File tree Expand file tree Collapse file tree 4 files changed +64
-0
lines changed
.appsec-tests/vpatch-CVE-2024-6235
appsec-rules/crowdsecurity
collections/crowdsecurity Expand file tree Collapse file tree 4 files changed +64
-0
lines changed Original file line number Diff line number Diff line change 1+ # # autogenerated on 2025-11-28 14:43:34
2+ id : CVE-2024-6235
3+ info :
4+ name : CVE-2024-6235
5+ author : crowdsec
6+ severity : info
7+ description : CVE-2024-6235 testing
8+ tags : appsec-testing
9+ http :
10+ - raw :
11+ - |
12+ GET /internal/v2/config/mps_secret/ADM_SESSIONID HTTP/1.1
13+ Host: {{Hostname}}
14+ Referer: {{RootURL}}/admin_ui/mas/ent/html/main.html
15+ Content-Type: application/json
16+ If-Modified-Since: Thu, 01 Jan 1970 05:30:00 GMT
17+ NITRO_WEB_APPLICATION: true
18+ Tenant-Name: Owner
19+ User-Name: nsroot
20+ Mps-Internal-Request: true
21+ cookie-reuse : true
22+ matchers :
23+ - type : status
24+ status :
25+ - 403
Original file line number Diff line number Diff line change 1+ # # autogenerated on 2025-11-28 14:43:34
2+ appsec-rules :
3+ - ./appsec-rules/crowdsecurity/base-config.yaml
4+ - ./appsec-rules/crowdsecurity/vpatch-CVE-2024-6235.yaml
5+ nuclei_template : CVE-2024-6235.yaml
Original file line number Diff line number Diff line change 1+ # # autogenerated on 2025-11-28 14:43:34
2+ name : crowdsecurity/vpatch-CVE-2024-6235
3+ description : ' Detects unauthorized access to sensitive NetScaler Console configuration endpoint disclosing ADM_SESSIONID.'
4+ rules :
5+ - and :
6+ - zones :
7+ - URI
8+ transform :
9+ - lowercase
10+ match :
11+ type : contains
12+ value : /internal/v2/config/mps_secret/adm_sessionid
13+ - zones :
14+ - HEADERS
15+ variables :
16+ - user-name
17+ transform :
18+ - lowercase
19+ match :
20+ type : equals
21+ value : nsroot
22+
23+ labels :
24+ type : exploit
25+ service : http
26+ confidence : 3
27+ spoofable : 0
28+ behavior : ' http:exploit'
29+ label : ' NetScaler Console - Sensitive Information Disclosure'
30+ classification :
31+ - cve.CVE-2024-6235
32+ - attack.T1592
33+ - cwe.CWE-200
Original file line number Diff line number Diff line change @@ -139,6 +139,7 @@ appsec-rules:
139139- crowdsecurity/vpatch-CVE-2025-27222
140140- crowdsecurity/vpatch-CVE-2025-64446
141141- crowdsecurity/vpatch-CVE-2020-10987
142+ - crowdsecurity/vpatch-CVE-2024-6235
142143author : crowdsecurity
143144contexts :
144145- crowdsecurity/appsec_base
You can’t perform that action at this time.
0 commit comments