Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2020-35774 PoC — Twitter TwitterServer 跨站脚本漏洞

Source
Associated Vulnerability
Title:Twitter TwitterServer 跨站脚本漏洞 (CVE-2020-35774)
Description:Twitter TwitterServer是美国Twitter公司的一个基于Scala语言的用于构建Twitter服务器的软件。该软件可通过模板来构建Twitter服务器,另外可对服务器进行管理、监控。 Twitter TwitterServer 20.12.0之前版本存在跨站脚本漏洞,该漏洞源于在一些配置中,允许通过直方图端点进行XSS。
Description
twitter-server before 20.12.0 is vulnerable to cross-site scripting in some configurations. The vulnerability exists in the administration panel of twitter-server in the histograms component via server/handler/HistogramQueryHandler.scala.
File Snapshot

id: CVE-2020-35774 info: name: twitter-server Cross-Site Scripting author: pikpikcu severity: ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.