城xss盲打

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: xss盲打 ### 详细说明: 地址:http://mall.kingdee.com/cart.action 1.三处小的xss (鸡肋) [<img src="https://images.seebug.org/upload/201501/3118190033eacb43407a6a5e1cf489075763c43c.jpg" alt="<img/src=1 onerror=alert(/test/)>.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201501/3118190033eacb43407a6a5e1cf489075763c43c.jpg) [<img src="https://images.seebug.org/upload/201501/311819205f3ca2cf240f9e36a0d2dd637ec7eeb1.jpg" alt="工作信息xss.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201501/311819205f3ca2cf240f9e36a0d2dd637ec7eeb1.jpg) [<img src="https://images.seebug.org/upload/201501/31181935ce8d33d0db9c4f21bb7eb7a74c2b3d4b.jpg" alt="教育信息xss.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201501/31181935ce8d33d0db9c4f21bb7eb7a74c2b3d4b.jpg) 2.一处反射型的xss, 位于商城主页的搜索处(鸡肋) ``` http://mall.kingdee.com/search.action?k=%3Cscript%3Ealert%282%29%3B%3C%2Fscript%3E ``` [<img...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息