From 9a4a0069092e456f4b3b807a90b2fc5ce1650f74 Mon Sep 17 00:00:00 2001 From: Prince Chaddha Date: Tue, 31 May 2022 14:30:59 +0530 Subject: [PATCH] Update commax-biometric-auth-bypass.yaml --- .../other/commax-biometric-auth-bypass.yaml | 10 ++++++---- 1 file changed, 6 insertions(+), 4 deletions(-) diff --git a/vulnerabilities/other/commax-biometric-auth-bypass.yaml b/vulnerabilities/other/commax-biometric-auth-bypass.yaml index c277be0818..11e74ddce7 100644 --- a/vulnerabilities/other/commax-biometric-auth-bypass.yaml +++ b/vulnerabilities/other/commax-biometric-auth-bypass.yaml @@ -4,7 +4,8 @@ info: name: COMMAX Biometric Access Control System 1.0.0 - Authentication Bypass author: gy741 severity: critical - description: COMMAX Biometric Access Control System 1.0.0 suffers from an authentication bypass vulnerability. An unauthenticated attacker through cookie poisoning can bypass authentication and disclose sensitive information and circumvent physical controls in smart homes and buildings. + description: | + COMMAX Biometric Access Control System 1.0.0 suffers from an authentication bypass vulnerability. An unauthenticated attacker through cookie poisoning can bypass authentication and disclose sensitive information and circumvent physical controls in smart homes and buildings. reference: - https://www.exploit-db.com/exploits/50206 - https://www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5661.php @@ -21,11 +22,9 @@ requests: matchers-condition: and matchers: - - type: status - status: - - 200 - type: word + part: body words: - "::: COMMAX :::" @@ -34,4 +33,7 @@ requests: words: - "text/html" + - type: status + status: + - 200 # Enhanced by mp on 2022/05/27