Merge pull request #496 from 418sec/4-npm-systeminformation
Security Fix for Server-site request forgery - huntr.dev
This commit is contained in:
commit
881dde4734
22
lib/poc.js
Normal file
22
lib/poc.js
Normal file
@ -0,0 +1,22 @@
|
||||
let si = require('./internet');
|
||||
si.inetChecksite([]).then((a) => {
|
||||
if (a.ok == false)
|
||||
console.log("inetChecksite is fixed!")
|
||||
else
|
||||
console.log("inetChecksite is not fixed!")
|
||||
});
|
||||
|
||||
|
||||
si.inetLatency([]).then((a) => {
|
||||
if (a == null)
|
||||
console.log("inetLatency is fixed!")
|
||||
else
|
||||
console.log("inetLatency is not fixed!")
|
||||
});
|
||||
si = require('./processes');
|
||||
si.services([]).then((a) => {
|
||||
if (typeof a == typeof [])
|
||||
console.log("services is fixed!")
|
||||
else
|
||||
console.log("services is not fixed!")
|
||||
});
|
||||
@ -529,6 +529,7 @@ function sanitizeShellString(str, strict = false) {
|
||||
s[i] === '\'' ||
|
||||
s[i] === '`' ||
|
||||
s[i] === '"' ||
|
||||
strict && s[i] === '@' ||
|
||||
strict && s[i] === ' ' ||
|
||||
strict && s[i] == '{' ||
|
||||
strict && s[i] == ')')) {
|
||||
|
||||
Loading…
x
Reference in New Issue
Block a user