55 < title > Home Page</ title >
66</ head >
77< body >
8- < p > Hello < span th:text ="${user} "> </ span > .</ p >
9- < p > Welcome to login java-sec-code application. < a th:href ="@{/appInfo} "> Application Infomation</ a > </ p >
10- < p >
11- < a th:href ="@{/swagger-ui.html} "> Swagger</ a >
12- < a th:href ="@{/codeinject?filepath=/tmp;cat /etc/passwd} "> CmdInject</ a >
13- < a th:href ="@{/jsonp/getToken?_callback=test} "> JSONP</ a >
14- < a th:href ="@{/file/pic} "> Picture Upload</ a >
15- < a th:href ="@{/file/any} "> File Upload</ a >
16- < a th:href ="@{cors/sec/originFilter} "> Cors</ a >
17- < a th:href ="@{/path_traversal/vul?filepath=../../../../../etc/passwd} "> PathTraversal</ a >
18- < a th:href ="@{sqli/mybatis/vuln01?username=joychou' or '1'='1} "> SqlInject</ a >
19- < a th:href ="@{/ssrf/urlConnection/vuln?url=file:///etc/passwd} "> SSRF</ a >
20- < a th:href ="@{/rce/exec?cmd=whoami} "> RCE</ a >
21- < a th:href ="@{/ooxml/upload} "> ooxml XXE</ a >
22- < a th:href ="@{/xlsx-streamer/upload} "> xlsx-streamer XXE</ a >
23- </ p >
8+ < p > Hello < span th:text ="${user} "> </ span > .</ p >
9+ < p > Welcome to login java-sec-code application. < a th:href ="@{/appInfo} "> Application Infomation</ a > </ p >
10+ < p >
11+ < a th:href ="@{/swagger-ui.html} "> Swagger</ a >
12+ < a th:href ="@{/codeinject?filepath=/tmp;cat /etc/passwd} "> CmdInject</ a >
13+ < a th:href ="@{/jsonp/getToken?_callback=test} "> JSONP</ a >
14+ < a th:href ="@{/file/pic} "> Picture Upload</ a >
15+ < a th:href ="@{/file/any} "> File Upload</ a >
16+ < a th:href ="@{cors/sec/originFilter} "> Cors</ a >
17+ < a th:href ="@{/path_traversal/vul?filepath=../../../../../etc/passwd} "> PathTraversal</ a >
18+ < a th:href ="@{sqli/mybatis/vuln01?username=joychou' or '1'='1} "> SqlInject</ a >
19+ < a th:href ="@{/ssrf/urlConnection/vuln?url=file:///etc/passwd} "> SSRF</ a >
20+ < a th:href ="@{/rce/exec?cmd=whoami} "> RCE</ a >
21+ < a th:href ="@{/ooxml/upload} "> ooxml XXE</ a >
22+ < a th:href ="@{/xlsx-streamer/upload} "> xlsx-streamer XXE</ a >
23+ </ p >
2424
25- < P >
26- < a th:href ="@{/jwt/createToken} "> JWTCreateToken</ a >
27- < a th:href ="@{/jwt/getName} "> GetUserFromJWTToken</ a >
28- </ P >
29- < p > ...</ p >
30- < a th:href ="@{/logout} "> logout</ a >
25+ < P >
26+ < a th:href ="@{/jwt/createToken} "> JWTCreateToken</ a >
27+ < a th:href ="@{/jwt/getName} "> GetUserFromJWTToken</ a >
28+ </ P >
29+ < p > ...</ p >
30+ < a th:href ="@{/logout} "> logout</ a >
3131
3232</ body >
3333</ html >
0 commit comments