SecLists/Pattern-Matching/dangerous-functions-angular...

15 lines
291 B
Plaintext

# Angular pipes
bypassSecurityTrustHtml
bypassSecurityTrustScript
bypassSecurityTrustStyle
bypassSecurityTrustUrl
bypassSecurityTrustResourceUrl
# Angular inputs
[innerHTML] #Insert given HTML without escaping dangerous characters
# angular.js (aka Angular 1)
trustAsHtml
$eval
$evalAsync