网站地图    收藏   

主页 > 后端 > 网站安全 >

BlogPHP v2持久XSS缺陷及修复 - 网站安全 - 自学php

来源:自学PHP网    时间:2015-04-17 14:47 作者: 阅读:

[导读] # Exploit Title: BlogPHP v2 - XSS# Author: Paul Maaouchy( Paulzz )# Software Link: http://sourceforge.net/projects/blogphpscript/files/blogphpscript/2.0/BlogPHPv2.zip/download# Vers......

# Exploit Title: BlogPHP v2 - XSS
# Author: Paul Maaouchy( Paulzz )
# Software Link: http://sourceforge.net/projects/blogphpscript/files/blogphpscript/2.0/BlogPHPv2.zip/download
# Version: v2

How to exploit:
1- Go there : http://www.2cto.com /blogphp/register.html.
2- Put in the Username field the XSS Code.  Example:<META http-equiv="refresh" content="0;URL=http://www.2cto.com">  .
3- Put anything in the other field ( Password & E-mail).
4- Now anyone go there : http://www.2cto.com /blogphp/members.html will redirected to google.com OR exploit your XSS Code.
 
Paul Maaouchy ( Paulzz )

自学PHP网专注网站建设学习,PHP程序学习,平面设计学习,以及操作系统学习

京ICP备14009008号-1@版权所有www.zixuephp.com

网站声明:本站所有视频,教程都由网友上传,站长收集和分享给大家学习使用,如由牵扯版权问题请联系站长邮箱904561283@qq.com

添加评论