-
Updated
May 11, 2022 - Python
owasp
Here are 487 public repositories matching this topic...
-
Updated
Apr 25, 2022
-
Updated
May 12, 2022 - JavaScript
-
Updated
May 14, 2022 - TypeScript
-
Updated
May 12, 2022 - PHP
Onekongpc
What and where?
Please give the broken URL. Where is the link located?
Would you like to be assigned to this issue?
Check the box if you will submit a PR to fix this issue. Please read CONTRIBUTING.md.
-KONG [ ] Assign me, please!
-
Updated
Feb 5, 2022 - Ruby
-
Updated
May 11, 2022 - HTML
-
Updated
Apr 27, 2022 - Go
-
Updated
May 14, 2022 - HTML
-
Updated
Jan 29, 2022 - Python
Description
BeanUtils is a library that is doing automatic mapping to Java object.
It can cause arm when the attack controls part of the list of properties being sets. BeanUtils does not blacklist properties like class, classloader or other objects that are likely to load arbitrary classes and possibly run code.
Code
import org.apache.commons.beanutils.BeanUtils;
public-
Updated
May 10, 2022 - HTML
-
Updated
May 5, 2022 - JavaScript
-
Updated
Apr 21, 2022 - C
-
Updated
Apr 26, 2022 - TeX
-
Updated
Dec 1, 2021
Description
$ crssandbox -d "foo=ping tests broken"
...
932150 PL1 Remote Command Execution: Direct Unix Command Execution
...
Audit Logs / Triggered Rule Numbers
[2022-03-04 10:04:23.251575] [-:error] 127.0.0.1:33906 YiHWFxV2mSN4XfIw_cXfcQAAABc [client 127.0.0.1] ModSecurity: Warning. Pattern match "(?:^|=)\\\\s*(?:{|\\\\s*\\\\(\\\\s*|\\\\w+=(?:[^\\\\s]*|\\\\$.*
-
Updated
Jul 11, 2019
-
Updated
Mar 19, 2022 - Raku
-
Updated
May 10, 2022 - PHP
-
Updated
May 6, 2022 - Go
I just finished dealing with auto-migrated issues for this article, it could definitely use some content updates:
https://github.com/OWASP/www-community/blob/master/pages/HttpOnly.md it still talks about old versions of IE and Opera.
This article includes an extensive table that needs re-working after the auto-migration as well (which I did not tackle).
Is Opera even relevant in 2020? Do
sim swapping
-
Updated
Feb 24, 2021 - Python
-
Updated
May 14, 2022 - HTML
-
Updated
Apr 23, 2022
Improve this page
Add a description, image, and links to the owasp topic page so that developers can more easily learn about it.
Add this topic to your repo
To associate your repository with the owasp topic, visit your repo's landing page and select "manage topics."
Is your feature request related to a problem?
The Traditional and Traditional Plus JSON reports treat "Other Info" as consistent between alerts which is not always the case. A new JSON report should be added which treats "Other Info" as potentially unique per alert instance.
As per the original issue a perfect way to test/experience this need is the Retire.JS passive scan alerts which i