nuclei-templates/http/misconfiguration/aem/aem-default-get-servlet.yaml

94 lines
3.3 KiB
YAML
Raw Normal View History

2021-04-13 08:48:34 +00:00
id: aem-default-get-servlet
2021-04-13 08:48:34 +00:00
info:
name: AEM DefaultGetServlet
author: DhiyaneshDk
2021-04-13 08:48:34 +00:00
severity: low
2022-03-12 08:40:53 +00:00
description: Sensitive information might be exposed via AEM DefaultGetServlet.
reference:
- https://speakerdeck.com/0ang3el/hunting-for-security-bugs-in-aem-webapps?slide=43
- https://github.com/thomashartm/burp-aem-scanner/blob/master/src/main/java/burp/actions/dispatcher/GetServletExposed.java
2022-07-26 03:37:49 +00:00
metadata:
shodan-query: http.component:"Adobe Experience Manager"
2022-03-12 08:40:53 +00:00
tags: aem,adobe
2021-04-13 08:48:34 +00:00
http:
2021-04-13 08:48:34 +00:00
- method: GET
path:
2022-03-12 08:40:53 +00:00
- '{{BaseURL}}/etc'
- '{{BaseURL}}/var'
- '{{BaseURL}}/apps'
- '{{BaseURL}}/home'
- '{{BaseURL}}///etc'
- '{{BaseURL}}///var'
- '{{BaseURL}}///apps'
- '{{BaseURL}}///home'
2021-04-13 08:48:34 +00:00
- '{{BaseURL}}/.json'
- '{{BaseURL}}/.1.json'
- '{{BaseURL}}/....4.2.1....json'
- '{{BaseURL}}/.json?FNZ.css'
- '{{BaseURL}}/.json?FNZ.ico'
- '{{BaseURL}}/.json?FNZ.html'
- '{{BaseURL}}/.json/FNZ.css'
- '{{BaseURL}}/.json/FNZ.html'
- '{{BaseURL}}/.json/FNZ.png'
- '{{BaseURL}}/.json/FNZ.ico'
- '{{BaseURL}}/.children.1.json'
- '{{BaseURL}}/.children....4.2.1....json'
- '{{BaseURL}}/.children.json?FNZ.css'
- '{{BaseURL}}/.children.json?FNZ.ico'
- '{{BaseURL}}/.children.json?FNZ.html'
- '{{BaseURL}}/.children.json/FNZ.css'
- '{{BaseURL}}/.children.json/FNZ.html'
- '{{BaseURL}}/.children.json/FNZ.png'
- '{{BaseURL}}/.children.json/FNZ.ico'
- '{{BaseURL}}/etc.json'
- '{{BaseURL}}/etc.1.json'
- '{{BaseURL}}/etc....4.2.1....json'
- '{{BaseURL}}/etc.json?FNZ.css'
- '{{BaseURL}}/etc.json?FNZ.ico'
- '{{BaseURL}}/etc.json?FNZ.html'
- '{{BaseURL}}/etc.json/FNZ.css'
- '{{BaseURL}}/etc.json/FNZ.html'
- '{{BaseURL}}/etc.json/FNZ.ico'
- '{{BaseURL}}/etc.children.json'
- '{{BaseURL}}/etc.children.1.json'
- '{{BaseURL}}/etc.children....4.2.1....json'
- '{{BaseURL}}/etc.children.json?FNZ.css'
- '{{BaseURL}}/etc.children.json?FNZ.ico'
- '{{BaseURL}}/etc.children.json?FNZ.html'
- '{{BaseURL}}/etc.children.json/FNZ.css'
- '{{BaseURL}}/etc.children.json/FNZ.html'
- '{{BaseURL}}/etc.children.json/FNZ.png'
- '{{BaseURL}}/etc.children.json/FNZ.ico'
- '{{BaseURL}}///etc.json'
- '{{BaseURL}}///etc.1.json'
- '{{BaseURL}}///etc....4.2.1....json'
- '{{BaseURL}}///etc.json?FNZ.css'
- '{{BaseURL}}///etc.json?FNZ.ico'
- '{{BaseURL}}///etc.json/FNZ.html'
- '{{BaseURL}}///etc.json/FNZ.png'
- '{{BaseURL}}///etc.json/FNZ.ico'
- '{{BaseURL}}///etc.children.json'
- '{{BaseURL}}///etc.children.1.json'
- '{{BaseURL}}///etc.children....4.2.1....json'
- '{{BaseURL}}///etc.children.json?FNZ.css'
- '{{BaseURL}}///etc.children.json?FNZ.ico'
- '{{BaseURL}}///etc.children.json?FNZ.html'
- '{{BaseURL}}///etc.children.json/FNZ.css'
- '{{BaseURL}}///etc.children.json/FNZ.html'
- '{{BaseURL}}///etc.children.json/FNZ.png'
- '{{BaseURL}}///etc.children.json/FNZ.ico'
stop-at-first-match: true
2021-04-13 08:48:34 +00:00
matchers-condition: and
matchers:
- type: status
status:
- 200
- type: word
words:
- 'jcr:createdBy'
condition: and