dopost, rpok, aidparameters.dopost=replace&rpok=1&aid='>\\/dede/co_ do.php line 156, the $aid variable in the ShowMsg() function is controllable. The $aid variable is obtained from $_GET['aid'].

/include/common.func.php line 280, the $aid variable is a $gourl variable in the ShowMsg() function.

/include/common.func.php line 326 and line 321, $gourl variables are spliced into $msg variables and output without filtering.

http://127.0.0.1/dede/co_do.php?dopost=replace&rpok=1&aid=%27%3E%3CscrIpt%3Ealert(666)%3C/script%3E
