menu arrow_back 湛蓝安全空间 |狂野湛蓝,暴躁每天 chevron_right ... chevron_right CatfishCMS 4.6.15 前台xss chevron_right CatfishCMS 4.6.15 前台xss.md
  • home 首页
  • brightness_4 暗黑模式
  • cloud
    xLIYhHS7e34ez7Ma
    cloud
    湛蓝安全
    code
    Github
    CatfishCMS 4.6.15 前台xss.md
    815 B / 2021-07-15 19:49:11
        CatfishCMS 4.6.15 前台xss
    =========================
    
    一、漏洞简介
    ------------
    
    二、漏洞影响
    ------------
    
    CatfishCMS 4.6
    
    三、复现过程
    ------------
    
    ### 代码分析
    
    url:
    
        http://0-sec.org/cms/CatfishCMS-4.6.12/index.php/index/Index/pinglun
    
    文件:application/index/controller/Index.php
    
    方法:pinglun(
    
    ![](./resource/CatfishCMS4.6.15前台xss/media/rId25.png)
    
    文件:application\\index\\controller\\Common.php
    
    过滤函数:filterJs()
    
    ![](./resource/CatfishCMS4.6.15前台xss/media/rId26.png)
    
    ### 漏洞复现
    
    首先注册一个用户
    
    ![](./resource/CatfishCMS4.6.15前台xss/media/rId28.png)
    
    ![](./resource/CatfishCMS4.6.15前台xss/media/rId29.png)
    
    ![](./resource/CatfishCMS4.6.15前台xss/media/rId30.png)
    
    ![](./resource/CatfishCMS4.6.15前台xss/media/rId31.png)
    
    
    links
    file_download