收藏
回答

该网页可能存在被他人恶意利用生成违规内容的情况如xss注入文件上传漏洞?

请问该网页可能存在被他人恶意利用生成违规内容的情况(如xss注入、文件上传漏洞等),是什么内容违规?

链接:http://wp.yivibao.com/pages/payCopy3/payCopy3?order=202305121821160267724&qrCode=https%3A%2F%2Fqr.alipay.com%2Fbax04408c98a8hboet2f55e9&link=%3Cform%20id%3D%27alipaysubmit%27%20name%3D%27alipaysubmit%27%20action%3D%27https%3A%2F%2Fopenapi.alipay.com%2Fgateway.do%3Fcharset%3DUTF-8%27%20method%3D%27POST%27%3E%3Cinput%20type%3D%27hidden%27%20name%3D%27method%27%20value%3D%27alipay.trade.wap.pay%27%2F%3E%3Cinput%20type%3D%27hidden%27%20name%3D%27app_id%27%20value%3D%272021002117618663%27%2F%3E%3Cinput%20type%3D%27hidden%27%20name%3D%27timestamp%27%20value%3D%272023-05-12%2018%3A21%3A17%27%2F%3E%3Cinput%20type%3D%27hidden%27%20name%3D%27format%27%20value%3D%27json%27%2F%3E%3Cinput%20type%3D%27hidden%27%20name%3D%27version%27%20value%3D%271.0%27%2F%3E%3Cinput%20type%3D%27hidden%27%20name%3D%27alipay_sdk%27%20value%3D%27alipay-easysdk-php-2.0.0%27%2F%3E%3Cinput%20type%3D%27hidden%27%20name%3D%27charset%27%20value%3D%27UTF-8%27%2F%3E%3Cinput%20type%3D%27hidden%27%20name%3D%27sign_type%27%20value%3D%27RSA2%27%2F%3E%3Cinput%20type%3D%27hidden%27%20name%3D%27app_cert_sn%27%20value%3D%275edf5b68e21bf8482d213f90a317d66b%27%2F%3E%3Cinput%20type%3D%27hidden%27%20name%3D%27alipay_root_cert_sn%27%20value%3D%27687b59193f3f462dd5336e5abf83c5d8_02941eef3187dddf3d3b83462e1dfcf6%27%2F%3E%3Cinput%20type%3D%27hidden%27%20name%3D%27biz_content%27%20value%3D%27%7B%22subject%22%3A%22%E8%AE%A2%E5%8D%95%E5%8F%B7%3A202305121821160267724%E5%A6%82%E6%9E%9C%E6%82%A8%E4%B8%8D%E6%98%AF%E9%80%9A%E8%BF%87%E7%BD%91%E7%AB%99%E6%94%AF%E4%BB%98%EF%BC%8C%E6%82%A8%E6%9C%89%E5%8F%AF%E8%83%BD%E8%A2%AB%E9%AA%97%EF%BC%8C%E8%AF%B7%E5%8A%A0%E5%AE%A2%E6%9C%8DQQ%3A303646020%22,%22out_trade_no%22%3A%22202305121821160267724%22,%22total_amount%22%3A%2241.00%22,%22quit_url%22%3A%22http%3A%5C%2F%5C%2Fwp.yivibao.com%5C%2Fpages%5C%2FpayCopy3%5C%2FpayCopy3%3FbackPay%3D1%22,%22product_code%22%3A%22QUICK_WAP_WAY%22,%22timeout_express%22%3A%2230m%22%7D%27%2F%3E%3Cinput%20type%3D%27hidden%27%20name%3D%27return_url%27%20value%3D%27http%3A%2F%2Fwp.yivibao.com%2Fpages%2ForderDetail%2ForderDetail%3Forder%3D202305121821160267724%27%2F%3E%3Cinput%20type%3D%27hidden%27%20name%3D%27notify_url%27%20value%3D%27http%3A%2F%2Fapi.quanyi365.com%2Fapi%2Fnotify%2Fali-notify%27%2F%3E%3Cinput%20type%3D%27hidden%27%20name%3D%27sign%27%20value%3D%27Fnac%2BXIF9AZyfw%2FKjWRjCu0%2B0cnFLIkwml2NYRZ%2BqmiQ%2BJf7xG0Ph4r6TDQI%2FqTAiC%2FNeNzDZVD8RrmtpmM90DQjAGple5PI3s3PngxVsdv7Y04o2TGIAlamcNyGtMQpa025ZYodNN2s3GHu4RsDq8DVqUBFuRYOkyFP7tZz8jlBh538n7IvWVtL8pxVCv%2BgIhrHpGvE2RzYOZaRTXxNbvWTzFiWikIcrth5Utke%2BTRJ2BiUfdoUnVRBGg4dDrxhnJ%2FfNpvGnWTFpYZ3AjdgP4%2FxS%2B4jeQjdTEaFokx29eMyrFaboHdL8w%2F6Dot32qkih49FOseDfPlHU6%2FVmdjQLw%3D%3D%27%2F%3E%3Cinput%20type%3D%27submit%27%20value%3D%27ok%27%20style%3D%27display%3Anone%3B%27%27%3E%3C%2Fform%3E%3Cscript%3Edocument.forms%5B%27alipaysubmit%27%5D.submit%28%29%3B%3C%2Fscript%3E



该页面是一个校验用户订单支付状态的页面,没有xss注入,文件上传漏洞,请告知是具体哪里违规,该如何解决违规。


回答关注问题邀请回答
收藏

1 个回答

  • CRMEB
    CRMEB
    2023-05-13

    请个更专业的人给你检查下代码

    2023-05-13
    有用
    回复
登录 后发表内容