Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

max_request for multiple yaml templates is not set #10988

Open
pwnhxl opened this issue Oct 10, 2024 · 4 comments · May be fixed by #11146
Open

max_request for multiple yaml templates is not set #10988

pwnhxl opened this issue Oct 10, 2024 · 4 comments · May be fixed by #11146
Assignees
Labels
Done Ready to merge Type: Bug Inconsistencies or issues which will cause an issue or problem for users or implementors.

Comments

@pwnhxl
Copy link
Contributor

pwnhxl commented Oct 10, 2024

Template IDs or paths

  • ...
    [DBG] The expression condition couldn't be evaluated correctly for template "CVE-2024-4577": No parameter 'max_request' found.
    [DBG] The expression condition couldn't be evaluated correctly for template "CVE-2024-34257": No parameter 'max_request' found.
    [DBG] The expression condition couldn't be evaluated correctly for template "CVE-2024-45195": No parameter 'max_request' found.
    [DBG] The expression condition couldn't be evaluated correctly for template "camaleon-default-login": No parameter 'max_request' found.
    [DBG] The expression condition couldn't be evaluated correctly for template "readymade-unilevel-sqli": No parameter 'max_request' found.
    [DBG] The expression condition couldn't be evaluated correctly for template "CVE-2024-37393": No parameter 'max_request' found.
    [DBG] The expression condition couldn't be evaluated correctly for template "CVE-2023-43472": No parameter 'max_request' found.
    [DBG] The expression condition couldn't be evaluated correctly for template "CVE-2024-6646": No parameter 'max_request' found.
    [DBG] The expression condition couldn't be evaluated correctly for template "CVE-2024-6782": No parameter 'max_request' found.
    [DBG] The expression condition couldn't be evaluated correctly for template "prestashop-apmarketplace-sqli": No parameter 'max_request' found.
    [DBG] The expression condition couldn't be evaluated correctly for template "CVE-2024-39914": No parameter 'max_request' found.
    [DBG] The expression condition couldn't be evaluated correctly for template "CVE-2023-41599": No parameter 'max_request' found.
    [DBG] The expression condition couldn't be evaluated correctly for template "apache-hertzbeat-default-login": No parameter 'max_request' found.
    [DBG] The expression condition couldn't be evaluated correctly for template "xinclude-injection": No parameter 'max_request' found.
    [DBG] The expression condition couldn't be evaluated correctly for template "CVE-2019-0232": No parameter 'max_request' found.
    [DBG] The expression condition couldn't be evaluated correctly for template "CVE-2024-6781": No parameter 'max_request' found.
    [DBG] The expression condition couldn't be evaluated correctly for template "CVE-2024-22207": No parameter 'max_request' found.
    [DBG] The expression condition couldn't be evaluated correctly for template "CVE-2023-43662": No parameter 'max_request' found.
    [DBG] The expression condition couldn't be evaluated correctly for template "jellyfin-default-login": No parameter 'max_request' found.
    [DBG] The expression condition couldn't be evaluated correctly for template "CVE-2021-43831": No parameter 'max_request' found.
    [DBG] The expression condition couldn't be evaluated correctly for template "CVE-2024-37843": No parameter 'max_request' found.
    [DBG] The expression condition couldn't be evaluated correctly for template "CVE-2023-46818": No parameter 'max_request' found.
    [DBG] The expression condition couldn't be evaluated correctly for template "next-js-cache-poisoning": No parameter 'max_request' found.
    [DBG] The expression condition couldn't be evaluated correctly for template "CVE-2022-34265": No parameter 'max_request' found.
    [DBG] The expression condition couldn't be evaluated correctly for template "CVE-2024-39250": No parameter 'max_request' found.
    [DBG] The expression condition couldn't be evaluated correctly for template "CVE-2024-6746": No parameter 'max_request' found.
    [DBG] The expression condition couldn't be evaluated correctly for template "CVE-2023-3380": No parameter 'max_request' found.

Environment

  • OS:
  • Nuclei:
  • Go:

