d***@qq.com
d***@qq.com
  • 发布:2024-04-28 15:52
  • 更新:2024-04-29 17:03
  • 阅读:59

三级等保 IOS IPA包测评出现 InnerHTML的XSS攻击漏洞

分类:uni-app

[文件]:
/PandoraApi.bundle/pulltorefresh.js
[代码]:
!function(){var a,b,c,d,e,f,g,h,i,j=TouchEvent.prototype.preventDefault,k=!1;TouchEvent.prototype.preventDefault=function(a){"string"!=typeof a&&(k=!0),j.call(this)},window.addEventListener("touchstart",function(){k=!1},!0),a='<div style="position: fixed;top: 0;left: 0;height:0px;line-height:0;width: 100%;overflow:hidden;text-align: center;z-index: 2147483647"><div style="margin: 3px auto;margin-bottom:10px;width:{WIDTH};height:{WIDTH};background-color: rgb(255, 255, 255);border-radius: 50%;box-shadow: rgb(187, 187, 187) 0px {SHADOWOFFSETY}px {SHADOWBLUR}px;"><canvas width="200" height="200" style="width:{WIDTH}"></canvas></div></div>',"function"!=typeof Object.assign&&(Object.assign=function(a){"use strict";var b,c,d,e;if(null==a)throw new TypeError("Cannot convert undefin...

[文件]:
/PandoraApi.bundle/all.js
[代码]:
var plusType;function adsfsdaf99dsafsd090dsfsd(){var t,n=["log","logLevel","unshift","slice","ERROR","toString","addEventListener","message","warn","error","INFO","plusready","assert","LOG","Timer [","valueOf","join","bridge","console","message","apply","clear","stringify","time","timeEnd","length","format","tools","concat","exec","error JSON.stringify()ing argument: ","WARN","call","prototype","plus","push","shift","level","info"];t=n,function(e){for(;--e;)t.push(t.shift())}(448);function l(e,t){return n[e=+e]}!function(e){var u=l;window[u("0x10")][u("0x9")];function...

通过 HBuilderX 打包生成的 ipa 文件,请问一下这两个文件是哪里的,碰到这个问题咋解决?

2024-04-28 15:52 负责人:DCloud_App_Array 分享
已邀请:
d***@qq.com

d***@qq.com (作者)

uniapp 开发就是一个坑啊

要回复问题请先登录注册