nuclei-templates/exposures/configs/configuration-listing.yaml

30 lines
663 B
YAML
Raw Normal View History

id: configuration-listing
info:
name: Sensitive Configuration Files Listing - Detect
author: j33n1k4
severity: medium
description: Listing of sensitive configuration files containing items such as usernames, passwords, and IP addresses was detected.
reference:
- https://www.exploit-db.com/ghdb/7014
tags: config,listing,exposure
requests:
- method: GET
path:
- "{{BaseURL}}/config/"
matchers-condition: and
matchers:
- type: word
words:
- "Index of /configs"
- "Parent Directory"
condition: and
- type: status
status:
- 200
# Enhanced by md on 2023/02/09