We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
1 parent 4c21c97 commit 3cd29c1Copy full SHA for 3cd29c1
src/main/java/org/joychou/controller/URLWhiteList.java
@@ -91,9 +91,9 @@ public String indexOf(HttpServletRequest request) throws Exception{
91
}
92
93
// URL类getHost方法被绕过造成的安全问题
94
- // 绕过姿势:http://localhost:8080/url/seccode?url=http://www.taobao.com%23@joychou.com/, URL类getHost为joychou.com
+ // 绕过姿势:http://localhost:8080/url/urlVul?url=http://www.taobao.com%23@joychou.com/, URL类getHost为joychou.com
95
// 直接访问http://www.taobao.com#@joychou.com/,浏览器请求的是www.taobao.com
96
- @RequestMapping("/url")
+ @RequestMapping("/urlVul")
97
@ResponseBody
98
public String urlVul(HttpServletRequest request) throws Exception{
99
String url = request.getParameter("url");
0 commit comments