diff --git a/cves/2017/CVE-2017-17736.yaml b/cves/2017/CVE-2017-17736.yaml new file mode 100644 index 0000000000..d024014e65 --- /dev/null +++ b/cves/2017/CVE-2017-17736.yaml @@ -0,0 +1,35 @@ +id: CVE-2017-17736 + +info: + name: Kentico - Unauthenticated Administration Dashboard + author: shiar + severity: critical + description: | + Kentico 9.0 before 9.0.51 and 10.0 before 10.0.48 allows remote attackers to obtain Global Administrator access by visiting CMSInstall/install.aspx and then navigating to the CMS Administration Dashboard. + reference: + - https://www.exploit-db.com/ghdb/5694 + - https://nvd.nist.gov/vuln/detail/CVE-2017-17736 + metadata: + verified: true + google-dork: intitle:"kentico database setup" + tags: cve,cve2017,kentico,cms,install,rce,unauth + +requests: + - method: GET + path: + - "{{BaseURL}}/CMSInstall/install.aspx" + + matchers-condition: or + matchers: + - type: word + words: + - "Kentico" + - "Database Setup" + - "SQLServer" + condition: and + + - type: word + words: + - "Database Setup" + - "SQLServer" + condition: and