Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Cross-site scripting exists in Finnesoft #4

Open
dabaizhizhu opened this issue Jun 1, 2024 · 0 comments
Open

Cross-site scripting exists in Finnesoft #4

dabaizhizhu opened this issue Jun 1, 2024 · 0 comments

Comments

@dabaizhizhu
Copy link
Owner

Discovered as Fanen Software,and this type of vulnerability can be used to kill all vulnerabilities, and other products can be searched on FOFA:title="泛恩(FineSoft)医药管理软件",There are thousands of influencing IPs
屏幕截图 2024-06-01 190427

The company of the vulnerability product is:Hangzhou Meisoft Information Technology Co., Ltd(杭州美软信息技术有限公司)
image

Vulnerability details:
Access the vulnerability URL:http://zjdyyy.8866.org:8089/yy/login.jsp
Enter any account and password, click Login, the page will report an error, and a controllable parameter will appear at the URL:myclient
Insert malicious code at the value of a controllable parameter:'><script>alert("crosssitescript")</script>
The page executes malicious code, which proves that cross-site scripting attacks can be implemented
image

Remediation scenarios:Strict filtering of user-controllable parameters

Discover people:dabaizhizhu

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant