32 lines
1.2 KiB
YAML
32 lines
1.2 KiB
YAML
id: CVE-2015-2863
|
|
|
|
info:
|
|
name: Kaseya Virtual System Administrator - Open Redirect
|
|
author: 0x_Akoko
|
|
severity: low
|
|
description: |
|
|
Open redirect vulnerability in Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.29, 8.x before 8.0.0.18, 9.0 before 9.0.0.14, and 9.1 before 9.1.0.4 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
|
|
reference:
|
|
- https://github.com/pedrib/PoC/blob/3f927b957b86a91ce65b017c4b9c93d05e241592/advisories/Kaseya/kaseya-vsa-vuln.txt
|
|
- https://www.cvedetails.com/cve/CVE-2015-2863
|
|
- http://www.kb.cert.org/vuls/id/919604
|
|
classification:
|
|
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
|
|
cvss-score: 6.1
|
|
cve-id: CVE-2015-2863
|
|
cwe-id: CWE-601
|
|
tags: cve,cve2015,redirect,kaseya
|
|
|
|
requests:
|
|
- method: GET
|
|
path:
|
|
- '{{BaseURL}}/inc/supportLoad.asp?urlToLoad=http://oast.me'
|
|
- '{{BaseURL}}/vsaPres/Web20/core/LocalProxy.ashx?url=http://oast.me'
|
|
|
|
stop-at-first-match: true
|
|
matchers:
|
|
- type: regex
|
|
part: header
|
|
regex:
|
|
- '(?m)^(?:Location\s*?:\s*?)(?:https?:\/\/|\/\/|\/\\\\|\/\\)?(?:[a-zA-Z0-9\-_\.@]*)oast\.me\/?(\/|[^.].*)?$' # https://regex101.com/r/ZDYhFh/1
|