2023-01-23 05:03:27 +00:00
id : sound4-directory-listing
info :
2023-01-23 05:36:13 +00:00
name : SOUND4 Impact/Pulse/First/Eco <=2.x - Information Disclosure
2023-01-23 05:03:27 +00:00
author : arafatansari
severity : medium
description : |
The application is vulnerable to sensitive directory indexing / information disclosure vulnerability. An unauthenticated attacker can visit the log directory and disclose the server's log files containing sensitive and system information.
reference :
- https://packetstormsecurity.com/files/170259/SOUND4-IMPACT-FIRST-PULSE-Eco-2.x-Information-Disclosure.html
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5732.php
metadata :
verified : true
2023-10-14 11:27:55 +00:00
max-request : 1
2023-01-23 05:36:13 +00:00
shodan-query : http.html:"SOUND4"
2023-01-23 07:48:36 +00:00
tags : misconfig,listing,sound4,disclosure,packetstorm
2023-01-23 05:03:27 +00:00
2023-04-27 04:28:59 +00:00
http :
2023-01-23 05:03:27 +00:00
- method : GET
path :
- "{{BaseURL}}/log/"
matchers-condition : and
matchers :
- type : word
words :
- "<title>Index of /log</title>"
- "Parent Directory"
condition : and
- type : status
status :
- 200