如何使用XSpear完成XSS扫描与参数分析

来源:岁月联盟 编辑:猪蛋儿 时间:2020-01-29
    | 2  | INFO  | STATIC ANALYSIS  | GET    | -     |                        | Content-Type: text/html                       |
    | 3  | LOW   | STATIC ANALYSIS  | GET    | -     |                        | Not Set X-Frame-Options                       |
    | 4  | MIDUM | STATIC ANALYSIS  | GET    | -     |                        | Not Set CSP                                   |
    | 5  | INFO  | DYNAMIC ANALYSIS | GET    | cat   | XsPeaR"                                | Found SQL Error Pattern                       |
    | 6  | INFO  | REFLECTED        | GET    | cat   | rEfe6                                  | reflected parameter                           |
    | 7  | INFO  | FILERD RULE      | GET    | cat   | onhwul=64                              | not filtered event handler on{any} pattern    |
    | 8  | HIGH  | XSS              | GET    | cat   | alert(45)             | reflected XSS Code                            |
    | 9  | HIGH  | XSS              | GET    | cat   |             | reflected HTML5 XSS Code                      |
    | 10 | HIGH  | XSS              | GET    | cat   |     | reflected HTML5 XSS Code                      |
    | 11 | HIGH  | XSS              | GET    | cat   |    | reflected onfocus XSS Code                    |

上一页  [1] [2] [3] [4] [5] [6] [7] [8] [9] [10]  下一页