Popular Vulnerable Code

Everything

Anybody who knows everything should be told a thing or two.
- Franklin P. Jones

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
                <script type="text/javascript">
                        // workaround for bug in Safari 3.  See #7189
                        if (/3[\.0-9]+ Safari/.test(navigator.appVersion))
                        {
                                window.console = {
                                    origConsole: window.console,
                                    log: function(s){
                                                this.origConsole.log(s);
                                        },
                                        info: function(s){
                                                this.origConsole.info(s);
                                        },
                                        error: function(s){
                                                this.origConsole.error(s);
                                        },
                                        warn: function(s){
                                                this.origConsole.warn(s);
                                        }
                               };
                        }
                </script>
 
                <script type="text/javascript">
                        window.dojoUrl = "../../dojo/dojo.js";
                        window.testUrl = "";
                        window.testModule = "";
 
                        // parse out our test URL and our Dojo URL from the query string
                        var qstr = window.location.search.substr(1);
                        if(qstr.length){
                                var qparts = qstr.split("&");
                                for(var x=0; x<qparts.length; x++){
                                        var tp = qparts[x].split("=");
                                        if(tp[0] == "dojoUrl"){
                                                window.dojoUrl = tp[1];
                                        }
                                        if(tp[0] == "testUrl"){
                                                window.testUrl = tp[1];
                                        }
                                        if(tp[0] == "testModule"){
                                                window.testModule = tp[1];
                                        }
                                        if(tp[0] == "registerModulePath"){
                                                var modules = tp[1].split(";");
                                                window.registerModulePath=[];
                                                for (var i=0; i<modules.length;i++){
                                                         window.registerModulePath.push(modules[i].split(","));
                                                }
                                        }
                                }
                        }
 
                        document.write("<scr"+"ipt type='text/javascript' djConfig='isDebug:true' src='"+dojoUrl+"'></scr"+"ipt>");
                </script>
                <script type="text/javascript">
                        try{
                                dojo.require("doh.runner");
                        }catch(e){
                                document.write("<scr"+"ipt type='text/javascript' src='runner.js'></scr"+"ipt>");
                        }
                        if(testUrl.length){
                                document.write("<scr"+"ipt type='text/javascript' src='"+testUrl+".js'></scr"+"ipt>");
                        }
                </script>
                <style type="text/css">
                        @import "../../dojo/resources/dojo.css";
                        var SHRSB_Globals ={"src":"http:\/\/spotthevuln.com\/wordpress\/wp-content\/plugins\/sexybookmarks\/spritegen_default","perfoption":null};