当前位置:网站首页>携程网主站XSS漏洞
携程网主站XSS漏洞
2022-04-21 16:33:00 【Sword-heart】
漏洞详情
披露状态:
2010-08-02: 细节已通知厂商并且等待厂商处理中
2010-08-02: 厂商已经确认,细节仅向厂商公开
2010-08-12: 细节向核心白帽子及相关领域专家公开
2010-08-22: 细节向普通白帽子公开
2010-09-01: 细节向实习白帽子公开
2010-09-06: 细节向公众公开
简要描述:
主站存在XSS,非存储
详细说明:
漏洞证明:
http://www.ctrip.com/rp/uiserver2.asp?action=<script>alert(/xss/)</script>
修复方案:
版权声明:转载请注明来源 霍家二爷@乌云
版权声明
本文为[Sword-heart]所创,转载请带上原文链接,感谢
https://blog.csdn.net/jd_cx/article/details/124189959
边栏推荐
- 迭代加深搜索
- 云呐:大型医疗设备资产管理系统贵吗?医院资产管理的主要内容
- Teach you how to do orb slam3 with oak-d and ROS noetic based on LXD
- SQL -- database operation (DDL, DML, DQL) + use the command to view the storage location of the current database (database version query)
- [interview ordinary people vs Expert Series] can you talk about CAS mechanism?
- ES6 how to determine whether an array is repeated
- Haotian Xuhui signed a contract with Changyang technology to jointly build a new ecosystem of industrial Internet security
- 汇编语言程序设计:模块化程序设计 输入字符类型统计的设计与调试
- 物联网的历史演进、应用和安全要求
- Function stack frame creation and destruction (understand)
猜你喜欢

Changan dark blue's first product can be pure electricity, extended range and hydrogen electricity, with an acceleration of 5.9s
![[interview ordinary people vs Expert Series] can you talk about CAS mechanism?](/img/f3/4be96982e9199f676b685ccf39ec5a.png)
[interview ordinary people vs Expert Series] can you talk about CAS mechanism?

elmentUI下拉框实现全部功能

The conflict between Russia and Ukraine raised concerns. The five eye network security department suggested that allies strengthen infrastructure protection measures

Campus talking notes (5)

SQL -- database operation (DDL, DML, DQL) + use the command to view the storage location of the current database (database version query)

云呐:资产密集型企业固定资产管理系统的基本功能特点

SIGIR 2022 | 从Prompt的角度考量强化学习推荐系统

Jianmu continuous integration platform v2 3.0 release

建木持续集成平台v2.3.0发布
随机推荐
What is the future development trend of mobile processor
云呐:大型医疗设备资产管理系统贵吗?医院资产管理的主要内容
Buuctf's [actf2020 freshman competition] BackupFile
关于下一代安全防护的讨论
【2023校招刷題】華為性格測評(綜合測評)戰略指南
打卡:4.21 C语言篇 -(1)初识C语言 - (11)关键字register,#define定义的宏
下载Chrome插件安装到浏览器
【面试普通人VS高手系列】能谈一下CAS机制吗?
elmentUI下拉框实现全部功能
建木持续集成平台v2.3.0发布
确定还不来看看?这样管理你的代码库既方便又省心
SIGIR 2022 | reinforcement learning recommendation system from the perspective of prompt
程序设计天梯赛L2-007 家庭房产(太逆天了,做题老看题解导致忘了这题并查集怎么写了,直接建图dfs做的,麻烦的一)
Soda problem
What are the mainstream mobile phone SOC chips at present?
目前主流的手机屏幕类型都有哪些
OJ daily practice - Bonus
求字符串最长子串
程序设计天梯赛L3-28 森森旅游(想到multiset就算成功)
Which exchange is rapeseed meal futures listed on? How is it safest for a novice to open a futures account?