From 8782c160eb5e697d0f2fb3f472f4eac6cf5b62be Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?Cenk=20Kalpako=C4=9Flu?=
<36031097+ckalpakoglu@users.noreply.github.com>
Date: Thu, 12 Aug 2021 10:54:07 +0300
Subject: [PATCH 1/4] Update xss.go
add new vuln
---
vulnerability/xss/xss.go | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/vulnerability/xss/xss.go b/vulnerability/xss/xss.go
index c77fe06d..6f4addf1 100644
--- a/vulnerability/xss/xss.go
+++ b/vulnerability/xss/xss.go
@@ -57,6 +57,8 @@ func xss1Handler(w http.ResponseWriter, r *http.Request, _ httprouter.Params){
}else if vulnDetails == ""{
data["value"] = template.HTML(value)
data["term"] = template.HTML(notFound) //vulnerable function
+ }else if vulnDetails == "cenk"{
+ data["value"] = template.HTML(value)
}else{
vuln := fmt.Sprintf("%s",term)
data["value"] = template.HTML(value)
@@ -113,4 +115,4 @@ func removeScriptTag(text string)string{
filter := regexp.MustCompile("")
output := filter.ReplaceAllString(text,"")
return output
-}
\ No newline at end of file
+}
From bee6b65112c25b2f1e3f5f9abbb27b6313ae4683 Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?Cenk=20Kalpako=C4=9Flu?=
<36031097+ckalpakoglu@users.noreply.github.com>
Date: Thu, 12 Aug 2021 10:57:47 +0300
Subject: [PATCH 2/4] Update xss.go
---
vulnerability/xss/xss.go | 1 +
1 file changed, 1 insertion(+)
diff --git a/vulnerability/xss/xss.go b/vulnerability/xss/xss.go
index 6f4addf1..44c14c6c 100644
--- a/vulnerability/xss/xss.go
+++ b/vulnerability/xss/xss.go
@@ -59,6 +59,7 @@ func xss1Handler(w http.ResponseWriter, r *http.Request, _ httprouter.Params){
data["term"] = template.HTML(notFound) //vulnerable function
}else if vulnDetails == "cenk"{
data["value"] = template.HTML(value)
+ data["term"] = template.HTML(notFound) //vulnerable function
}else{
vuln := fmt.Sprintf("%s",term)
data["value"] = template.HTML(value)
From 6dd674431b1a40b746d0506afd55df1c6a2a7ddf Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?Cenk=20Kalpako=C4=9Flu?=
<36031097+ckalpakoglu@users.noreply.github.com>
Date: Thu, 12 Aug 2021 10:57:56 +0300
Subject: [PATCH 3/4] Create xss.go
tttt
From 2941c86f882a3951c3f42d8c8cab6f284f52fd66 Mon Sep 17 00:00:00 2001
From: zisanyavuz <121107976+zisanyavuz@users.noreply.github.com>
Date: Mon, 20 May 2024 11:53:33 +0300
Subject: [PATCH 4/4] Create QA.js
---
QA.js | 4 ++++
1 file changed, 4 insertions(+)
create mode 100644 QA.js
diff --git a/QA.js b/QA.js
new file mode 100644
index 00000000..36b549da
--- /dev/null
+++ b/QA.js
@@ -0,0 +1,4 @@
+//QA file change
+const QA = {
+ "url": "https://github.com/endpointlabs/govwa"
+}