Skip to main content

exploiting-cross-site-script-inclusion-xssi

Identifying and exploiting Cross-Site Script Inclusion (XSSI), where the script tag's exemption from the Same-Origin Policy lets an attacker include a victim endpoint cross-origin (with the victim's ambient cookies) and read sensitive data from static scripts, dynamic JS, JSONP responses, or non-JS files (CSV) included as scripts. Activates when assessing endpoints that return JS/JSONP or data reachable via a script tag.

الانتقال إلى التثبيت

معلومات المصدر

المستودع
xalgord/xalgorix
آخر نشاط في المصدر
٦ يونيو ٢٠٢٦ في ١٦:٤١
لغة SKILL.md المكتشفة
الإنجليزية
النجوم
٨١٣
التفرعات
١٤٦

خيارات التثبيت

يُحدَّد Prompt الذي يراجع المصدر أولًا بشكل افتراضي. يمكنك التبديل إلى أمر مباشر أو تنزيل نسخة محلية.

مراجعة ملفات المصدر

اقرأ SKILL.md وأي ملفات مرافقة يعرضها SkillsMP قبل أن تقرر التثبيت.