Update CVE-2022-36537.yaml

patch-1
Ritik Chaddha 2023-01-16 00:39:02 +05:30 committed by GitHub
parent 3321d8d6f5
commit cbc0ceed61
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 6 additions and 6 deletions

View File

@ -17,7 +17,7 @@ info:
metadata:
verified: "true"
shodan-query: http.title:"Server backup manager"
tags: cve,cve2022,sensitive-information,unauth,zk-framework
tags: cve,cve2022,zk-framework,exposure,unauth
requests:
- raw:
@ -39,14 +39,14 @@ requests:
/WEB-INF/web.xml
------WebKitFormBoundaryCs6yB0zvpfSBbYEp--
req-condition: true
cookie-reuse: true
matchers-condition: and
matchers:
- type: word
part: body_2
words:
- "display-name"
- type: regex
part: body
regex:
- "<display-name>.*</display-name>"
- "<welcome-file-list>((.|\n)*)welcome-file-list>"
- "xml version"
- "web-app"
condition: and