Steps To Reproduce

  • ...
    [DBG] The expression condition couldn't be evaluated correctly for template "CVE-2024-4577": No parameter 'max_request' found.
    [DBG] The expression condition couldn't be evaluated correctly for template "CVE-2024-34257": No parameter 'max_request' found.
    [DBG] The expression condition couldn't be evaluated correctly for template "CVE-2024-45195": No parameter 'max_request' found.
    [DBG] The expression condition couldn't be evaluated correctly for template "camaleon-default-login": No parameter 'max_request' found.
    [DBG] The expression condition couldn't be evaluated correctly for template "readymade-unilevel-sqli": No parameter 'max_request' found.
    [DBG] The expression condition couldn't be evaluated correctly for template "CVE-2024-37393": No parameter 'max_request' found.
    [DBG] The expression condition couldn't be evaluated correctly for template "CVE-2023-43472": No parameter 'max_request' found.
    [DBG] The expression condition couldn't be evaluated correctly for template "CVE-2024-6646": No parameter 'max_request' found.
    [DBG] The expression condition couldn't be evaluated correctly for template "CVE-2024-6782": No parameter 'max_request' found.
    [DBG] The expression condition couldn't be evaluated correctly for template "prestashop-apmarketplace-sqli": No parameter 'max_request' found.
    [DBG] The expression condition couldn't be evaluated correctly for template "CVE-2024-39914": No parameter 'max_request' found.
    [DBG] The expression condition couldn't be evaluated correctly for template "CVE-2023-41599": No parameter 'max_request' found.
    [DBG] The expression condition couldn't be evaluated correctly for template "apache-hertzbeat-default-login": No parameter 'max_request' found.
    [DBG] The expression condition couldn't be evaluated correctly for template "xinclude-injection": No parameter 'max_request' found.
    [DBG] The expression condition couldn't be evaluated correctly for template "CVE-2019-0232": No parameter 'max_request' found.
    [DBG] The expression condition couldn't be evaluated correctly for template "CVE-2024-6781": No parameter 'max_request' found.
    [DBG] The expression condition couldn't be evaluated correctly for template "CVE-2024-22207": No parameter 'max_request' found.
    [DBG] The expression condition couldn't be evaluated correctly for template "CVE-2023-43662": No parameter 'max_request' found.
    [DBG] The expression condition couldn't be evaluated correctly for template "jellyfin-default-login": No parameter 'max_request' found.
    [DBG] The expression condition couldn't be evaluated correctly for template "CVE-2021-43831": No parameter 'max_request' found.
    [DBG] The expression condition couldn't be evaluated correctly for template "CVE-2024-37843": No parameter 'max_request' found.
    [DBG] The expression condition couldn't be evaluated correctly for template "CVE-2023-46818": No parameter 'max_request' found.
    [DBG] The expression condition couldn't be evaluated correctly for template "next-js-cache-poisoning": No parameter 'max_request' found.
    [DBG] The expression condition couldn't be evaluated correctly for template "CVE-2022-34265": No parameter 'max_request' found.
    [DBG] The expression condition couldn't be evaluated correctly for template "CVE-2024-39250": No parameter 'max_request' found.
    [DBG] The expression condition couldn't be evaluated correctly for template "CVE-2024-6746": No parameter 'max_request' found.
    [DBG] The expression condition couldn't be evaluated correctly for template "CVE-2023-3380": No parameter 'max_request' found.

Relevant dumped responses

No response

Anything else?

No response

@pwnhxl pwnhxl added the false-negative Nuclei template missing valid results label Oct 10, 2024
@DhiyaneshGeek
Copy link
Member

Hi @pwnhxl

Can you share me the command that is used to replicate this issue ?

Thanks

@pwnhxl
Copy link
Contributor Author

pwnhxl commented Nov 2, 2024

Forget I just wanted to say that these templates don't have max_request set so you can't filter templates using -tc 'max_request <= 5'

For example, camaleon-default-login max_request is less than 5 but is not listed

nuclei -tc 'max_request <= 5' -tags camaleon -tl


______ ____/ / ()

/ __ / / / / ___/ / _ / /

/ / / / /_/ / // // /

// //_,/_/_/_/_/ v3.3.5

projectdiscovery.io

Listing available v10.0.3 nuclei templates for /root/nuclei-templates

http/cves/2024/CVE-2024-46986.yaml

@pwnhxl
Copy link
Contributor Author

pwnhxl commented Nov 2, 2024

nuclei -tc 'max_request <= 5' -tags camaleon -tl -debug

                     __     _
   ____  __  _______/ /__  (_)
  / __ \/ / / / ___/ / _ \/ /
 / / / / /_/ / /__/ /  __/ /
/_/ /_/\__,_/\___/_/\___/_/   v3.3.5

		projectdiscovery.io

[DBG] The expression condition couldn't be evaluated correctly for template "camaleon-panel": No parameter 'max_request' found.
[DBG] The expression condition couldn't be evaluated correctly for template "camaleon-default-login": No parameter 'max_request' found.

Listing available v10.0.3 nuclei templates for /root/nuclei-templates
http/cves/2024/CVE-2024-46986.yaml

@DhiyaneshGeek DhiyaneshGeek added Type: Bug Inconsistencies or issues which will cause an issue or problem for users or implementors. Done Ready to merge and removed false-negative Nuclei template missing valid results labels Nov 5, 2024
@DhiyaneshGeek DhiyaneshGeek linked a pull request Nov 5, 2024 that will close this issue
2 tasks
@DhiyaneshGeek
Copy link
Member

Hi @pwnhxl

i have updated the templates, which had missing max-request , let me know if these changes looks good

Thanks for flagging this issue 😄

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Done Ready to merge Type: Bug Inconsistencies or issues which will cause an issue or problem for users or implementors.
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants