在 Vehicle Service Management System 1.0 中,攻击者可以窃取 Cookie,从而导致完全账户接管。
<!DOCTYPE html>
<html>
<title>Cookie Stealing</title>
<body>
</body>
</html>
<!DOCTYPE html>
<html>
<title>Cookie Stealing</title>
<body>
</body>
</html>
<!DOCTYPE html>
<html>
<title>Cookie Stealing</title>
<body>
</body>
</html>
<!DOCTYPE html>
<html>
<title>Cookie Stealing</title>
<body>
</body>
</html>
攻击者上传恶意 HTML 文件,该文件重定向到第三方网站,Cookie 在请求中暴露。这导致完全账户接管。
建议验证文件上传功能,并在会话中执行二次检查。