From f85eda7ec18468f43d22bb7956cdf60698c213fb Mon Sep 17 00:00:00 2001 From: "Z. Cliffe Schreuders" Date: Mon, 15 Jul 2019 11:47:50 +0100 Subject: [PATCH] webapps conflict with eachother since they accept any virtualhost name --- .../unix/webapp/gitlist_040/secgen_metadata.xml | 5 +++++ .../unix/webapp/moinmoin_195/secgen_metadata.xml | 8 +++++++- .../unix/webapp/onlinestore/secgen_metadata.xml | 5 +++++ 3 files changed, 17 insertions(+), 1 deletion(-) diff --git a/modules/vulnerabilities/unix/webapp/gitlist_040/secgen_metadata.xml b/modules/vulnerabilities/unix/webapp/gitlist_040/secgen_metadata.xml index 2e1f85951..576fe6b90 100644 --- a/modules/vulnerabilities/unix/webapp/gitlist_040/secgen_metadata.xml +++ b/modules/vulnerabilities/unix/webapp/gitlist_040/secgen_metadata.xml @@ -49,6 +49,11 @@ exploit/linux/http/gitlist_exec Visit the webapp in a browser at: ip:80/gitlist + + + webapp + + .*apache.*compatible.* diff --git a/modules/vulnerabilities/unix/webapp/moinmoin_195/secgen_metadata.xml b/modules/vulnerabilities/unix/webapp/moinmoin_195/secgen_metadata.xml index c7d47b679..e9d6b89c8 100644 --- a/modules/vulnerabilities/unix/webapp/moinmoin_195/secgen_metadata.xml +++ b/modules/vulnerabilities/unix/webapp/moinmoin_195/secgen_metadata.xml @@ -33,6 +33,7 @@ 80 + This is some leaked data. @@ -69,6 +70,11 @@ Path traversal found in AttachFile module. + + + webapp + + .*Stretch.* @@ -79,4 +85,4 @@ - \ No newline at end of file + diff --git a/modules/vulnerabilities/unix/webapp/onlinestore/secgen_metadata.xml b/modules/vulnerabilities/unix/webapp/onlinestore/secgen_metadata.xml index af851a041..9bcfc9de8 100644 --- a/modules/vulnerabilities/unix/webapp/onlinestore/secgen_metadata.xml +++ b/modules/vulnerabilities/unix/webapp/onlinestore/secgen_metadata.xml @@ -143,6 +143,11 @@ modules/bases/kali.* + + + webapp + + .*apache.*compatible.*