
typo3 install.php XSS
$docker-compose up
Gehe zu http://[web-server-ip]:port/typo3 und ignoriere die folgende Meldung:
Directory / is not writable Path /var/www/html/typo3 exists, but no file underneath it can be created.
Gehe auf die im Container bereitgestellte typo3-Seite und führe die Installation durch. Der Host der MySQL-Datenbank ist 'db'.
Gib während der Installation in Schritt 4/5 im Feld 'Site name' den XSS-Payload ein.

Nach Abschluss der Installation und Anmeldung sieht man, wie das XSS wie unten gezeigt ausgeführt wird.

debconf: unable to initialize frontend: Readline debconf: (This frontend requires a controlling tty.) debconf: falling back to frontend: Teletype
RUN apt-get install -y debconf-utils RUN echo 'debconf debconf/frontend select Noninteractive' | debconf-set-selections RUN apt-get install -y -q [package]
Aufgrund der Eigenschaft des Apache2-Servers, der als www-data-Benutzer läuft, haben wir das typo3-Verzeichnis als www-data erstellt.
Das MySQL-Image wurde auf Version 5.8 gesetzt.
System Requirements For more information as well as installation instructions see the Installation guide. Operating System Linux, Windows or Mac, or common cloud infrastructure setups Webserver Apache httpd, Nginx, Microsoft IIS, Caddy Server Supported Browsers Chrome (latest) Edge (latest) Firefox (latest) Internet Explorer >= 11 Safari (latest) Database MariaDB >= 10.0 <= 10.3 Microsoft SQL Server MySQL >= 5.0 <= 5.7 PostgreSQL SQLite Hardware RAM >= 256 MB PHP PHP >= 7.2 <= 7.4
Wir haben dem MySQL-Container eine Command-Option hinzugefügt.
Invalid Charset Your database uses character set "latin1", but only "utf8" is supported with TYPO3. You probably want to change this before proceeding.