Skip to content

Instantly share code, notes, and snippets.

@KarthikaRamachandran
Created November 4, 2016 14:24
Show Gist options
  • Select an option

  • Save KarthikaRamachandran/238484190de9ae456f649b6d01d1efbb to your computer and use it in GitHub Desktop.

Select an option

Save KarthikaRamachandran/238484190de9ae456f649b6d01d1efbb to your computer and use it in GitHub Desktop.
XSS Vulnerability
import Ember from 'ember';
export default Ember.Controller.extend({
appName: 'Ember Twiddle',
actions : {
setContent : function(){
Ember.$("#firstItem").find("span").html(Ember.String.htmlSafe("<img src='kar.jpg' onerror='alert(1);'/>"));
Ember.$("#secondItem").html(Ember.String.htmlSafe("<b>HI</b>"));
}
}
});
import Ember from 'ember';
export function makeBold(params/*, hash*/) {
return Ember.String.htmlSafe("<b>"+Ember.Handlebars.Utils.escapeExpression(params)+"</b>");
}
export default Ember.Helper.helper(makeBold);
<h1>Encode Html</h1>
<br>
<br>
{{make-bold "<img src='kar.jpg' onerror='alert(1);'/>"}}<br/><br/><br/>
{{make-bold "<span>Text</span>"}}<br/>
{{outlet}}<br/><br/>
<button {{action "setContent"}}>SET</button>
<ul>
<li id="firstItem">
<span>ONE</span>
</li>
<li id="secondItem">
<span>TWO</span>
</li>
</ul>
<br>
<br>
import Ember from 'ember';
export default function destroyApp(application) {
Ember.run(application, 'destroy');
}
import Resolver from '../../resolver';
import config from '../../config/environment';
const resolver = Resolver.create();
resolver.namespace = {
modulePrefix: config.modulePrefix,
podModulePrefix: config.podModulePrefix
};
export default resolver;
import Ember from 'ember';
import Application from '../../app';
import config from '../../config/environment';
const { run } = Ember;
const assign = Ember.assign || Ember.merge;
export default function startApp(attrs) {
let application;
let attributes = assign({rootElement: "#test-root"}, config.APP);
attributes = assign(attributes, attrs); // use defaults, but you can override;
run(() => {
application = Application.create(attributes);
application.setupForTesting();
application.injectTestHelpers();
});
return application;
}
import resolver from './helpers/resolver';
import {
setResolver
} from 'ember-qunit';
setResolver(resolver);
{
"version": "0.10.6",
"EmberENV": {
"FEATURES": {}
},
"options": {
"use_pods": false,
"enable-testing": false
},
"dependencies": {
"jquery": "https://cdnjs.cloudflare.com/ajax/libs/jquery/1.11.3/jquery.js",
"ember": "2.9.0",
"ember-data": "2.9.0",
"ember-template-compiler": "2.9.0",
"ember-testing": "2.9.0"
},
"addons": {}
}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment