Skip to content

X-Forward-For导致的XSS漏洞 #6

@m4ra7h0n

Description

@m4ra7h0n

请求头添加了一个
X-Forwarded-For: 127.<img src=1 onerror=alert(123)>0.0.2

image
image

修复建议:禁用多级代理

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions