Merge pull request #3648 from nielsing/telerik-dialog-update

Adding .axd extensions to all paths
patch-1
Prince Chaddha 2022-02-02 02:01:51 +05:30 committed by GitHub
commit 6bcb846f06
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 2 additions and 1 deletions

View File

@ -2,7 +2,7 @@ id: telerik-dialoghandler-detect
info:
name: Detect Telerik Web UI Dialog Handler
author: organiccrap,zhenwarx
author: organiccrap,zhenwarx,nielsing
severity: info
reference:
- https://captmeelo.com/pentest/2018/08/03/pwning-with-telerik.html
@ -28,6 +28,7 @@ requests:
- '{{BaseURL}}/common/admin/Calendar/Telerik.Web.UI.DialogHandler.aspx?dp=1'
- '{{BaseURL}}/cms/portlets/Telerik.Web.UI.DialogHandler.aspx?dp=1'
- '{{BaseURL}}/dashboard/UserControl/CMS/Page/Telerik.Web.UI.DialogHandler.aspx/Desktopmodules/Admin/dnnWerk.Users/DialogHandler.aspx?dp=1'
- '{{BaseURL}}/Telerik.Web.UI.DialogHandler.axd?dp=1'
stop-at-first-match: true
matchers-condition: and