diff --git a/vulnerabilities/oracle/oracle-siebel-xss.yaml b/vulnerabilities/oracle/oracle-siebel-xss.yaml index e3a186b898..19e3bc099e 100644 --- a/vulnerabilities/oracle/oracle-siebel-xss.yaml +++ b/vulnerabilities/oracle/oracle-siebel-xss.yaml @@ -1,22 +1,28 @@ id: oracle-siebel-xss info: - name: Oracle Siebel XSS + name: Oracle Siebel Loyalty 8.1 - XSS Vulnerability author: dhiyaneshDK severity: medium reference: https://packetstormsecurity.com/files/86721/Oracle-Siebel-Loyalty-8.1-Cross-Site-Scripting.html - tags: xss + tags: xss,oracle requests: - method: GET path: - - '{{BaseURL}}/loyalty_enu/start.swe/%3E%22%3E%3Cscript%3Ealert("XSS")%3C/script%3E' + - '{{BaseURL}}/loyalty_enu/start.swe/%3E%22%3E%2Fscript%3E%3Cscript%3Ealert%28document.domain%29%3C%2Fscript%3E' matchers-condition: and matchers: - type: word words: - - 'XSS' + - '' + + - type: word + part: header + words: + - text/html + - type: status status: - 200