Skip to content

nuclei workflow #4430

Answered by princechaddha
ody5sey asked this question in Q&A
Discussion options

You must be logged in to vote

If you do not want to send the second request when the first is not matched, you can use the flow in the templates. You can read more about it at Flow Documentation.

Example: CVE-2021-28164

id: CVE-2021-28164

info:
  name: Eclipse Jetty - Information Disclosure
  author: noamrathaus
  severity: medium
  description: |
    Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224 is susceptible to improper authorization. The default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to access protected resources within the WEB-INF directory. An attacker can access sensitive information regarding the implementation of a web application.
  tags: packetstorm,vulhub,cve,cv…

Replies: 2 comments

Comment options

You must be logged in to vote
0 replies
Answer selected by ehsandeep
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
Type: Enhancement Most issues will probably ask for additions or changes.
2 participants
Converted from issue

This discussion was converted from issue #4429 on November 27, 2023 10:33.