Files
nuclei-templates/http/technologies/wordpress/plugins/flexmls-detect.yaml
Prince Chaddha 0474fff656 Merge pull request #13648 from matejsmycka/discovery-vuln-distinc
[BULK EDIT]  Implement asset-discovery and vulnerability detection distinction
2025-10-24 19:21:52 +05:30

48 lines
1.2 KiB
YAML

id: flexmls-idx-detect
info:
name: Flexmls IDX - Detect
author: rxerium,sorrowx3
severity: info
metadata:
verified: true
max-request: 1
shodan-query: html:"/wp-content/plugins/flexmls-idx"
tags: tech,detect,flexmls,idx,discovery
http:
- method: GET
path:
- "{{BaseURL}}/wp-content/plugins/flexmls-idx/readme.txt"
payloads:
last_version: helpers/wordpress/plugins/flexmls-idx.txt
extractors:
- type: regex
part: body
internal: true
name: internal_detected_version
group: 1
regex:
- '(?i)Stable.tag:\s?([\w.]+)'
- type: regex
part: body
name: detected_version
group: 1
regex:
- '(?i)Stable.tag:\s?([\w.]+)'
matchers-condition: or
matchers:
- type: dsl
name: "outdated_version"
dsl:
- compare_versions(internal_detected_version, concat("< ", last_version))
- type: regex
part: body
regex:
- '(?i)Stable.tag:\s?([\w.]+)'
# digest: 4a0a00473045022100a1dca7d50fd8292bb5b8df9bd810ea03f2cf5bad3f841be5a93620ee318efe7202206d81d2e8a218d8d90221b9c6f11298aff80b3d3858a257ce640d7bc3a9fb7c00:922c64590222798bb761d5b6d8e72950