TemplateMan Update [Tue Nov 7 07:20:43 UTC 2023] 🤖

patch-1
GitHub Action 2023-11-07 07:20:43 +00:00
parent 5c51d43890
commit b9a98fc9cb
15 changed files with 18 additions and 18 deletions

View File

@ -16,7 +16,7 @@ info:
cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cvss-score: 9.8 cvss-score: 9.8
cve-id: CVE-2017-7925 cve-id: CVE-2017-7925
cwe-id: CWE-522,CWE-260 cwe-id: CWE-260,CWE-522
epss-score: 0.35031 epss-score: 0.35031
epss-percentile: 0.9665 epss-percentile: 0.9665
cpe: cpe:2.3:o:dahuasecurity:dh-ipc-hdbw23a0rn-zs_firmware:-:*:*:*:*:*:*:* cpe: cpe:2.3:o:dahuasecurity:dh-ipc-hdbw23a0rn-zs_firmware:-:*:*:*:*:*:*:*

View File

@ -18,7 +18,7 @@ info:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
cvss-score: 7.5 cvss-score: 7.5
cve-id: CVE-2018-0296 cve-id: CVE-2018-0296
cwe-id: CWE-20,CWE-22 cwe-id: CWE-22,CWE-20
epss-score: 0.97359 epss-score: 0.97359
epss-percentile: 0.99865 epss-percentile: 0.99865
cpe: cpe:2.3:a:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* cpe: cpe:2.3:a:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:*

View File

@ -17,7 +17,7 @@ info:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cvss-score: 9.8 cvss-score: 9.8
cve-id: CVE-2019-3929 cve-id: CVE-2019-3929
cwe-id: CWE-79,CWE-78 cwe-id: CWE-78,CWE-79
epss-score: 0.97419 epss-score: 0.97419
epss-percentile: 0.99908 epss-percentile: 0.99908
cpe: cpe:2.3:o:crestron:am-100_firmware:1.6.0.2:*:*:*:*:*:*:* cpe: cpe:2.3:o:crestron:am-100_firmware:1.6.0.2:*:*:*:*:*:*:*

View File

@ -16,7 +16,7 @@ info:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
cvss-score: 6.5 cvss-score: 6.5
cve-id: CVE-2020-8193 cve-id: CVE-2020-8193
cwe-id: CWE-284,CWE-287 cwe-id: CWE-287,CWE-284
epss-score: 0.93748 epss-score: 0.93748
epss-percentile: 0.98861 epss-percentile: 0.98861
cpe: cpe:2.3:o:citrix:application_delivery_controller_firmware:*:*:*:*:*:*:*:* cpe: cpe:2.3:o:citrix:application_delivery_controller_firmware:*:*:*:*:*:*:*:*

View File

@ -18,7 +18,7 @@ info:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cvss-score: 9.8 cvss-score: 9.8
cve-id: CVE-2021-1472 cve-id: CVE-2021-1472
cwe-id: CWE-287,CWE-119 cwe-id: CWE-119,CWE-287
epss-score: 0.97318 epss-score: 0.97318
epss-percentile: 0.99841 epss-percentile: 0.99841
cpe: cpe:2.3:o:cisco:rv160_firmware:*:*:*:*:*:*:*:* cpe: cpe:2.3:o:cisco:rv160_firmware:*:*:*:*:*:*:*:*

View File

@ -17,7 +17,7 @@ info:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
cvss-score: 9.9 cvss-score: 9.9
cve-id: CVE-2021-21345 cve-id: CVE-2021-21345
cwe-id: CWE-502,CWE-78 cwe-id: CWE-78,CWE-502
epss-score: 0.37552 epss-score: 0.37552
epss-percentile: 0.96773 epss-percentile: 0.96773
cpe: cpe:2.3:a:xstream_project:xstream:*:*:*:*:*:*:*:* cpe: cpe:2.3:a:xstream_project:xstream:*:*:*:*:*:*:*:*

View File

@ -16,7 +16,7 @@ info:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cvss-score: 9.8 cvss-score: 9.8
cve-id: CVE-2021-34621 cve-id: CVE-2021-34621
cwe-id: CWE-306,CWE-269 cwe-id: CWE-269,CWE-306
epss-score: 0.7888 epss-score: 0.7888
epss-percentile: 0.97929 epss-percentile: 0.97929
cpe: cpe:2.3:a:properfraction:profilepress:*:*:*:*:*:wordpress:*:* cpe: cpe:2.3:a:properfraction:profilepress:*:*:*:*:*:wordpress:*:*

View File

@ -18,7 +18,7 @@ info:
cvss-metrics: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H cvss-metrics: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
cvss-score: 8.5 cvss-score: 8.5
cve-id: CVE-2021-39144 cve-id: CVE-2021-39144
cwe-id: CWE-502,CWE-306 cwe-id: CWE-306,CWE-502
epss-score: 0.96508 epss-score: 0.96508
epss-percentile: 0.99453 epss-percentile: 0.99453
cpe: cpe:2.3:a:xstream_project:xstream:*:*:*:*:*:*:*:* cpe: cpe:2.3:a:xstream_project:xstream:*:*:*:*:*:*:*:*

View File

@ -18,7 +18,7 @@ info:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
cvss-score: 9.1 cvss-score: 9.1
cve-id: CVE-2022-0482 cve-id: CVE-2022-0482
cwe-id: CWE-863,CWE-359 cwe-id: CWE-359,CWE-863
epss-score: 0.06254 epss-score: 0.06254
epss-percentile: 0.92812 epss-percentile: 0.92812
cpe: cpe:2.3:a:easyappointments:easyappointments:*:*:*:*:*:wordpress:*:* cpe: cpe:2.3:a:easyappointments:easyappointments:*:*:*:*:*:wordpress:*:*

View File

@ -17,7 +17,7 @@ info:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
cvss-score: 6.1 cvss-score: 6.1
cve-id: CVE-2022-23544 cve-id: CVE-2022-23544
cwe-id: CWE-918,CWE-79 cwe-id: CWE-79,CWE-918
epss-score: 0.00059 epss-score: 0.00059
epss-percentile: 0.23314 epss-percentile: 0.23314
cpe: cpe:2.3:a:metersphere:metersphere:*:*:*:*:*:*:*:* cpe: cpe:2.3:a:metersphere:metersphere:*:*:*:*:*:*:*:*

View File

@ -18,7 +18,7 @@ info:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cvss-score: 9.8 cvss-score: 9.8
cve-id: CVE-2022-46169 cve-id: CVE-2022-46169
cwe-id: CWE-78,CWE-74 cwe-id: CWE-74,CWE-78
epss-score: 0.96583 epss-score: 0.96583
epss-percentile: 0.99485 epss-percentile: 0.99485
cpe: cpe:2.3:a:cacti:cacti:*:*:*:*:*:*:*:* cpe: cpe:2.3:a:cacti:cacti:*:*:*:*:*:*:*:*

View File

@ -18,7 +18,7 @@ info:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cvss-score: 9.8 cvss-score: 9.8
cve-id: CVE-2023-34124 cve-id: CVE-2023-34124
cwe-id: CWE-287,CWE-305 cwe-id: CWE-305,CWE-287
epss-score: 0.01627 epss-score: 0.01627
epss-percentile: 0.86122 epss-percentile: 0.86122
cpe: cpe:2.3:a:sonicwall:analytics:*:*:*:*:*:*:*:* cpe: cpe:2.3:a:sonicwall:analytics:*:*:*:*:*:*:*:*

View File

@ -44,4 +44,5 @@ http:
- 'status_code_2 == 200' - 'status_code_2 == 200'
- 'contains(body_2, "{{payload}}")' - 'contains(body_2, "{{payload}}")'
condition: and condition: and
# digest: 4a0a00473045022100b950d772245477a3b9ca9e272b20a63f38c6dc64378b6fa9dace29426cca5450022007f3af02a3422204244432721fbbdd6997a13cea83e2aac2259e960c7aefeb14:922c64590222798bb761d5b6d8e72950
# digest: 4a0a00473045022100b950d772245477a3b9ca9e272b20a63f38c6dc64378b6fa9dace29426cca5450022007f3af02a3422204244432721fbbdd6997a13cea83e2aac2259e960c7aefeb14:922c64590222798bb761d5b6d8e72950

View File

@ -43,23 +43,21 @@ http:
- type: regex - type: regex
part: interactsh_request part: interactsh_request
regex: regex:
- '\d{6}\.([a-zA-Z0-9\.\-]+)\.([a-z0-9]+)\.([a-z0-9]+)\.([a-z0-9]+)\.\w+' # Print extracted ${:-{{rand1}}}${:-{{rand2}}}.${hostName} in output
extractors: extractors:
- type: kval - type: kval
kval: kval:
- interactsh_ip # Print remote interaction IP in output
- type: regex - type: regex
group: 2 group: 2
regex: regex:
- '\d{6}\.([a-zA-Z0-9\.\-]+)\.([a-z0-9]+)\.([a-z0-9]+)\.([a-z0-9]+)\.\w+' # Print injection point in output
part: interactsh_request part: interactsh_request
- type: regex - type: regex
group: 1 group: 1
regex: regex:
- '\d{6}\.([a-zA-Z0-9\.\-]+)\.([a-z0-9]+)\.([a-z0-9]+)\.([a-z0-9]+)\.\w+' # Print extracted ${:-{{rand1}}}${:-{{rand2}}}.${hostName} in output
part: interactsh_request part: interactsh_request
# digest: 490a00463044022069d41d35a4b8d057e5cd95eb255e94f2df8b3fdeb26f901e821fbe7bdd097b1f0220356c88a5e90ddfd1e00fc7973c4d2bdf2fcc98a5f66169596bbd41323c20b8d4:922c64590222798bb761d5b6d8e72950 # digest: 490a00463044022069d41d35a4b8d057e5cd95eb255e94f2df8b3fdeb26f901e821fbe7bdd097b1f0220356c88a5e90ddfd1e00fc7973c4d2bdf2fcc98a5f66169596bbd41323c20b8d4:922c64590222798bb761d5b6d8e72950

View File

@ -26,4 +26,5 @@ ssl:
- type: json - type: json
json: json:
- " .issuer_cn" - " .issuer_cn"
# digest: 4a0a0047304502210089c3b7edfbbd1e6f13c79ed724e93ae0db447239b79bb2be0496828c5b7d2e2a022069d9ff039f32ebf74f17f2a6efe0a56b6704a80540b1b1d93bf359b0fc28b2f1:922c64590222798bb761d5b6d8e72950
# digest: 4a0a0047304502210089c3b7edfbbd1e6f13c79ed724e93ae0db447239b79bb2be0496828c5b7d2e2a022069d9ff039f32ebf74f17f2a6efe0a56b6704a80540b1b1d93bf359b0fc28b2f1:922c64590222798bb761d5b6d8e72950