jsp.md (2287B)
1 --- 2 title: "JSP" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/pentesting-web/jsp.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-web/jsp.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # JSP 14 15 ## `getContextPath()` Link Manipulation 16 17 Some JSP applications prepend `request.getContextPath()` to relative resource URLs in attributes such as `src`, `href`, or `action`. If a servlet container incorporates attacker-controlled path parameters into that value and the template does not apply HTML-attribute encoding, HTML character references can transform the rendered value into a protocol-relative URL on an attacker-controlled host.<sup>[[1]](#references)</sup> 18 19 ```text 20 http://127.0.0.1:8080//attacker.example/xss.js#/..;/..;/contextPathExample/test.jsp 21 ``` 22 23 In an affected page, the browser decodes `/` as `/` and `#` as `#`. A generated resource URL can therefore begin with `//attacker.example/xss.js`, while the fragment hides the remaining path. If this value reaches a `<script src>` attribute, the page loads attacker-controlled JavaScript and the issue becomes XSS; other resource attributes may enable related content injection.<sup>[[1]](#references)</sup> 24 25  26 27 Apply context-appropriate output encoding to dynamic values placed in HTML attributes. For a URL embedded in an attribute, OWASP recommends URL encoding followed by HTML-attribute encoding; using a fixed, trusted resource base also avoids deriving an origin from request-controlled path data.<sup>[[2]](#references)</sup> 28 29 ## References 30 31 - [1] [JSP ContextPath Link Manipulation - XSS](https://blog.rakeshmane.com/2020/04/jsp-contextpath-link-manipulation-xss.html) 32 - [2] [OWASP Cross-Site Scripting Prevention Cheat Sheet](https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html)