You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository has been archived by the owner on Sep 5, 2018. It is now read-only.
The text was updated successfully, but these errors were encountered:
adon-at-work
changed the title
Vulnerability could exists if attributeValue partially contributes to a dangerous protocol. for example: java{{url}}
Vulnerability could exists if attributeValue partially contributes to a dangerous protocol
Apr 10, 2015
it is an interesting pattern that in theory can bypass any blacklist / whitelist filters. however, if we consider the attribute value context as the whole and trigger the URI parser to parse the string, then we can detect this issue.
For example: java{{url}}
The text was updated successfully, but these errors were encountered: