mirror of
https://github.com/danielmiessler/SecLists
synced 2025-12-13 20:35:18 +01:00
fix(docs): Moved 'AdobeCQ-AEM.txt' into the CMS directory
This commit is contained in:
parent
32746dd3bf
commit
9034c8bcc1
3 changed files with 30 additions and 5 deletions
30
Discovery/Web-Content/CMS/README.md
Normal file
30
Discovery/Web-Content/CMS/README.md
Normal file
|
|
@ -0,0 +1,30 @@
|
|||
# CMS Wordlists
|
||||
|
||||
These wordlists are specific to Content Management Systems.
|
||||
|
||||
## AdobeCQ-AEM.txt
|
||||
Use for: Discovering sensitive filepaths of **Adobe Experience Manager**
|
||||
Creation date: Oct 1, 2017
|
||||
No updates have been made to this wordlist since its creation.
|
||||
|
||||
|
||||
## Oracle-EBS-wordlist.txt
|
||||
Use for: Fuzzing for common filepaths of [Oracle E-Business Suite](https://www.oracle.com/applications/ebusiness/) (EBS) version 11.
|
||||
|
||||
EBS v11 exposes:
|
||||
- usernames
|
||||
- ports
|
||||
- OS information
|
||||
- protocol information
|
||||
- Unauthenticated file upload
|
||||
- Cookie contents
|
||||
- SHA-1 hashed passwords
|
||||
|
||||
As an Unauthenticated user it's also possible to:
|
||||
- Create forms
|
||||
- Get servlets status
|
||||
- Get certain configuration files
|
||||
|
||||
Reference: https://the-infosec.com/2017/03/29/do-you-know-what-your-erp-is-telling-us/
|
||||
|
||||
Date of last update: Oct 7, 2019
|
||||
|
|
@ -1,10 +1,5 @@
|
|||
# Web discovery wordlists
|
||||
|
||||
## AdobeCQ-AEM.txt
|
||||
Use for: Discovering sensitive filepaths of **Adobe Experience Manager**
|
||||
Creation date: Oct 1, 2017
|
||||
No updates have been made to this wordlist since its creation.
|
||||
|
||||
## AdobeXML.fuzz.txt
|
||||
Use for: Discovering sensitive filepaths of **Adobe ColdFusion**
|
||||
|
||||
|
|
|
|||
Loading…
Reference in a new issue