2017-12-02 12:08:35 +08:00
|
|
|
|
# Apache httpOnly Cookie Disclosure(CVE-2012-0053)
|
2017-12-01 21:04:39 +08:00
|
|
|
|
|
|
|
|
|
## POC
|
2017-12-01 21:06:22 +08:00
|
|
|
|
* 来自[https://gist.github.com/pilate/1955a1c28324d4724b7b/7fe51f2a66c1d4a40a736540b3ad3fde02b7fb08](https://gist.github.com/pilate/1955a1c28324d4724b7b/7fe51f2a66c1d4a40a736540b3ad3fde02b7fb08)
|
|
|
|
|
* [http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0053](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0053)
|
2017-12-01 21:04:39 +08:00
|
|
|
|
|
|
|
|
|
## 利用方法
|
|
|
|
|
|
|
|
|
|
1. 打开Google,访问存在此漏洞的网站。
|
|
|
|
|
2. F12开启控制台,Console,将CVE-2017-0053.js中的代码复制出来,并且放在Console中执行。
|