diff --git a/misconfiguration/unauthenticated-nginx-dashboard.yaml b/misconfiguration/unauthenticated-nginx-dashboard.yaml new file mode 100644 index 00000000000..142321c8ebf --- /dev/null +++ b/misconfiguration/unauthenticated-nginx-dashboard.yaml @@ -0,0 +1,27 @@ +id: unauthenticated-nginx-dashboard + +info: + name: Nginx Dashboard + author: BibekSapkota (sar00n) + severity: low + reference: + - https://www.acunetix.com/vulnerabilities/web/unrestricted-access-to-nginx-dashboard/ + metadata: + shpdan-query: html:"NGINX+ Dashboard" + tags: misconfig,nginx + +requests: + - method: GET + path: + - "{{BaseURL}}/dashboard.html" + + max-size: 2048 + matchers-condition: and + matchers: + - type: word + words: + - 'Nginx+ Dashboard' + + - type: status + status: + - 200