Prototype Pollution Exploit

JavaScript 原型链污染漏洞利用方法论。当目标为 Node.js 应用、使用 lodash/jQuery/深拷贝函数、接收 JSON 输入时使用。覆盖 Server-side(RCE/权限绕过)和 Client-side(XSS/DOM 操控)两种场景

wgpsec 93e438a 3 files · 31.0 KB Updated

File contents

wgpsec/aboutsecurity/tree/main/skills/exploit/web-method/prototype-pollution-exploit commit 93e438a9f9

Frequently asked questions

npx skillmds@latest add wgpsec/prototype-pollution-exploit