From 00f10f851392ca20964d6916e5f68e0e379bd383 Mon Sep 17 00:00:00 2001 From: Dominique RIGHETTO Date: Sat, 18 Jul 2020 18:00:24 +0200 Subject: [PATCH] Add character that can break a MongoDB query when JS expression is used --- Fuzzing/Databases/NoSQL.txt | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/Fuzzing/Databases/NoSQL.txt b/Fuzzing/Databases/NoSQL.txt index 83ce0d92..4ab698a4 100644 --- a/Fuzzing/Databases/NoSQL.txt +++ b/Fuzzing/Databases/NoSQL.txt @@ -18,3 +18,12 @@ db.injection.insert({success:1});return 1;db.stores.mapReduce(function() { { emi ';sleep(5000); ';it=new%20Date();do{pt=new%20Date();}while(pt-it<5000); {$nin: [""]}} +' +" +\ +/ +// +; +{ +} +: