Skip to content

Instantly share code, notes, and snippets.

@selvagsz
Last active January 29, 2016 07:54
Show Gist options
  • Save selvagsz/388e05f9d90eb19b90b0 to your computer and use it in GitHub Desktop.
Save selvagsz/388e05f9d90eb19b90b0 to your computer and use it in GitHub Desktop.
Ember CVE-2015-7565
import Ember from 'ember';
export default Ember.Controller.extend({
appName: {
level1: {
string: "<b style='color: red;'>Emberjs</b>"
}
}
});
<h1>Welcome to {{appName.level1}}</h1>
<br>
<br>
{{outlet}}
<br>
<br>
{
"version": "0.5.0",
"EmberENV": {
"FEATURES": {}
},
"options": {
"enable-testing": false
},
"dependencies": {
"jquery": "https://cdnjs.cloudflare.com/ajax/libs/jquery/1.11.3/jquery.js",
"ember": "1.12.1",
"ember-data": "https://cdnjs.cloudflare.com/ajax/libs/ember-data.js/2.2.0/ember-data.js",
"ember-template-compiler": "1.12.1"
}
}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment