### 简要描述: 该cms有xss漏洞 详见图 ### 详细说明: [<img src="https://images.seebug.org/upload/201309/231126241af821f04fd18fed8ed6a7ada801591b.jpg" alt="1.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201309/231126241af821f04fd18fed8ed6a7ada801591b.jpg) Destoon B2B网站系统 [<img src="https://images.seebug.org/upload/201309/2311270035e9d0f608fdcd050500d1400a99bfbc.jpg" alt="2.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201309/2311270035e9d0f608fdcd050500d1400a99bfbc.jpg) 申请个帐号 然后购买广告 [<img src="https://images.seebug.org/upload/201309/23112737054c7b010e90bb43d0145d69a4c4d40f.jpg" alt="3.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201309/23112737054c7b010e90bb43d0145d69a4c4d40f.jpg) 好像所有的广告都没过滤 [<img src="https://images.seebug.org/upload/201309/2311281687b6adf41bb0400d7f0507b18701a277.jpg" alt="4.jpg" width="600"...
### 简要描述: 该cms有xss漏洞 详见图 ### 详细说明: [<img src="https://images.seebug.org/upload/201309/231126241af821f04fd18fed8ed6a7ada801591b.jpg" alt="1.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201309/231126241af821f04fd18fed8ed6a7ada801591b.jpg) Destoon B2B网站系统 [<img src="https://images.seebug.org/upload/201309/2311270035e9d0f608fdcd050500d1400a99bfbc.jpg" alt="2.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201309/2311270035e9d0f608fdcd050500d1400a99bfbc.jpg) 申请个帐号 然后购买广告 [<img src="https://images.seebug.org/upload/201309/23112737054c7b010e90bb43d0145d69a4c4d40f.jpg" alt="3.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201309/23112737054c7b010e90bb43d0145d69a4c4d40f.jpg) 好像所有的广告都没过滤 [<img src="https://images.seebug.org/upload/201309/2311281687b6adf41bb0400d7f0507b18701a277.jpg" alt="4.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201309/2311281687b6adf41bb0400d7f0507b18701a277.jpg) 随便点一个 直接插xss代码 [<img src="https://images.seebug.org/upload/201309/2311285204363eb3cf899125690fe859e59d06be.jpg" alt="5.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201309/2311285204363eb3cf899125690fe859e59d06be.jpg) 本地登录后台 点刚才提交的广告 [<img src="https://images.seebug.org/upload/201309/231129450e3c46e7473433dc63109adb3b3c1f11.jpg" alt="6.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201309/231129450e3c46e7473433dc63109adb3b3c1f11.jpg) 看到没 中招了 [<img src="https://images.seebug.org/upload/201309/23112928e34a52ab8ee0cd73211b7fd6c009c736.jpg" alt="7.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201309/23112928e34a52ab8ee0cd73211b7fd6c009c736.jpg) cookies到手 [<img src="https://images.seebug.org/upload/201309/2311301723d02ffe36cb71389bec092a127e2559.jpg" alt="8.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201309/2311301723d02ffe36cb71389bec092a127e2559.jpg) 登录到后台 ### 漏洞证明: [<img src="https://images.seebug.org/upload/201309/231126241af821f04fd18fed8ed6a7ada801591b.jpg" alt="1.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201309/231126241af821f04fd18fed8ed6a7ada801591b.jpg) Destoon B2B网站系统 [<img src="https://images.seebug.org/upload/201309/2311270035e9d0f608fdcd050500d1400a99bfbc.jpg" alt="2.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201309/2311270035e9d0f608fdcd050500d1400a99bfbc.jpg) 申请个帐号 然后购买广告 [<img src="https://images.seebug.org/upload/201309/23112737054c7b010e90bb43d0145d69a4c4d40f.jpg" alt="3.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201309/23112737054c7b010e90bb43d0145d69a4c4d40f.jpg) 好像所有的广告都没过滤 [<img src="https://images.seebug.org/upload/201309/2311281687b6adf41bb0400d7f0507b18701a277.jpg" alt="4.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201309/2311281687b6adf41bb0400d7f0507b18701a277.jpg) 随便点一个 直接插xss代码 [<img src="https://images.seebug.org/upload/201309/2311285204363eb3cf899125690fe859e59d06be.jpg" alt="5.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201309/2311285204363eb3cf899125690fe859e59d06be.jpg) 本地登录后台 点刚才提交的广告 [<img src="https://images.seebug.org/upload/201309/231129450e3c46e7473433dc63109adb3b3c1f11.jpg" alt="6.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201309/231129450e3c46e7473433dc63109adb3b3c1f11.jpg) 看到没 中招了 [<img src="https://images.seebug.org/upload/201309/23112928e34a52ab8ee0cd73211b7fd6c009c736.jpg" alt="7.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201309/23112928e34a52ab8ee0cd73211b7fd6c009c736.jpg) cookies到手 [<img src="https://images.seebug.org/upload/201309/2311301723d02ffe36cb71389bec092a127e2559.jpg" alt="8.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201309/2311301723d02ffe36cb71389bec092a127e2559.jpg) 登录到后台