From 8782c160eb5e697d0f2fb3f472f4eac6cf5b62be Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Cenk=20Kalpako=C4=9Flu?= <36031097+ckalpakoglu@users.noreply.github.com> Date: Thu, 12 Aug 2021 10:54:07 +0300 Subject: [PATCH 1/4] Update xss.go add new vuln --- vulnerability/xss/xss.go | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/vulnerability/xss/xss.go b/vulnerability/xss/xss.go index c77fe06d..6f4addf1 100644 --- a/vulnerability/xss/xss.go +++ b/vulnerability/xss/xss.go @@ -57,6 +57,8 @@ func xss1Handler(w http.ResponseWriter, r *http.Request, _ httprouter.Params){ }else if vulnDetails == ""{ data["value"] = template.HTML(value) data["term"] = template.HTML(notFound) //vulnerable function + }else if vulnDetails == "cenk"{ + data["value"] = template.HTML(value) }else{ vuln := fmt.Sprintf("%s",term) data["value"] = template.HTML(value) @@ -113,4 +115,4 @@ func removeScriptTag(text string)string{ filter := regexp.MustCompile(".*") output := filter.ReplaceAllString(text,"") return output -} \ No newline at end of file +} From bee6b65112c25b2f1e3f5f9abbb27b6313ae4683 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Cenk=20Kalpako=C4=9Flu?= <36031097+ckalpakoglu@users.noreply.github.com> Date: Thu, 12 Aug 2021 10:57:47 +0300 Subject: [PATCH 2/4] Update xss.go --- vulnerability/xss/xss.go | 1 + 1 file changed, 1 insertion(+) diff --git a/vulnerability/xss/xss.go b/vulnerability/xss/xss.go index 6f4addf1..44c14c6c 100644 --- a/vulnerability/xss/xss.go +++ b/vulnerability/xss/xss.go @@ -59,6 +59,7 @@ func xss1Handler(w http.ResponseWriter, r *http.Request, _ httprouter.Params){ data["term"] = template.HTML(notFound) //vulnerable function }else if vulnDetails == "cenk"{ data["value"] = template.HTML(value) + data["term"] = template.HTML(notFound) //vulnerable function }else{ vuln := fmt.Sprintf("%s",term) data["value"] = template.HTML(value) From 6dd674431b1a40b746d0506afd55df1c6a2a7ddf Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Cenk=20Kalpako=C4=9Flu?= <36031097+ckalpakoglu@users.noreply.github.com> Date: Thu, 12 Aug 2021 10:57:56 +0300 Subject: [PATCH 3/4] Create xss.go tttt From 2941c86f882a3951c3f42d8c8cab6f284f52fd66 Mon Sep 17 00:00:00 2001 From: zisanyavuz <121107976+zisanyavuz@users.noreply.github.com> Date: Mon, 20 May 2024 11:53:33 +0300 Subject: [PATCH 4/4] Create QA.js --- QA.js | 4 ++++ 1 file changed, 4 insertions(+) create mode 100644 QA.js diff --git a/QA.js b/QA.js new file mode 100644 index 00000000..36b549da --- /dev/null +++ b/QA.js @@ -0,0 +1,4 @@ +//QA file change +const QA = { + "url": "https://github.com/endpointlabs/govwa" +}