From 9034c8bcc12ceed85c08fe3b87b908acea22e89b Mon Sep 17 00:00:00 2001 From: "Ignacio J. Perez Portal" <5990@protonmail.com> Date: Wed, 9 Oct 2024 17:48:50 -0300 Subject: [PATCH] fix(docs): Moved 'AdobeCQ-AEM.txt' into the CMS directory --- .../Web-Content/{ => CMS}/AdobeCQ-AEM.txt | 0 Discovery/Web-Content/CMS/README.md | 30 +++++++++++++++++++ Discovery/Web-Content/README.md | 5 ---- 3 files changed, 30 insertions(+), 5 deletions(-) rename Discovery/Web-Content/{ => CMS}/AdobeCQ-AEM.txt (100%) create mode 100644 Discovery/Web-Content/CMS/README.md diff --git a/Discovery/Web-Content/AdobeCQ-AEM.txt b/Discovery/Web-Content/CMS/AdobeCQ-AEM.txt similarity index 100% rename from Discovery/Web-Content/AdobeCQ-AEM.txt rename to Discovery/Web-Content/CMS/AdobeCQ-AEM.txt diff --git a/Discovery/Web-Content/CMS/README.md b/Discovery/Web-Content/CMS/README.md new file mode 100644 index 00000000..619e3282 --- /dev/null +++ b/Discovery/Web-Content/CMS/README.md @@ -0,0 +1,30 @@ +# CMS Wordlists + +These wordlists are specific to Content Management Systems. + +## AdobeCQ-AEM.txt +Use for: Discovering sensitive filepaths of **Adobe Experience Manager** +Creation date: Oct 1, 2017 +No updates have been made to this wordlist since its creation. + + +## Oracle-EBS-wordlist.txt +Use for: Fuzzing for common filepaths of [Oracle E-Business Suite](https://www.oracle.com/applications/ebusiness/) (EBS) version 11. + +EBS v11 exposes: +- usernames +- ports +- OS information +- protocol information +- Unauthenticated file upload +- Cookie contents +- SHA-1 hashed passwords + +As an Unauthenticated user it's also possible to: +- Create forms +- Get servlets status +- Get certain configuration files + +Reference: https://the-infosec.com/2017/03/29/do-you-know-what-your-erp-is-telling-us/ + +Date of last update: Oct 7, 2019 \ No newline at end of file diff --git a/Discovery/Web-Content/README.md b/Discovery/Web-Content/README.md index 6cd7158b..ca3849cd 100644 --- a/Discovery/Web-Content/README.md +++ b/Discovery/Web-Content/README.md @@ -1,10 +1,5 @@ # Web discovery wordlists -## AdobeCQ-AEM.txt -Use for: Discovering sensitive filepaths of **Adobe Experience Manager** -Creation date: Oct 1, 2017 -No updates have been made to this wordlist since its creation. - ## AdobeXML.fuzz.txt Use for: Discovering sensitive filepaths of **Adobe ColdFusion**