After setting up the local environment in “/admin/Admin_ log.php?pid=draft” Enter ryjqn"<script>alert(1)<script> to return all the execution results, and a prompt box will pop up,as shown in the figure https://github.com/xuechengen/emlog_6.0.0/blob/main/1.png https://github.com/xuechengen/emlog_6.0.0/blob/main/2.png https://github.com/xuechengen/emlog_6.0.0/blob/main/3.png By looking at the code, it is found that the parameter PID is not filtered https://github.com/xuechengen/emlog_6.0.0/blob/main/4.png
-
Notifications
You must be signed in to change notification settings - Fork 0
xuechengen/emlog_6.0.0
About
No description, website, or topics provided.
Resources
Stars
Watchers
Forks
Releases
No releases published
Packages 0
No packages published