updated req & metadata

patch-1
Ritik Chaddha 2023-07-21 19:05:21 +05:30 committed by GitHub
parent ddfc12d099
commit 079d75303c
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 13 additions and 4 deletions

View File

@ -17,12 +17,21 @@ info:
cve-id: CVE-2012-4032 cve-id: CVE-2012-4032
cwe-id: CWE-20 cwe-id: CWE-20
cpe: cpe:2.3:a:websitepanel:websitepanel:*:*:*:*:*:*:*:* cpe: cpe:2.3:a:websitepanel:websitepanel:*:*:*:*:*:*:*:*
tags: cve,cve2012,redirect,websitepanel metadata:
max-request: 1
shodan-query: title:"WebsitePanel" html:"login"
tags: cve,cve2012,redirect,websitepanel,authenticated
http: http:
- method: GET - raw:
path: - |
- "{{BaseURL}}/hosting/Default.aspx?pid=Login&ReturnUrl=http%3A%2F%2Fwww.interact.sh" POST /Default.aspx?pid=Login&ReturnUrl=http%3A%2F%2Fwww.interact.sh HTTP/1.1
Host: {{Hostname}}
Cookie: UserCulture=en-US; .WEBSITEPANELPORTALAUTHASPX=
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36
Content-Type: application/x-www-form-urlencoded
ctl03%24ctl01%24ctl00%24txtUsername={{username}}&ctl03%24ctl01%24ctl00%24txtPassword={{password}}&ctl03%24ctl01%24ctl00%24btnLogin=+++Sign+In+++&ctl03%24ctl01%24ctl00%24ddlLanguage=en-US&ctl03%24ctl01%24ctl00%24ddlTheme=Default
matchers: matchers:
- type: regex - type: regex