From 221d36e2c3c2835eb9765bd98837375ba74640f0 Mon Sep 17 00:00:00 2001 From: Dhiyaneshwaran Date: Tue, 10 Oct 2023 13:24:26 +0530 Subject: [PATCH] Create psalm-config.yaml --- http/exposures/configs/psalm-config.yaml | 42 ++++++++++++++++++++++++ 1 file changed, 42 insertions(+) create mode 100644 http/exposures/configs/psalm-config.yaml diff --git a/http/exposures/configs/psalm-config.yaml b/http/exposures/configs/psalm-config.yaml new file mode 100644 index 0000000000..f5d9420160 --- /dev/null +++ b/http/exposures/configs/psalm-config.yaml @@ -0,0 +1,42 @@ +id: psalm-config + +info: + name: Psalm Configuration Exposure - Detect + author: DhiyaneshDK + severity: low + description: | + Psalm configuration page was detected. + reference: + - https://psalm.dev/docs/running_psalm/configuration/ + classification: + cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N + cvss-score: 0.0 + cwe-id: CWE-200 + metadata: + max-request: 1 + verified: true + shodan-query: html:"psalm.xml" + tags: devops,exposure,php,psalm,config + +http: + - method: GET + path: + - "{{BaseURL}}/psalm.xml" + + matchers-condition: and + matchers: + - type: word + part: body + words: + - '