78778443 / QingScan

一个漏洞扫描器粘合剂,添加目标后30款工具自动调用;支持 web扫描、系统扫描、子域名收集、目录扫描、主机扫描、主机发现、组件识别、URL爬虫、XRAY扫描、AWVS自动扫描、POC批量验证,SSH批量测试、vulmap。
1.76k stars 288 forks source link

Search function Cross Site Script(XSS) Vulnerability #17

Open we1x4n opened 2 years ago

we1x4n commented 2 years ago

XSS Payload

a" onclick =alert(1) "

There is an xss vulnerability in all search functions. Since there are many locations, only three locations are provided to prove the existence of the vulnerability

URL:菜单管理 image URL:python依赖库 image URL:hydra列表 image