diff --git a/Discovery/Web-Content/Oracle-EBS-wordlist.txt b/Discovery/Web-Content/CMS/Oracle-EBS-wordlist.txt similarity index 100% rename from Discovery/Web-Content/Oracle-EBS-wordlist.txt rename to Discovery/Web-Content/CMS/Oracle-EBS-wordlist.txt diff --git a/Discovery/Web-Content/README.md b/Discovery/Web-Content/README.md index ca3849cd..cf4596e6 100644 --- a/Discovery/Web-Content/README.md +++ b/Discovery/Web-Content/README.md @@ -110,34 +110,4 @@ References: Use for: Fuzzing for common filepaths in webpages designed with **[Microsoft Frontpage](https://en.wikipedia.org/wiki/Microsoft_FrontPage)** Year of the first release of Microsoft Frontpage: 1997 -Year of the last release of Microsoft Frontpage: 2003 - -## Oracle-EBS-wordlist.txt -Use for: Fuzzing for common filepaths of [Oracle E-Business Suite](https://www.oracle.com/applications/ebusiness/) (EBS) version 11. - -EBS v11 exposes: -- usernames -- ports -- OS information -- protocol information -- Unauthenticated file upload -- Cookie contents -- SHA-1 hashed passwords - -As an Unauthenticated user it's also possible to: -- Create forms -- Get servlets status -- Get certain configuration files - -Reference: https://the-infosec.com/2017/03/29/do-you-know-what-your-erp-is-telling-us/ - -Date of last update: Oct 7, 2019 - - -## iis-systemweb.txt -Use for: Fuzzing the `/aspnet_client/system_web/` directory on [Microsoft IIS](https://www.iis.net/) servers to detect **CGIs** and **scripts** even even if the two ladder directories are inaccessible. - -Reference: https://github.com/irsdl/IIS-ShortName-Scanner -Discussion: https://github.com/danielmiessler/SecLists/pull/783 - -Date of last update: Jun 27, 2022 +Year of the last release of Microsoft Frontpage: 2003 \ No newline at end of file