PR
feat: add CVE-2018-8581 template
projectdiscovery/nuclei-templates#14911

/claim #14576

PR Information

Template validation

  • Validated with a host running a vulnerable version and/or configuration (True Positive)
  • Validated with a host running a patched version and/or configuration (avoid False Positive)

Additional Details (leave it blank if not applicable)

  • Template path: http/cves/2018/CVE-2018-8581.yaml
  • Validation command:
    nuclei -duc -validate -lfa -ud . -t http/cves/2018/CVE-2018-8581.yaml
  • Detection logic:

    • Precheck confirms Exchange EWS exposure using /EWS/Exchange.asmx and X-Owa-Version
    • Authenticated SOAP Subscribe PushSubscription request triggers outbound request to {{interactsh-url}}
    • Confirms SSRF via OAST (interactsh_protocol + interactsh_request) and success SOAP response markers

Claim

Total prize pool $100
Total paid $0
Status Pending
Submitted January 16, 2026
Last updated January 16, 2026

Contributors

VA

Vara Rahul Rajana

@rajanarahul93

100%

Sponsors

PR

ProjectDiscovery

@projectdiscovery

$100