目标: 1000 元 · 已筹: 1359 元
Jenkins Gitlab Hook 1.4.2 and earlier does not escape project names in the build_now endpoint, resulting in a reflected cross-site scripting vulnerability.
登录后查看神龙缓存的 POC 文件快照