update nuclei-ignore & CVE-2014-9608

patch-1
Ritik Chaddha 2023-07-27 23:36:32 +05:30
parent 3dfaae84a4
commit d06b81dfbe
2 changed files with 10 additions and 10 deletions

View File

@ -24,16 +24,8 @@ tags:
files:
- http/cves/2006/CVE-2006-1681.yaml
- http/cves/2007/CVE-2007-5728.yaml
- http/cves/2011/CVE-2011-4618.yaml
- http/cves/2014/CVE-2014-9608.yaml
- http/cves/2018/CVE-2018-5316.yaml
- http/cves/2018/CVE-2018-5233.yaml
- http/cves/2019/CVE-2019-14696.yaml
- http/cves/2020/CVE-2020-11930.yaml
- http/cves/2020/CVE-2020-19295.yaml
- http/cves/2020/CVE-2020-2036.yaml
- http/cves/2020/CVE-2020-28351.yaml
- http/cves/2021/CVE-2021-35265.yaml
- http/vulnerabilities/oracle/oracle-ebs-xss.yaml
- http/vulnerabilities/other/nginx-module-vts-xss.yaml

View File

@ -4,7 +4,8 @@ info:
name: Netsweeper 4.0.3 - Cross-Site Scripting
author: daffainfo
severity: medium
description: A cross-site scripting vulnerability in webadmin/policy/group_table_ajax.php/ in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
description: |
A cross-site scripting vulnerability in webadmin/policy/group_table_ajax.php/ in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
reference:
- https://packetstormsecurity.com/files/download/133034/netsweeper-issues.tgz
- https://nvd.nist.gov/vuln/detail/CVE-2014-9608
@ -34,6 +35,13 @@ http:
words:
- '</script><script>alert(document.domain)</script>'
- type: word
part: header
words:
- 'webadminU='
- 'webadmin='
condition: or
- type: word
part: header
words:
@ -41,4 +49,4 @@ http:
- type: status
status:
- 200
- 200