Sourcecodester Toll Tax Management System 1.0 的 manage_recipient.php 中存在一个跨站脚本(XSS)漏洞,允许远程认证用户通过“owner”输入字段注入任意 Web 脚本。
跨站脚本(XSS)
Sourcecodester
https://www.sourcecodester.com/php/15304/toll-tax-management-system-phpoop-free-source-code.html - 1.0
sourcecodester Toll Tax Management System 1.0 中的跨站脚本(XSS)漏洞允许远程攻击者通过 manage_recipient 页面上的 owner 输入字段执行任意代码
"<svg onload=alert(document.cookie)>",填写其余表单详情,然后单击“保存”按钮。https://www.sourcecodester.com/ https://www.sourcecodester.com/php/15304/toll-tax-management-system-phpoop-free-source-code.html https://owasp.org/www-community/attacks/xss/