Blast from The Past

Introduction

Arbitrary File Reading leads to RCE in the Pulse Secure SSL VPN by "sp1d3rs"

The following CVEs affect the VPN:

Does 'nuclei' have these CVEs?

It DOES! Here it is!

That's amazing. Looks like we could have found this if we just ran nuclei on the target.

Unfortunately, the Department of Defense (DoD) bug bounty program redacts the affected endpoints. Therefore, there's no way to know which endpoint it was.

Maybe, we could leverage Shodan?