This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
id: CVE-2023-5830 | |
info: | |
name: ColumbiaSoft DocumentLocator - Improper Authentication | |
author: Gonski | |
severity: critical | |
description: | | |
Instances of ColumbiaSoft's Document Locator prior to version 7.2 SP4 and 2021.1 are vulnerable to an Improper Authentication/SSRF vulnerability. This template identifies vulnerable instances of the ColumbiaSoft Document Locater application by confirming external DNS interaction/lookups by modifying the value of the client-side SERVER parameter at /api/authentication/login. | |
impact: | | |
An attacker could exploit this vulnerability to gain unauthorized access to sensitive information. |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
{ | |
"queries": [ | |
{ | |
"name": "Find all Certificate Templates", | |
"category": "Certificates", | |
"queryList": [ | |
{ | |
"final": true, | |
"query": "MATCH (n:GPO) WHERE n.type = 'Certificate Template' RETURN n" | |
} |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
import dns.resolver | |
import sys | |
list_of_dcs = [] | |
new_dict = {} | |
GREEN = '\033[0;32m' | |
def print_colored(message, color_code): | |
RESET_COLOR = "\033[0m" | |
print(f"{color_code}{message}{RESET_COLOR}") |