Skip to content

Commit 87383dc

Browse files
Script now changes upload filename based on input filename
1 parent ad9f996 commit 87383dc

File tree

1 file changed

+2
-1
lines changed

1 file changed

+2
-1
lines changed

xssless.py

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -266,6 +266,7 @@ def xss_gen(requestList, settingsDict):
266266

267267
if 'fileDict' in settingsDict:
268268
if item['name'] in settingsDict['fileDict']:
269+
new_filename = settingsDict['fileDict'][item['name']].split("/")[-1]
269270
filecontents = payload_encode_file(settingsDict['fileDict'][item['name']])
270271

271272
# Find content type
@@ -274,7 +275,7 @@ def xss_gen(requestList, settingsDict):
274275
if content_type is None:
275276
content_type = "application/octet-stream"
276277

277-
multipart += 'Content-Disposition: form-data; name="' + item['name'] + '"; filename="' + item['filename'] + '"\\r\\n'
278+
multipart += 'Content-Disposition: form-data; name="' + item['name'] + '"; filename="' + new_filename + '"\\r\\n'
278279
multipart += 'Content-Type: ' + content_type + '\\r\\n\\r\\n'
279280
multipart += filecontents + '\\r\\n'
280281
else:

0 commit comments

Comments
 (0)