nuclei-templates/vulnerabilities/other/xiuno-bbs-reinstallation.yaml

27 lines
823 B
YAML

id: xiuno-bbs-reinstallation
info:
name: Xiuno BBS CNVD-2019-01348
author: princechaddha
severity: medium
description: The Xiuno BBS system has a system reinstallation vulnerability. The vulnerability stems from the failure to protect or filter the installation directory after the system is installed. Attackers can directly reinstall the system through the installation page.
reference: https://www.cnvd.org.cn/flaw/show/CNVD-2019-01348
tags: xiuno
requests:
- method: GET
path:
- "{{BaseURL}}/install/"
headers:
Accept-Encoding: deflate
matchers-condition: and
matchers:
- type: status
status:
- 200
- type: word
words:
- "/view/js/xiuno.js"
- "Choose Language (选择语言)"
part: body
condition: and