diff --git a/vulnerabilities/other/dedecms-openredirect.yaml b/vulnerabilities/other/dedecms-openredirect.yaml new file mode 100644 index 0000000000..d00f523db7 --- /dev/null +++ b/vulnerabilities/other/dedecms-openredirect.yaml @@ -0,0 +1,24 @@ +id: dedecms-openredirect + +info: + name: DedeCMS Open Redirect + author: pikpikcu + severity: low + reference: https://blog.csdn.net/ystyaoshengting/article/details/82734888 + tags: dedecms,redirect + +requests: + - method: GET + path: + - "{{BaseURL}}/plus/download.php?open=1&link=aHR0cHM6Ly9ldmlsLmNvbQo=" + + matchers-condition: and + matchers: + - type: word + words: + - "Location: https://evil.com" + part: header + + - type: status + status: + - 302