
이 저장소는 CVE-2023-30212 취약점을 시뮬레이션하기 위한 Docker 컨테이너를 제공하여, 그 영향을 실습하고 이해할 수 있게 해줍니다. 자신의 컴퓨터에서 컨테이너를 설정하는 데 도움이 되는 종합 가이드가 포함되어 있습니다. Docker 생성 과정에 대한 문서도 포함되어 있습니다.
| Vendor | Product | Version |
|---|---|---|
| ourphp | ourphp | 7.2.0 |
Docker에서 OURPHP <= 7.2.0을 설치하려면 가이드 를 사용하여 실습용 Docker를 설치할 수 있습니다.
# ourphp 7.2.0 version has a vulnerability to XSS (Cross-Site Scripting).
# In the file /client/manage/ourphp_out.php, there is a direct echo functionality that, along with controllable variables, can enable attackers to execute XSS code.When the ourphp_admin parameter is set to "logout," we echo a controllable variable called "out."
# To exploit this, we prepend a script tag and close it, forming our payload.This vulnerability can be exploited through the "out" parameter by injecting the following script: "</script><script>alert(xss)</script>"
# After completing the setup of the docker directly. Access the following path :
http://localhost/client/manage/ourphp_out.php?ourphp_admin=logout&out=</script><script>alert(`xss`)</script>
# </script><script>alert(`xss`)</script>