美时空分站XSS与网址跳转漏洞
Author:Insight-labs(Web Security Group)
1.XSS
2.URL Redirect
http://shop.wanmei.com/affiche.php?ad_id=34&uri=[URL]
http://wulin2.wanmei.com/arrival/a.htm?to=[URL]
http://zhuxian.wanmei.com/arrival/a.htm?to=[URL]
http://yt.wanmei.com/arrival/a.htm?to=[URL]
3.爆路径
http://event2.wanmei.com/messagewall/blessingsListAction.do?path=../
4.internal ip
;; ANSWER SECTION:
gm.wanmei.com. 313 IN A 10.15.0.82
;; ANSWER SECTION:
monitor.wanmei.com. 257 IN A 10.15.0.13

