Files
nuclei-templates/misconfiguration/tomcat-scripts.yaml
Sandeep Singh de9c4d605c Apache Tomcat Template improvements (#3446)
* Improved Tomcat matchers / extractors / paths

* removed duplicate detections / matchers

* removed duplicate template

* Added missing tomcat tags
2021-12-29 19:10:59 +05:30

27 lines
658 B
YAML

id: tomcat-scripts
info:
name: Detect Tomcat Exposed Scripts
author: Co0nan
severity: info
tags: apache,tomcat
requests:
- method: GET
path:
- "{{BaseURL}}/examples/servlets/index.html"
- "{{BaseURL}}/examples/jsp/index.html"
- "{{BaseURL}}/examples/websocket/index.xhtml"
- "{{BaseURL}}/..;/examples/servlets/index.html"
- "{{BaseURL}}/..;/examples/jsp/index.html"
- "{{BaseURL}}/..;/examples/websocket/index.xhtml"
matchers:
- type: word
words:
- "JSP Examples"
- "JSP Samples"
- "Servlets Examples"
- "WebSocket Examples"
condition: or