From fd3a1efd5169d7b44204e5c73792e1790b488299 Mon Sep 17 00:00:00 2001 From: Prince Chaddha Date: Thu, 17 Mar 2022 16:49:43 +0530 Subject: [PATCH] Update cache-poisoning.yaml --- vulnerabilities/generic/cache-poisoning.yaml | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/vulnerabilities/generic/cache-poisoning.yaml b/vulnerabilities/generic/cache-poisoning.yaml index fa843b73a4..1ac1d781c6 100644 --- a/vulnerabilities/generic/cache-poisoning.yaml +++ b/vulnerabilities/generic/cache-poisoning.yaml @@ -2,8 +2,8 @@ id: cache-poisoning info: name: Cache Poisoning - author: melbadry9,xelkomy - severity: info + author: melbadry9,xelkomy,akincibor + severity: low reference: - https://blog.melbadry9.xyz/fuzzing/nuclei-cache-poisoning - https://portswigger.net/research/practical-web-cache-poisoning @@ -12,13 +12,13 @@ info: requests: - raw: - | - GET /?mel=9 HTTP/1.1 + GET /?{{randstr}}=9 HTTP/1.1 X-Forwarded-Prefix: cache.example.com X-Forwarded-Host: cache.example.com X-Forwarded-For: cache.example.com - | - GET /?mel=9 HTTP/1.1 + GET /?{{randstr}}=9 HTTP/1.1 req-condition: true matchers: