DESTOON 20140625版本站内信XSS

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: 只测试了ie6,弹了个框框。 ### 详细说明: ``` function dsafe($string) { if(is_array($string)) { return array_map('dsafe', $string); } else { $string = preg_replace("/\<\!\-\-([\s\S]*?)\-\-\>/", "", $string); $string = preg_replace("/\/\*([\s\S]*?)\*\//", "", $string); $string = preg_replace("/&#([a-z0-9]+)([;]*)/i", "", $string); if(preg_match("/&#([a-z0-9]+)([;]*)/i", $string)) return nl2br(strip_tags($string)); $match = array("/s[\s]*c[\s]*r[\s]*i[\s]*p[\s]*t/i","/d[\s]*a[\s]*t[\s]*a/i","/b[\s]*a[\s]*s[\s]*e/i","/e[\\\]*x[\\\]*p[\\\]*r[\\\]*e[\\\]*s[\\\]*s[\\\]*i[\\\]*o[\\\]*n/i","/on([a-z]{2,})([\(|\=|\s]+)/i","/about/i","/frame/i","/link/i","/import/i","/meta/i","/textarea/i","/eval/i","/alert/i","/confirm/i","/prompt/i","/cookie/i","/document/i","/newline/i","/colon/i","/\\\x/i"); $replace =...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息