Merge pull request #8724 from projectdiscovery/pussycat0x-patch-5

Endpoint Update CVE-2023-49103
patch-1
Dhiyaneshwaran 2023-11-30 17:19:28 +05:30 committed by GitHub
commit f8b1e66e22
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 5 additions and 2 deletions

View File

@ -10,7 +10,8 @@ info:
- https://github.com/creacitysec/CVE-2023-49103/blob/main/exploit.py - https://github.com/creacitysec/CVE-2023-49103/blob/main/exploit.py
- https://nvd.nist.gov/vuln/detail/CVE-2023-49103 - https://nvd.nist.gov/vuln/detail/CVE-2023-49103
- https://owncloud.com/security-advisories/disclosure-of-sensitive-credentials-and-configuration-in-containerized-deployments/ - https://owncloud.com/security-advisories/disclosure-of-sensitive-credentials-and-configuration-in-containerized-deployments/
- https://owncloud.org/security - https://www.labs.greynoise.io//grimoire/2023-11-29-owncloud-redux/
- https://attackerkb.com/topics/G9urDj4Cg2/cve-2023-49103
classification: classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
cvss-score: 10 cvss-score: 10
@ -28,7 +29,9 @@ http:
- method: GET - method: GET
path: path:
- "{{BaseURL}}/owncloud/apps/graphapi/vendor/microsoft/microsoft-graph/tests/GetPhpInfo.php" - "{{BaseURL}}/owncloud/apps/graphapi/vendor/microsoft/microsoft-graph/tests/GetPhpInfo.php"
- "{{BaseURL}}/apps/graphapi/vendor/microsoft/microsoft-graph/tests/GetPhpInfo.php"
stop-at-first-match: true
matchers-condition: and matchers-condition: and
matchers: matchers:
- type: word - type: word