diff --git a/dast-java/src/main/java/com/alipay/antbenchmark/controller/bs/BS00113Controller.java b/dast-java/src/main/java/com/alipay/antbenchmark/controller/bs/BS00113Controller.java index 651ebef9..185d754e 100644 --- a/dast-java/src/main/java/com/alipay/antbenchmark/controller/bs/BS00113Controller.java +++ b/dast-java/src/main/java/com/alipay/antbenchmark/controller/bs/BS00113Controller.java @@ -29,7 +29,7 @@ public void doPost(HttpServletRequest request, HttpServletResponse response) thr param = param.replace("\n", "").replace("\r", "").replace("\"", "\\\""); param = param.replace("<", "").replace(">", ""); try { - response.getWriter().println(param + "{\"username\":\"test\"}"); + response.getWriter().println(param + "({\"username\":\"test\"})"); } catch (Exception e) { response.getWriter().println(e.toString()); return; diff --git a/dast-java/src/main/resources/callscanner/payloads/BS00113.txt b/dast-java/src/main/resources/callscanner/payloads/BS00113.txt index d9de4aff..f15f8afd 100644 --- a/dast-java/src/main/resources/callscanner/payloads/BS00113.txt +++ b/dast-java/src/main/resources/callscanner/payloads/BS00113.txt @@ -1,4 +1,4 @@ -GET /jsonp/BS00113 HTTP/1.1 +GET /jsonp/BS00113?BS00113=callback HTTP/1.1 Host: localhost Connection: close Accept-Encoding: gzip, deflate