surveygizmo-takeover: surveygizmo takeover detection

日期: 2025-08-01 | 影响软件: surveygizmo | POC: 已公开

漏洞描述

surveygizmo takeover was detected.

PoC代码[已公开]

id: surveygizmo-takeover

info:
  name: surveygizmo takeover detection
  author: pdteam
  severity: high
  description: surveygizmo takeover was detected.
  reference:
    - https://github.com/EdOverflow/can-i-take-over-xyz
  metadata:
    max-request: 1
  tags: takeover,vuln

http:
  - method: GET
    path:
      - "{{BaseURL}}"

    matchers-condition: and
    matchers:
      - type: dsl
        dsl:
          - Host != ip

      - type: word
        words:
          - data-html-name

    extractors:
      - type: dsl
        dsl:
          - cname
# digest: 4a0a00473045022100d6514f6bd6a2a3aec9613a95ffe9ab3fa0f508c2cc715af08821a97c09d81d890220483e5a36e444deb131e8b256e7eebd2c2cdfa05395e9d3dc4f91714d363bf659:922c64590222798bb761d5b6d8e72950

相关漏洞推荐