In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Cross-site Scripting (XSS) vulnerabilities in an interactive lesson.
Start learningUpgrade redis-commander
to version 0.5.0 or higher.
redis-commander
is a Redis management tool written in node.js
Affected versions of this package are vulnerable to Reflected Cross-Site Scripting (XSS) via the clipboard.swf
component.
An attacker may input a crafted XXX in the highlighterId
parameter of the clipboard.swf component, causing a Reflected XSS on hosts serving Redis Commander.
http://instance/jstree/_docs/syntax/clipboard.swf?highlighterId=\%22))}%20catch(e)%20{alert(document.domain);}//
<>