nuclei-templates/http/exposures/configs/phpinfo-files.yaml

71 lines
1.8 KiB
YAML
Raw Permalink Normal View History

2020-04-04 18:19:48 +00:00
id: phpinfo-files
info:
name: PHPinfo Page - Detect
2023-12-31 16:09:36 +00:00
author: pdteam,daffainfo,meme-lord,dhiyaneshDK,wabafet,mastercho
2023-03-17 16:49:35 +00:00
severity: low
description: |
PHPinfo page was detected. The output of the phpinfo() command can reveal sensitive and detailed PHP environment information.
2023-03-17 16:49:35 +00:00
remediation: Remove PHP Info pages from publicly accessible sites, or restrict access to authorized users only.
2023-03-02 20:58:29 +00:00
classification:
cwe-id: CWE-200
metadata:
max-request: 25
tags: config,exposure,phpinfo
2020-04-04 18:19:48 +00:00
http:
2020-04-04 18:19:48 +00:00
- method: GET
2020-05-25 08:02:27 +00:00
path:
- "{{BaseURL}}{{paths}}"
payloads:
paths:
- "/php.php"
- "/php2.php"
- "/phpinfo.php"
- "/info.php"
- "/infophp.php"
- "/php_info.php"
- "/test.php"
- "/i.php"
2024-09-28 11:53:47 +00:00
- "/a.php"
- "/p.php"
- "/pi.php"
- "/asdf.php"
- "/pinfo.php"
- "/phpversion.php"
- "/time.php"
2024-09-26 05:02:14 +00:00
- "/inf0.php"
- "/index.php"
- "/temp.php"
- "/old_phpinfo.php"
- "/infos.php"
- "/linusadmin-phpinfo.php"
- "/php-info.php"
- "/dashboard/phpinfo.php"
- "/_profiler/phpinfo.php"
- "/_profiler/phpinfo"
- "/?phpinfo=1"
- "/l.php?act=phpinfo"
2021-09-17 07:50:06 +00:00
stop-at-first-match: true
2023-10-14 11:27:55 +00:00
matchers-condition: and
2020-04-04 18:19:48 +00:00
matchers:
- type: word
part: body
2020-05-25 08:02:27 +00:00
words:
2020-04-04 18:19:48 +00:00
- "PHP Extension"
- "PHP Version"
condition: and
- type: status
status:
- 200
extractors:
- type: regex
part: body
group: 1
regex:
2021-09-17 07:50:06 +00:00
- '>PHP Version <\/td><td class="v">([0-9.]+)'
2024-10-04 11:32:41 +00:00
# digest: 490a0046304402207abcbc13ec5b9284e67a831e54e5a987cb3641c78280bf59e6d18084ecf1a872022035e8ebcffb3074c0dd3a8b07d814f25d57645b748c3c33ef12195e2dbcf51daf:922c64590222798bb761d5b6d8e72950