nuclei-templates/http/exposures/configs/phpinfo-files.yaml

71 lines
1.8 KiB
YAML
Raw Normal View History

2020-04-04 18:19:48 +00:00
id: phpinfo-files
info:
name: PHPinfo Page - Detect
2023-12-31 16:09:36 +00:00
author: pdteam,daffainfo,meme-lord,dhiyaneshDK,wabafet,mastercho
2023-03-17 16:49:35 +00:00
severity: low
description: |
PHPinfo page was detected. The output of the phpinfo() command can reveal sensitive and detailed PHP environment information.
2023-03-17 16:49:35 +00:00
remediation: Remove PHP Info pages from publicly accessible sites, or restrict access to authorized users only.
2023-03-02 20:58:29 +00:00
classification:
cwe-id: CWE-200
metadata:
max-request: 25
tags: config,exposure,phpinfo
2020-04-04 18:19:48 +00:00
http:
2020-04-04 18:19:48 +00:00
- method: GET
2020-05-25 08:02:27 +00:00
path:
- "{{BaseURL}}{{paths}}"
payloads:
paths:
- "/php.php"
- "/php2.php"
- "/phpinfo.php"
- "/info.php"
- "/infophp.php"
- "/php_info.php"
- "/test.php"
- "/i.php"
2024-09-28 11:53:47 +00:00
- "/a.php"
- "/p.php"
- "/pi.php"
- "/asdf.php"
- "/pinfo.php"
- "/phpversion.php"
- "/time.php"
2024-09-26 05:02:14 +00:00
- "/inf0.php"
- "/index.php"
- "/temp.php"
- "/old_phpinfo.php"
- "/infos.php"
- "/linusadmin-phpinfo.php"
- "/php-info.php"
- "/dashboard/phpinfo.php"
- "/_profiler/phpinfo.php"
- "/_profiler/phpinfo"
- "/?phpinfo=1"
- "/l.php?act=phpinfo"
2021-09-17 07:50:06 +00:00
stop-at-first-match: true
2023-10-14 11:27:55 +00:00
matchers-condition: and
2020-04-04 18:19:48 +00:00
matchers:
- type: word
part: body
2020-05-25 08:02:27 +00:00
words:
2020-04-04 18:19:48 +00:00
- "PHP Extension"
- "PHP Version"
condition: and
- type: status
status:
- 200
extractors:
- type: regex
part: body
group: 1
regex:
2021-09-17 07:50:06 +00:00
- '>PHP Version <\/td><td class="v">([0-9.]+)'
2024-09-26 05:37:30 +00:00
# digest: 490a0046304402206ad6f443ffbaace771aec5f22f010b026d133fb7ffa59fff136813d63f853da502200cdd41c804a2ce73444bdc4494fe0e82c8c728b2a092c2d223661ed083fe7ffa:922c64590222798bb761d5b6d8e72950