网站地图    收藏   

主页 > 后端 > 网站安全 >

新浪博客字符过滤不严导致执行任意代码(导致

来源:自学PHP网    时间:2015-04-17 13:03 作者: 阅读:

[导读] 简要描述:QQ天天收到广告:女人必看http://blog.sina.com.cn/u/2439749250是新浪的博客,其中插入一段代码,新浪并没有过滤,导致可以直接跳转详细说明:我们查看网页源码!DOCTYPE html PUBLIC -//W3...

 

简要描述:QQ天天收到广告:女人必看http://blog.sina.com.cn/u/2439749250

 

是新浪的博客,其中插入一段代码,新浪并没有过滤,导致可以直接跳转

详细说明:我们查看网页源码

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

 

<html xmlns="http://www.w3.org/1999/xhtml">

 

<head>

 

<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />

 

<title>大河源人_新浪博客</title>

 

<meta name="keywords" content="大河源人_新浪博客,大河源人,杂谈" />

 

<meta name="description" content="大河源人_新浪博客,大河源人,甜美范练就魔鬼身材,完美转身变窈窕淑女" />

 

<meta http-equiv="X-UA-Compatible" content="IE=EmulateIE7" />

 

<!–[if lte IE 6]> www.2cto.com

 

<script type="text/javascript">

 

try{

 

document.execCommand("BackgroundImageCache", false, true);

 

}catch(e){}

 

</script>

 

<![endif]–>

 

<script type="text/javascript">

 

window.staticTime=new Date().getTime();

 

 

 

var locInterval = setInterval(function(){

 

var tc = document.getElementById('trayContainer');

 

if(tc) {

 

var isLogin = false;var sup = document.cookie.match(/sup=([^;]+);/gi);if(sup != null){ sup = decodeURIComponent(sup[0]);var uid = sup.match(/uid=([^&]+)/gi); isLogin = (uid != null); } if (isLogin){ tc.innerHTML = '<div class="topbar_loading"><img src=http://up.2cto.com/2011/1228/20111228010858768.gif" />加载中…</div>'; } else { tc.innerHTML = '<div class="topbar_menu"><span class="link"><a href="http://blog.sina.com.cn" target="_blank">博客首页</a></span><span class="line_s"></span></div><div class="topbar_login"><a href="#" class="login" id="linkTrayLogin" onclick="return false;">登录</a><a href="http://login.sina.com.cn/signup/signupmail.php?entry=blog&r=&srcuid=&src=blogicp" class="register" target="_blank" id="linkReg">注册</a></div><div class="topbar_ad" id="divPopularize"></div><div id="phprender" ></div>';}

 

clearInterval(locInterval);

 

locInterval = null;

 

}

 

},50);

 

 

 

</script>

 

<link rel="pingback" href="http://upload.move.blog.sina.com.cn/blog_rebuild/blog/xmlrpc.php" />

 

<link rel="EditURI" type="application/rsd+xml" title="RSD" href="http://upload.move.blog.sina.com.cn/blog_rebuild/blog/xmlrpc.php?rsd" />

 

<link href="http://blog.sina.com.cn/blog_rebuild/blog/wlwmanifest.xml" type="application/wlwmanifest+xml" rel="wlwmanifest" />

 

<link rel="alternate" type="application/rss+xml" href="http://blog.sina.com.cn/rss/2439749250.xml" title="RSS" />

 

<link href="http://simg.sinajs.cn/blog7style/css/conf/blog/index.css" type="text/css" rel="stylesheet" /><style id="tplstyle" type="text/css">@charset "utf-8";@import url("http://simg.sinajs.cn/blog7newtpl/css/30/30_1/t.css");

 

</style>

 

<style id="positionstyle"  type="text/css">

 

.sinabloghead .blogtoparea{ left:120px;top:113.95px;}

 

.sinabloghead .blognav{ left:120px;top:200.067px;}

 

</style>

 

<style id="bgtyle"  type="text/css">

 

</style>

 

<style id="headtyle"  type="text/css">

 

</style>

 

<style id="navtyle"  type="text/css">

 

</style>

 

</head>

 

<body>

 

<!--$sinatopbar-->

 

<div style="z-index:512;" class="sinatopbar">

 

                     <div class="topbar_main">

 

                            <a id="login_bar_logo_link_350" href="http://blog.sina.com.cn" target="_blank"><img class="topbar_logo" src=http://up.2cto.com/2011/1228/20111228010858244.gif" width="100" alt="新浪博客"/></a>

 

 

 

                            <div id="trayContainer" style="float:left">

 

                                                        </div>

 

                            <div class="topbar_floatR">

 

                                   <span class="tb_wrtBlog">

 

                                          <a target="_blank" href="http://control.blog.sina.com.cn/admin/article/article_add.php"><img class="SG_icon SG_icon15" src=http://up.2cto.com/2011/1228/20111228010858889.gif" width="15" height="15" title="博文" align="absmiddle"/>       发博文</a>

 

 

 

                                          <span id="arrowAddArticle" class="wrtblog_arrow"></span>

 

                                 &nbs

自学PHP网专注网站建设学习,PHP程序学习,平面设计学习,以及操作系统学习

京ICP备14009008号-1@版权所有www.zixuephp.com

网站声明:本站所有视频,教程都由网友上传,站长收集和分享给大家学习使用,如由牵扯版权问题请联系站长邮箱904561283@qq.com

添加评论