漏洞描述
Cobub Razor 0.8.0 Physical path Leakage Vulnerability
id: CVE-2018-8770
info:
name: Cobub Razor 0.8.0 Physical path Leakage Vulnerability
author: we1x4n
severity: medium
description: |-
Cobub Razor 0.8.0 Physical path Leakage Vulnerability
reference:
- https://www.tenable.com/security/research/tra-2018-23
- https://nvd.nist.gov/vuln/detail/CVE-2018-8770
tags: cve,cve2018,cobub,razor,discosure
created: 2023/08/10
rules:
r0:
request:
method: GET
path: /tests/generate.php
expression: 'response.status == 200 && response.body.bcontains(b"Fatal error: Class ''PHPUnit_Framework_TestCase'' not found in ") && response.body.bcontains(b"/application/third_party/CIUnit/libraries/CIUnitTestCase.php on line")'
expression: r0()