mirror of
https://github.com/projectdiscovery/nuclei-templates.git
synced 2026-02-03 01:03:34 +08:00
42 lines
1.2 KiB
YAML
42 lines
1.2 KiB
YAML
id: phpwind-installer
|
||
|
||
info:
|
||
name: phpwind Installer Exposure
|
||
author: tess
|
||
severity: high
|
||
description: phpwind is susceptible to the Installation page exposure due to misconfiguration.
|
||
classification:
|
||
cpe: cpe:2.3:a:phpwind:phpwind:*:*:*:*:*:*:*:*
|
||
metadata:
|
||
verified: true
|
||
max-request: 1
|
||
vendor: phpwind
|
||
product: phpwind
|
||
shodan-query: title:"Powered by phpwind"
|
||
tags: misconfig,phpwind,exposure,install
|
||
|
||
http:
|
||
- method: GET
|
||
path:
|
||
- '{{BaseURL}}/install.php?a=check'
|
||
|
||
matchers-condition: and
|
||
matchers:
|
||
- type: word
|
||
part: body
|
||
words:
|
||
- 'Powered by phpwind</title>'
|
||
- '安装'
|
||
condition: and
|
||
|
||
- type: word
|
||
part: body
|
||
words:
|
||
- "You have installed. To reinstall, you need to clear the data/install.lock file"
|
||
- "您已经安装过,需要重新安装请先删除data/install.lock文件"
|
||
negative: true
|
||
|
||
- type: status
|
||
status:
|
||
- 200
|
||
# digest: 4a0a0047304502200531bf7338c43d41f3b7b091365e403078f0431e895efa4c2b10b844e055c259022100ca4b96129bc0e41ffa172788646735c2fa5aa865a67e2284e9e0c05ad2662ec6:922c64590222798bb761d5b6d8e72950 |