当前位置: 首页 > news >正文

Novel-Plus has business logic vulnerabilities.

1.The lack of restrictions on the frequency of requests to this interface has led to the arbitrary inflation of click counts, compromising the integrity of the ranking list.
POST /book/addVisitCount HTTP/1.1
Host: 192.168.56.1:8083
Content-Length: 26
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36 Edg/144.0.0.0
Accept: /
Content-Type: application/x-www-form-urlencoded; charset=UTF-8
Origin: http://192.168.56.1:8083
Referer: http://192.168.56.1:8083/book/2019016579009839104.html
Accept-Encoding: gzip, deflate, br
Accept-Language: zh-CN,zh;q=0.9,en;q=0.8,en-GB;q=0.7,en-US;q=0.6
Cookie: tale_remember_url=http%3A%2F%2Fwww.baidu.com; tale_remember_author=xiongxy; tale_remember_mail=3335469126%40qq.com; userClientMarkKey=664c48c00fbf49fd8acba09dd62c8db0; Hm_lvt_ecc8b50a3122e6d5e09be7a9e5383e07=1769957100,1770033416; HMACCOUNT=090AF7CD6CC25A4C; JSESSIONID=3a38b0ea-96c1-475e-9d96-9fcbb1328a64; Authorization=eyJhbGciOiJIUzUxMiJ9.eyJleHAiOjE3NzA4MTI2MzUsInN1YiI6IntcImlkXCI6MjAxNzk1MTIyMzM0NDI3MTM2MCxcInVzZXJuYW1lXCI6XCIxODM1MDE5NzIyOVwiLFwibmlja05hbWVcIjpcIjE4MzUwMTk3MjI5XCJ9IiwiY3JlYXRlZCI6MTc3MDIwNzgzNTU0Mn0.H4CsvZm6Z77I8jReOmiIroWep96SFr1EFu7k--Ex5Bgu7AoLBT-vJJfOzu_aBYrRPHEqgk8zlzSqTTipe9qcTA; Hm_lpvt_ecc8b50a3122e6d5e09be7a9e5383e07=1770207836
Connection: keep-alive

bookId=2019016579009839104

image
image