OQL pentesting cheatsheet
select property from org.springframework.boot.context.properties.source.ConfigurationProperty propertyselect property.name.string.toString() + "=" + property.value.toString() from org.springframework.boot.context.properties.source.ConfigurationProperty propertyList registered path patterns
select pathPattern from org.springframework.web.util.pattern.PathPattern pathPatternselect pathPattern.patternString.toString() from org.springframework.web.util.pattern.PathPattern pathPatternReturn all strings
select s from java.lang.String sReturn strings as strings
select s.toString() from java.lang.String sSearch for the keyword sentinel in all strings
select s from java.lang.String s where s.toString().contains("sentinel")Search for PRIVATE KEYs
select s from java.lang.String s where s.toString().contains("PRIVATE KEY")