Skip to content

Commit 5831469

Browse files
Add vpatch-CVE-2018-13317 rule and test (#1613)
* Add vpatch-CVE-2018-13317 rule * Add vpatch-CVE-2018-13317 test config * Add CVE-2018-13317.yaml test * Add vpatch-CVE-2018-13317 rule to vpatch collection * Update vpatch-CVE-2018-13317.yaml --------- Co-authored-by: Thibault "bui" Koechlin <[email protected]>
1 parent 7948d73 commit 5831469

File tree

4 files changed

+47
-0
lines changed

4 files changed

+47
-0
lines changed
Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,17 @@
1+
## autogenerated on 2025-12-17 15:06:18
2+
id: CVE-2018-13317
3+
info:
4+
name: CVE-2018-13317
5+
author: crowdsec
6+
severity: info
7+
description: CVE-2018-13317 testing
8+
tags: appsec-testing
9+
http:
10+
- method: GET
11+
path:
12+
- "{{BaseURL}}/password.htm"
13+
cookie-reuse: true
14+
matchers:
15+
- type: status
16+
status:
17+
- 403
Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
1+
## autogenerated on 2025-12-17 15:06:18
2+
appsec-rules:
3+
- ./appsec-rules/crowdsecurity/base-config.yaml
4+
- ./appsec-rules/crowdsecurity/vpatch-CVE-2018-13317.yaml
5+
nuclei_template: CVE-2018-13317.yaml
Lines changed: 24 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,24 @@
1+
## autogenerated on 2025-12-17 15:06:18
2+
name: crowdsecurity/vpatch-CVE-2018-13317
3+
description: 'Detects unauthenticated access to TOTOLINK A3002RU password disclosure endpoint.'
4+
rules:
5+
- zones:
6+
- URI
7+
transform:
8+
- lowercase
9+
- urldecode
10+
match:
11+
type: equals
12+
value: /password.htm
13+
14+
labels:
15+
type: exploit
16+
service: http
17+
confidence: 3
18+
spoofable: 0
19+
behavior: 'http:exploit'
20+
label: 'Totolink A3002RU - Information Disclosure'
21+
classification:
22+
- cve.CVE-2018-13317
23+
- attack.T1592
24+
- cwe.CWE-79

collections/crowdsecurity/appsec-virtual-patching.yaml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -141,6 +141,7 @@ appsec-rules:
141141
- crowdsecurity/vpatch-CVE-2020-10987
142142
- crowdsecurity/vpatch-CVE-2025-55182
143143
- crowdsecurity/vpatch-CVE-2024-6235
144+
- crowdsecurity/vpatch-CVE-2018-13317
144145
- crowdsecurity/vpatch-CVE-2025-9316
145146
- crowdsecurity/vpatch-CVE-2025-11700
146147
- crowdsecurity/vpatch-CVE-2025-13315

0 commit comments

Comments
 (0)