Web Hack List

Collected research

Chaining Three Bugs to Access All Your ServiceNow Data

ServiceNow renders Jelly templates twice, and any query parameter binds to a template variable, so ?jvar_page_title= injects into a no_escape title. The HTML sanitiser permits <style>, whose contents the XML parser still reads as tags, and the injection guard only matches a glide namespace declaration written with double quotes, so single quotes rebind the prefix and execute script pre-auth. A path check then strips .. from filenames, so co..nf/glide.db.properties evades the /conf/ blacklist.

Record

Researcher
Adam Kues
Published by
assetnote.io
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Adam Kues, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .