-
Updated
Aug 31, 2020 - Python
appsec
Here are 115 public repositories matching this topic...
-
Updated
Aug 31, 2020 - Python
-
Updated
Aug 31, 2020 - JavaScript
-
Updated
Aug 5, 2020 - Python
-
Updated
Aug 28, 2020 - Ruby
-
Updated
Jul 19, 2020 - Shell
Merge /Testing_for_Vertical_Bypassing_Authorization_Schema_WSTG-AUTHZ-00X.md into 4-Web_Application_Security_Testing/05-Authorization_Testing/03-Testing_for_Privilege_Escalation.md
-
Updated
Jun 11, 2019
-
Updated
Jul 28, 2020 - HTML
Authentication via Azure/aad-pod-identity for keyvault access could be a good feature to avoid use of clientId/ clientSecret in chart values. Don't you think ?
-
Updated
Aug 31, 2020 - Java
-
Updated
Aug 24, 2020
-
Updated
Oct 16, 2019 - Go
-
Updated
Aug 1, 2020 - HTML
I've found a way to bypass certain filters which implement the following behaviour: The filter checks everything between opening and closing or opening and opening brackets. A whitelist is checked against the HTML tag as well as every attribute found within the brackets. Whenever an attribute is not whitelisted the filter will block the input. Closing tags are detected as soon as a slash is found
sim swapping
-
Updated
Aug 7, 2020
-
Updated
Jul 23, 2020 - Dockerfile
-
Updated
Jul 27, 2020 - Python
-
Updated
Jul 3, 2020 - Scala
-
Updated
Jan 9, 2020
-
Updated
Jun 11, 2019 - PHP
-
Updated
Jan 7, 2020 - HTML
-
Updated
Mar 24, 2019 - Python
-
Updated
Aug 8, 2020 - Java
-
Updated
Jun 5, 2020 - Python
-
Updated
Aug 14, 2020 - JavaScript
-
Updated
Aug 14, 2020 - Python
Improve this page
Add a description, image, and links to the appsec topic page so that developers can more easily learn about it.
Add this topic to your repo
To associate your repository with the appsec topic, visit your repo's landing page and select "manage topics."


Describe the bug
The "Customize HTML Report Option" is missing the
evidencefield which is necessary for the receiver of the report to know where they need to solve the issue.In this example, the HTML source code of the page is several thousand lines of code the report is Reverse Tabnabbing so the developer will need to know which anchor
<a>tag to fix. Unfortunately, the evidence fie