Update CVE-2020-13121.yaml

patch-1
Dhiyaneshwaran 2022-11-09 12:05:02 +05:30 committed by GitHub
parent 8c14733e0b
commit 2f3d3d323e
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 11 additions and 3 deletions

View File

@ -16,10 +16,18 @@ info:
tags: cve,cve2020,redirect,submitty,oos
requests:
- method: GET
path:
- '{{BaseURL}}/authentication/login?old=http%3A%2F%2Flexample.com'
- raw:
- |
POST /authentication/check_login?old=http%253A%252F%252Fexample.com%252Fhome HTTP/1.1
Host: {{Hostname}}
Origin: {{RootURL}}
Content-Type: application/x-www-form-urlencoded
Referer: {{RootURL}}/authentication/login
user_id={{username}}&password={{password}}&stay_logged_in=on&login=Login
cookie-reuse: true
matchers-condition: and
matchers:
- type: regex
regex: