Merge pull request #7344 from ErikOwen/patch/tag-standardization

Patch: Tag Standardization
patch-1
Prince Chaddha 2023-07-04 13:10:55 +05:30 committed by GitHub
commit 50d86c25a1
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
228 changed files with 228 additions and 228 deletions

View File

@ -9,7 +9,7 @@ info:
- https://enterprise.arcgis.com/en/ - https://enterprise.arcgis.com/en/
classification: classification:
cwe-id: CWE-200 cwe-id: CWE-200
tags: api,arcgis,cms tags: api,arcgis,cms,panel
metadata: metadata:
max-request: 1 max-request: 1

View File

@ -7,7 +7,7 @@ info:
description: AVTECH AVC798HA DVR is susceptible to information exposure. CGI scripts in the /cgi-bin/nobody directory can be accessed without authentication. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized operations. description: AVTECH AVC798HA DVR is susceptible to information exposure. CGI scripts in the /cgi-bin/nobody directory can be accessed without authentication. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized operations.
reference: reference:
- http://www.avtech.com.tw/ - http://www.avtech.com.tw/
tags: dvr,exposure,avtech tags: dvr,exposure,avtech,panel
metadata: metadata:
max-request: 1 max-request: 1

View File

@ -10,7 +10,7 @@ info:
max-request: 1 max-request: 1
verified: true verified: true
shodan-query: html:"AWS EC2 Auto Scaling Lab" shodan-query: html:"AWS EC2 Auto Scaling Lab"
tags: exposure,ec2,aws,amazon tags: exposure,ec2,aws,amazon,panel
http: http:
- method: GET - method: GET

View File

@ -12,7 +12,7 @@ info:
max-request: 1 max-request: 1
shodan-query: http.html_hash:-1957161625 shodan-query: http.html_hash:-1957161625
verified: "true" verified: "true"
tags: c2,bruteratel,c4 tags: c2,bruteratel,c4,panel
http: http:
- method: GET - method: GET

View File

@ -12,7 +12,7 @@ info:
max-request: 1 max-request: 1
verified: true verified: true
shodan-query: ssl:”Covenant” http.component:”Blazor” shodan-query: ssl:”Covenant” http.component:”Blazor”
tags: c2,ir,osint,covenant tags: c2,ir,osint,covenant,panel
http: http:
- method: GET - method: GET

View File

@ -12,7 +12,7 @@ info:
max-request: 1 max-request: 1
verified: true verified: true
shodan-query: http.html_hash:-14029177 shodan-query: http.html_hash:-14029177
tags: c2,ir,osint,deimosc2 tags: c2,ir,osint,deimosc2,panel
http: http:
- method: GET - method: GET

View File

@ -13,7 +13,7 @@ info:
censys-query: bc517bf173440dad15b99a051389fadc366d5df2 || dcb32e6256459d3660fdc90e4c79e95a921841cc censys-query: bc517bf173440dad15b99a051389fadc366d5df2 || dcb32e6256459d3660fdc90e4c79e95a921841cc
max-request: 1 max-request: 1
verified: "true" verified: "true"
tags: c2,ir,osint,empire tags: c2,ir,osint,empire,panel
http: http:
- method: GET - method: GET

View File

@ -12,7 +12,7 @@ info:
censys-query: b18d778b4e4b6bf1fd5b2d790c941270145a6a6d censys-query: b18d778b4e4b6bf1fd5b2d790c941270145a6a6d
max-request: 1 max-request: 1
verified: "true" verified: "true"
tags: tech,evilginx,c2,phishing tags: tech,evilginx,c2,phishing,panel
http: http:
- method: GET - method: GET

View File

@ -13,7 +13,7 @@ info:
max-request: 1 max-request: 1
verified: true verified: true
shodan-query: 'ssl:Mythic port:7443' shodan-query: 'ssl:Mythic port:7443'
tags: c2,ir,osint,mythic tags: c2,ir,osint,mythic,panel
http: http:
- method: GET - method: GET

View File

@ -10,7 +10,7 @@ info:
censys-query: 10baf5fcdde4563d3e145a1f553ae433fb1c3572 censys-query: 10baf5fcdde4563d3e145a1f553ae433fb1c3572
max-request: 1 max-request: 1
verified: "true" verified: "true"
tags: tech,nh,c2 tags: tech,nh,c2,panel
http: http:
- method: GET - method: GET

View File

@ -13,7 +13,7 @@ info:
max-request: 1 max-request: 1
shodan-query: http.html_hash:1015055567 shodan-query: http.html_hash:1015055567
verified: "true" verified: "true"
tags: tech,viper,c2,malware,ir tags: tech,viper,c2,malware,ir,panel
http: http:
- method: GET - method: GET

View File

@ -11,7 +11,7 @@ info:
cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N
cvss-score: 0.0 cvss-score: 0.0
cwe-id: CWE-200 cwe-id: CWE-200
tags: tech,cacti,login tags: tech,cacti,login,panel
metadata: metadata:
max-request: 2 max-request: 2

View File

@ -9,7 +9,7 @@ info:
cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N
cvss-score: 0.0 cvss-score: 0.0
cwe-id: CWE-200 cwe-id: CWE-200
tags: login,tech,synology,rackstation tags: login,tech,synology,rackstation,panel
metadata: metadata:
max-request: 1 max-request: 1

View File

@ -10,7 +10,7 @@ info:
max-request: 1 max-request: 1
verified: true verified: true
shodan-query: html:"Crontab UI" shodan-query: html:"Crontab UI"
tags: exposure,crontab,ui tags: exposure,crontab,ui,panel
http: http:
- method: GET - method: GET

View File

@ -9,7 +9,7 @@ info:
cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N
cvss-score: 0.0 cvss-score: 0.0
cwe-id: CWE-200 cwe-id: CWE-200
tags: login,tech,edgeos,edgemax tags: login,tech,edgeos,edgemax,panel
metadata: metadata:
max-request: 1 max-request: 1

View File

@ -10,7 +10,7 @@ info:
max-request: 2 max-request: 2
verified: true verified: true
shodan-query: title:"EOS HTTP Browser" shodan-query: title:"EOS HTTP Browser"
tags: exposure,eos,httpbrowser tags: exposure,eos,httpbrowser,panel
http: http:
- method: GET - method: GET

View File

@ -14,7 +14,7 @@ info:
max-request: 2 max-request: 2
verified: true verified: true
shodan-query: title:"Mailing Lists" shodan-query: title:"Mailing Lists"
tags: exposure,mailman tags: exposure,mailman,panel
http: http:
- method: GET - method: GET

View File

@ -9,7 +9,7 @@ info:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N
cvss-score: 0.0 cvss-score: 0.0
cwe-id: CWE-200 cwe-id: CWE-200
tags: tech,consul,api tags: tech,consul,api,panel
metadata: metadata:
max-request: 1 max-request: 1

View File

@ -11,7 +11,7 @@ info:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N
cvss-score: 0.0 cvss-score: 0.0
cwe-id: CWE-200 cwe-id: CWE-200
tags: tech,konga,oss tags: tech,konga,oss,panel
metadata: metadata:
max-request: 1 max-request: 1

View File

@ -12,7 +12,7 @@ info:
metadata: metadata:
max-request: 1 max-request: 1
fofa-query: app="Kubernetes-Enterprise-Manager" fofa-query: app="Kubernetes-Enterprise-Manager"
tags: tech,kubernetes tags: tech,kubernetes,panel
http: http:
- method: GET - method: GET

View File

@ -14,7 +14,7 @@ info:
verified: true verified: true
shodan-query: http.html:"Mirantis Kubernetes Engine" shodan-query: http.html:"Mirantis Kubernetes Engine"
fofa-query: app="Mirantis-Kubernetes-Engine" fofa-query: app="Mirantis-Kubernetes-Engine"
tags: tech,kubernetes,devops,kube,k8s tags: tech,kubernetes,devops,kube,k8s,panel
http: http:
- method: GET - method: GET

View File

@ -14,7 +14,7 @@ info:
max-request: 1 max-request: 1
verified: true verified: true
shodan-query: http.favicon.hash:-379154636 shodan-query: http.favicon.hash:-379154636
tags: exposure,k8s,kubernetes,kubeview,dashboard tags: exposure,k8s,kubernetes,kubeview,dashboard,panel
http: http:
- method: GET - method: GET

View File

@ -13,7 +13,7 @@ info:
max-request: 1 max-request: 1
verified: true verified: true
shodan-query: http.component:"Magento" shodan-query: http.component:"Magento"
tags: magento,exposure tags: magento,exposure,panel
http: http:
- method: GET - method: GET

View File

@ -11,7 +11,7 @@ info:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N
cvss-score: 0.0 cvss-score: 0.0
cwe-id: CWE-200 cwe-id: CWE-200
tags: tech,mautic,crm tags: tech,mautic,crm,panel
metadata: metadata:
max-request: 1 max-request: 1

View File

@ -12,7 +12,7 @@ info:
metadata: metadata:
max-request: 1 max-request: 1
shodan-query: http.title:"Neo4j Browser" shodan-query: http.title:"Neo4j Browser"
tags: neo4j,exposure,unauth tags: neo4j,exposure,unauth,panel
http: http:
- method: GET - method: GET

View File

@ -10,7 +10,7 @@ info:
metadata: metadata:
max-request: 2 max-request: 2
shodan-query: http.title:"OpenWrt - LuCI" shodan-query: http.title:"OpenWrt - LuCI"
tags: openwrt,router tags: openwrt,router,panel
http: http:
- method: GET - method: GET

View File

@ -10,7 +10,7 @@ info:
max-request: 1 max-request: 1
verified: true verified: true
shodan-query: html:"PDI Intellifuel" shodan-query: html:"PDI Intellifuel"
tags: exposure,pdi,intellifuel tags: exposure,pdi,intellifuel,panel
http: http:
- method: GET - method: GET

View File

@ -4,7 +4,7 @@ info:
name: Pulse Secure Version name: Pulse Secure Version
author: dadevel author: dadevel
severity: info severity: info
tags: pulse tags: pulse,panel
metadata: metadata:
max-request: 2 max-request: 2

View File

@ -13,7 +13,7 @@ info:
max-request: 4 max-request: 4
verified: true verified: true
google-query: intitle:"Roxy file manager" google-query: intitle:"Roxy file manager"
tags: tech,fileupload,roxy,fileman tags: tech,fileupload,roxy,fileman,panel
http: http:
- method: GET - method: GET

View File

@ -4,7 +4,7 @@ info:
name: Synology RackStation Login Detect name: Synology RackStation Login Detect
author: princechaddha author: princechaddha
severity: info severity: info
tags: login,tech,synology,rackstation tags: login,tech,synology,rackstation,panel
metadata: metadata:
max-request: 1 max-request: 1

View File

@ -7,7 +7,7 @@ info:
metadata: metadata:
max-request: 1 max-request: 1
shodan-query: title:"Apache Tomcat" shodan-query: title:"Apache Tomcat"
tags: version,tomcat,docs tags: version,tomcat,docs,panel
http: http:
- method: GET - method: GET

View File

@ -10,7 +10,7 @@ info:
max-request: 1 max-request: 1
verified: true verified: true
shodan-query: http.favicon.hash:824580113 shodan-query: http.favicon.hash:824580113
tags: exposure,login,tup,openframe tags: exposure,login,tup,openframe,panel
http: http:
- method: GET - method: GET

View File

@ -8,7 +8,7 @@ info:
max-request: 1 max-request: 1
verified: true verified: true
shodan-query: http.html:"VMG1312-B10D" shodan-query: http.html:"VMG1312-B10D"
tags: tech,zyxel,modem,router tags: tech,zyxel,modem,router,panel
http: http:
- method: GET - method: GET

View File

@ -8,7 +8,7 @@ info:
max-request: 1 max-request: 1
verified: true verified: true
shodan-query: http.html:"VSG1432-B101" shodan-query: http.html:"VSG1432-B101"
tags: tech,zyxel,modem,router tags: tech,zyxel,modem,router,panel
http: http:
- method: GET - method: GET

View File

@ -13,7 +13,7 @@ info:
metadata: metadata:
max-request: 1 max-request: 1
shodan-query: http.title:"Welcome to your Strapi app" shodan-query: http.title:"Welcome to your Strapi app"
tags: api,strapi tags: api,strapi,exposure
http: http:
- method: GET - method: GET

View File

@ -11,7 +11,7 @@ info:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N
cvss-score: 0.0 cvss-score: 0.0
cwe-id: CWE-200 cwe-id: CWE-200
tags: azure,microsoft,cloud tags: azure,microsoft,cloud,exposure
metadata: metadata:
max-request: 1 max-request: 1

View File

@ -7,7 +7,7 @@ info:
description: eSMTP configuration was discovered. description: eSMTP configuration was discovered.
reference: reference:
- https://linux.die.net/man/5/esmtprc - https://linux.die.net/man/5/esmtprc
tags: esmtp,config tags: esmtp,config,exposure
metadata: metadata:
max-request: 1 max-request: 1

View File

@ -10,7 +10,7 @@ info:
max-request: 8 max-request: 8
verified: true verified: true
shodan-query: html:"JK Status Manager" shodan-query: html:"JK Status Manager"
tags: config,jk,status tags: config,jk,status,exposure
http: http:
- method: GET - method: GET

View File

@ -11,7 +11,7 @@ info:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N
cvss-score: 0.0 cvss-score: 0.0
cwe-id: CWE-200 cwe-id: CWE-200
tags: keycloak,config tags: keycloak,config,exposure
metadata: metadata:
max-request: 2 max-request: 2

View File

@ -10,7 +10,7 @@ info:
cwe-id: CWE-200 cwe-id: CWE-200
description: A MongoDB credentials file used by RoboMongo was detected. description: A MongoDB credentials file used by RoboMongo was detected.
reference: https://robomongo.org/ reference: https://robomongo.org/
tags: mongodb,robomongo,disclosure,config tags: mongodb,robomongo,disclosure,config,exposure
metadata: metadata:
max-request: 2 max-request: 2

View File

@ -4,7 +4,7 @@ info:
name: AWS S3 keys Leak name: AWS S3 keys Leak
author: r12w4n author: r12w4n
severity: high severity: high
tags: aws,s3,wordpress,disclosure tags: aws,s3,wordpress,disclosure,exposure
metadata: metadata:
max-request: 2 max-request: 2

View File

@ -8,7 +8,7 @@ info:
max-request: 2 max-request: 2
verified: true verified: true
github-query: filename:libs.versions.toml github-query: filename:libs.versions.toml
tags: file,gradle tags: file,gradle,exposure
http: http:
- method: GET - method: GET

View File

@ -16,7 +16,7 @@ info:
max-request: 3 max-request: 3
verified: true verified: true
google-query: intitle:"index of" "WebServers.xml" google-query: intitle:"index of" "WebServers.xml"
tags: jetbrains,config,edb,files tags: jetbrains,config,edb,files,exposure
http: http:
- method: GET - method: GET

View File

@ -9,7 +9,7 @@ info:
max-request: 3 max-request: 3
verified: true verified: true
google-query: intitle:"index of" "settings.yml" google-query: intitle:"index of" "settings.yml"
tags: misconfig,redmine,devops,files tags: misconfig,redmine,devops,files,exposure
http: http:
- method: GET - method: GET

View File

@ -9,7 +9,7 @@ info:
max-request: 4 max-request: 4
verified: true verified: true
google-query: intitle:"index of" "secrets.yml" google-query: intitle:"index of" "secrets.yml"
tags: misconfig,cloud,devops,files tags: cloud,devops,files,exposure,misconfig
http: http:
- method: GET - method: GET

View File

@ -11,7 +11,7 @@ info:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
cvss-score: 5.3 cvss-score: 5.3
cwe-id: CWE-200 cwe-id: CWE-200
tags: expose,listing,config,logs,storage,edb,files tags: expose,listing,config,logs,storage,edb,files,exposure
metadata: metadata:
max-request: 6 max-request: 6

View File

@ -4,7 +4,7 @@ info:
name: Publicly accessible access-log file name: Publicly accessible access-log file
author: sheikhrishad author: sheikhrishad
severity: low severity: low
tags: logs tags: logs,exposure
metadata: metadata:
max-request: 4 max-request: 4

View File

@ -6,7 +6,7 @@ info:
severity: high severity: high
reference: reference:
- https://twitter.com/damian_89_/status/1250721398747791360 - https://twitter.com/damian_89_/status/1250721398747791360
tags: tech,clockwork tags: tech,clockwork,exposure
metadata: metadata:
max-request: 1 max-request: 1

View File

@ -8,7 +8,7 @@ info:
and more. and more.
reference: reference:
- https://laravel.com/docs/8.x/telescope - https://laravel.com/docs/8.x/telescope
tags: laravel,disclosure,logs tags: laravel,disclosure,logs,exposure
metadata: metadata:
max-request: 1 max-request: 1

View File

@ -12,7 +12,7 @@ info:
metadata: metadata:
max-request: 1 max-request: 1
shodan-query: http.title:"RouterOS router configuration page" shodan-query: http.title:"RouterOS router configuration page"
tags: panel,router,routeros tags: panel,router,routeros,iot
http: http:
- method: GET - method: GET

View File

@ -7,7 +7,7 @@ info:
description: Aws container metadata content description: Aws container metadata content
reference: reference:
- https://docs.aws.amazon.com/en_us/elasticbeanstalk/latest/dg/create_deploy_docker_ecstutorial.html#create_deploy_docker_ecstutorial_connect_inspect - https://docs.aws.amazon.com/en_us/elasticbeanstalk/latest/dg/create_deploy_docker_ecstutorial.html#create_deploy_docker_ecstutorial_connect_inspect
tags: aws,docker,ec2 tags: aws,docker,ec2,misc
metadata: metadata:
max-request: 2 max-request: 2

View File

@ -8,7 +8,7 @@ info:
max-request: 1 max-request: 1
verified: true verified: true
shodan-query: http.html:"multipart/form-data" html:"file" shodan-query: http.html:"multipart/form-data" html:"file"
tags: exposure,upload,form tags: exposure,upload,form,misc
http: http:
- method: GET - method: GET

View File

@ -7,7 +7,7 @@ info:
metadata: metadata:
max-request: 1 max-request: 1
shodan-query: title:"Microsoft Azure Web App - Error 404" shodan-query: title:"Microsoft Azure Web App - Error 404"
tags: error,azure,microsoft tags: error,azure,microsoft,misc
http: http:
- method: GET - method: GET

View File

@ -11,7 +11,7 @@ info:
metadata: metadata:
max-request: 2 max-request: 2
shodan-query: http.title:"Conductor UI", http.title:"Workflow UI" shodan-query: http.title:"Conductor UI", http.title:"Workflow UI"
tags: tech,netflix,conductor,api tags: tech,netflix,conductor,api,misc
http: http:
- method: GET - method: GET

View File

@ -6,7 +6,7 @@ info:
severity: low severity: low
reference: reference:
- https://packetstormsecurity.com/files/161345/Adobe-Connect-10-Username-Disclosure.html - https://packetstormsecurity.com/files/161345/Adobe-Connect-10-Username-Disclosure.html
tags: adobe,disclosure,packetstorm tags: adobe,disclosure,packetstorm,misconfig
metadata: metadata:
max-request: 1 max-request: 1

View File

@ -4,7 +4,7 @@ info:
name: Adobe Connect Central Version name: Adobe Connect Central Version
author: dhiyaneshDk author: dhiyaneshDk
severity: info severity: info
tags: adobe tags: adobe,misconfig
metadata: metadata:
max-request: 1 max-request: 1

View File

@ -9,7 +9,7 @@ info:
metadata: metadata:
max-request: 1 max-request: 1
shodan-query: http.component:"Adobe Experience Manager" shodan-query: http.component:"Adobe Experience Manager"
tags: aem tags: aem,misconfig
http: http:
- method: GET - method: GET

View File

@ -9,7 +9,7 @@ info:
metadata: metadata:
max-request: 1 max-request: 1
shodan-query: http.component:"Adobe Experience Manager" shodan-query: http.component:"Adobe Experience Manager"
tags: aem tags: aem,misconfig
http: http:
- method: GET - method: GET

View File

@ -16,7 +16,7 @@ info:
shodan-query: shodan-query:
- http.title:"AEM Sign In" - http.title:"AEM Sign In"
- http.component:"Adobe Experience Manager" - http.component:"Adobe Experience Manager"
tags: xss,aem,adobe tags: xss,aem,adobe,misconfig
http: http:
- method: GET - method: GET

View File

@ -11,7 +11,7 @@ info:
metadata: metadata:
max-request: 2 max-request: 2
shodan-query: http.component:"Adobe Experience Manager" shodan-query: http.component:"Adobe Experience Manager"
tags: aem,adobe tags: aem,adobe,misconfig
http: http:
- raw: - raw:

View File

@ -11,7 +11,7 @@ info:
shodan-query: shodan-query:
- http.title:"AEM Sign In" - http.title:"AEM Sign In"
- http.component:"Adobe Experience Manager" - http.component:"Adobe Experience Manager"
tags: exposure,aem,adobe tags: exposure,aem,adobe,misconfig
http: http:
- method: GET - method: GET

View File

@ -11,7 +11,7 @@ info:
metadata: metadata:
max-request: 64 max-request: 64
shodan-query: http.component:"Adobe Experience Manager" shodan-query: http.component:"Adobe Experience Manager"
tags: aem,adobe tags: aem,adobe,misconfig
http: http:
- method: GET - method: GET

View File

@ -9,7 +9,7 @@ info:
metadata: metadata:
max-request: 29 max-request: 29
shodan-query: http.component:"Adobe Experience Manager" shodan-query: http.component:"Adobe Experience Manager"
tags: aem tags: aem,misconfig
http: http:
- method: GET - method: GET

View File

@ -11,7 +11,7 @@ info:
metadata: metadata:
max-request: 2 max-request: 2
shodan-query: http.component:"Adobe Experience Manager" shodan-query: http.component:"Adobe Experience Manager"
tags: aem,adobe,hackerone tags: aem,adobe,hackerone,misconfig
http: http:
- method: GET - method: GET

View File

@ -9,7 +9,7 @@ info:
metadata: metadata:
max-request: 1 max-request: 1
shodan-query: http.component:"Adobe Experience Manager" shodan-query: http.component:"Adobe Experience Manager"
tags: aem tags: aem,misconfig
http: http:
- raw: - raw:

View File

@ -7,7 +7,7 @@ info:
metadata: metadata:
max-request: 1 max-request: 1
shodan-query: http.component:"Adobe Experience Manager" shodan-query: http.component:"Adobe Experience Manager"
tags: aem tags: aem,misconfig
http: http:
- raw: - raw:

View File

@ -11,7 +11,7 @@ info:
metadata: metadata:
max-request: 3 max-request: 3
shodan-query: http.component:"Adobe Experience Manager" shodan-query: http.component:"Adobe Experience Manager"
tags: aem,adobe tags: aem,adobe,misconfig
http: http:
- method: GET - method: GET

View File

@ -9,7 +9,7 @@ info:
metadata: metadata:
max-request: 1 max-request: 1
shodan-query: http.component:"Adobe Experience Manager" shodan-query: http.component:"Adobe Experience Manager"
tags: aem tags: aem,misconfig
http: http:
- method: GET - method: GET

View File

@ -9,7 +9,7 @@ info:
metadata: metadata:
max-request: 1 max-request: 1
shodan-query: http.component:"Adobe Experience Manager" shodan-query: http.component:"Adobe Experience Manager"
tags: aem tags: aem,misconfig
http: http:
- method: GET - method: GET

View File

@ -9,7 +9,7 @@ info:
metadata: metadata:
max-request: 4 max-request: 4
shodan-query: http.component:"Adobe Experience Manager" shodan-query: http.component:"Adobe Experience Manager"
tags: aem tags: aem,misconfig
http: http:
- method: GET - method: GET

View File

@ -11,7 +11,7 @@ info:
metadata: metadata:
max-request: 8 max-request: 8
shodan-query: http.component:"Adobe Experience Manager" shodan-query: http.component:"Adobe Experience Manager"
tags: aem,adobe tags: aem,adobe,misconfig
http: http:
- method: GET - method: GET

View File

@ -16,7 +16,7 @@ info:
metadata: metadata:
max-request: 2 max-request: 2
shodan-query: http.component:"Adobe Experience Manager" shodan-query: http.component:"Adobe Experience Manager"
tags: aem,xss tags: aem,xss,misconfig
http: http:
- method: GET - method: GET

View File

@ -8,7 +8,7 @@ info:
metadata: metadata:
max-request: 1 max-request: 1
shodan-query: http.component:"Adobe Experience Manager" shodan-query: http.component:"Adobe Experience Manager"
tags: aem,bruteforce tags: aem,bruteforce,misconfig
http: http:
- method: GET - method: GET

View File

@ -9,7 +9,7 @@ info:
metadata: metadata:
max-request: 1 max-request: 1
shodan-query: http.component:"Adobe Experience Manager" shodan-query: http.component:"Adobe Experience Manager"
tags: aem tags: aem,misconfig
http: http:
- method: GET - method: GET

View File

@ -18,7 +18,7 @@ info:
cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
cvss-score: 7.2 cvss-score: 7.2
cwe-id: CWE-79 cwe-id: CWE-79
tags: xss,aem,adobe tags: xss,aem,adobe,misconfig
http: http:
- method: GET - method: GET

View File

@ -8,7 +8,7 @@ info:
max-request: 1 max-request: 1
verified: true verified: true
shodan-query: title:"Airflow - DAGs" shodan-query: title:"Airflow - DAGs"
tags: apache,airflow,fpd tags: apache,airflow,fpd,misconfig
http: http:
- method: GET - method: GET

View File

@ -7,7 +7,7 @@ info:
metadata: metadata:
max-request: 2 max-request: 2
shodan-query: title:"Airflow - DAGs" shodan-query: title:"Airflow - DAGs"
tags: apache,airflow,unauth tags: apache,airflow,unauth,misconfig
http: http:
- method: GET - method: GET

View File

@ -15,7 +15,7 @@ info:
cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
cvss-score: 7.2 cvss-score: 7.2
cwe-id: CWE-79 cwe-id: CWE-79
tags: akamai,xss tags: akamai,xss,misconfig
metadata: metadata:
max-request: 1 max-request: 1

View File

@ -15,7 +15,7 @@ info:
metadata: metadata:
max-request: 204 max-request: 204
verified: true verified: true
tags: cache,poisoning,generic,xss,akamai,s3 tags: cache,poisoning,generic,xss,akamai,s3,misconfig
variables: variables:
rand: "{{rand_base(5)}}" rand: "{{rand_base(5)}}"

View File

@ -4,7 +4,7 @@ info:
name: Alibaba Mongoshake Unauth name: Alibaba Mongoshake Unauth
author: pikpikcu author: pikpikcu
severity: info severity: info
tags: mongoshake,unauth,alibaba tags: mongoshake,unauth,alibaba,misconfig
metadata: metadata:
max-request: 1 max-request: 1

View File

@ -7,7 +7,7 @@ info:
metadata: metadata:
max-request: 1 max-request: 1
shodan-query: http.title:"Android Debug Database" shodan-query: http.title:"Android Debug Database"
tags: unauth,android tags: unauth,android,misconfig
http: http:
- method: GET - method: GET

View File

@ -10,7 +10,7 @@ info:
cvss-score: 0.0 cvss-score: 0.0
cwe-id: CWE-200 cwe-id: CWE-200
reference: https://i.blackhat.com/us-18/Wed-August-8/us-18-Orange-Tsai-Breaking-Parser-Logic-Take-Your-Path-Normalization-Off-And-Pop-0days-Out-2.pdf reference: https://i.blackhat.com/us-18/Wed-August-8/us-18-Orange-Tsai-Breaking-Parser-Logic-Take-Your-Path-Normalization-Off-And-Pop-0days-Out-2.pdf
tags: panel,tomcat,apache tags: panel,tomcat,apache,misconfig
metadata: metadata:
max-request: 6 max-request: 6

View File

@ -4,7 +4,7 @@ info:
name: APCu service information leakage name: APCu service information leakage
author: koti2 author: koti2
severity: low severity: low
tags: config,service,apcu tags: config,service,apcu,misconfig
metadata: metadata:
max-request: 2 max-request: 2

View File

@ -6,7 +6,7 @@ info:
severity: high severity: high
reference: reference:
- https://www.errno.fr/artifactory/Attacking_Artifactory.html - https://www.errno.fr/artifactory/Attacking_Artifactory.html
tags: artifactory tags: artifactory,misconfig
metadata: metadata:
max-request: 1 max-request: 1

View File

@ -6,7 +6,7 @@ info:
severity: info severity: info
reference: reference:
- https://portswigger.net/kb/issues/00100800_asp-net-debugging-enabled - https://portswigger.net/kb/issues/00100800_asp-net-debugging-enabled
tags: debug tags: debug,misconfig
metadata: metadata:
max-request: 1 max-request: 1

View File

@ -6,7 +6,7 @@ info:
severity: info severity: info
reference: reference:
- https://link.medium.com/fgXKJHR9P7 - https://link.medium.com/fgXKJHR9P7
tags: aws,takeover tags: aws,takeover,misconfig
metadata: metadata:
max-request: 1 max-request: 1

View File

@ -8,7 +8,7 @@ info:
max-request: 1 max-request: 1
verified: true verified: true
shodan-query: title:"Blackbox Exporter" shodan-query: title:"Blackbox Exporter"
tags: blackbox,exposure,debug tags: blackbox,exposure,debug,misconfig
http: http:
- method: GET - method: GET

View File

@ -10,7 +10,7 @@ info:
metadata: metadata:
max-request: 1 max-request: 1
shodan-query: http.title:"browserless debugger" shodan-query: http.title:"browserless debugger"
tags: browserless,unauth,debug tags: browserless,unauth,debug,misconfig
http: http:
- method: GET - method: GET

View File

@ -4,7 +4,7 @@ info:
name: CGI Test page name: CGI Test page
author: YASH ANAND @yashanand155 author: YASH ANAND @yashanand155
severity: info severity: info
tags: cgi tags: cgi,misconfig
metadata: metadata:
max-request: 1 max-request: 1

View File

@ -6,7 +6,7 @@ info:
severity: high severity: high
reference: reference:
- https://github.com/detectify/ugly-duckling/blob/master/modules/crowdsourced/clockwork-dashboard-exposure.json - https://github.com/detectify/ugly-duckling/blob/master/modules/crowdsourced/clockwork-dashboard-exposure.json
tags: exposure,unauth tags: exposure,unauth,misconfig
metadata: metadata:
max-request: 1 max-request: 1

View File

@ -8,7 +8,7 @@ info:
max-request: 1 max-request: 1
verified: true verified: true
shodan-query: http.title:"Cluster Overview - Trino" shodan-query: http.title:"Cluster Overview - Trino"
tags: cluster,unauth,trino tags: cluster,unauth,trino,misconfig
http: http:
- method: POST - method: POST

View File

@ -8,7 +8,7 @@ info:
max-request: 1 max-request: 1
verified: true verified: true
shodan-query: title:"Collectd Exporter" shodan-query: title:"Collectd Exporter"
tags: collectd,exposure,debug tags: collectd,exposure,debug,misconfig
http: http:
- method: GET - method: GET

View File

@ -13,7 +13,7 @@ info:
max-request: 1 max-request: 1
verified: true verified: true
shodan-query: http.html:"Command API Explorer" shodan-query: http.html:"Command API Explorer"
tags: panel tags: panel,misconfig
http: http:
- method: GET - method: GET

View File

@ -9,7 +9,7 @@ info:
cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N
cvss-score: 0.0 cvss-score: 0.0
cwe-id: CWE-200 cwe-id: CWE-200
tags: fileupload tags: fileupload,misconfig
metadata: metadata:
max-request: 1 max-request: 1

View File

@ -11,7 +11,7 @@ info:
cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
cvss-score: 8.3 cvss-score: 8.3
cwe-id: CWE-522 cwe-id: CWE-522
tags: dlink,lfi tags: dlink,lfi,misconfig
metadata: metadata:
max-request: 1 max-request: 1

View File

@ -10,7 +10,7 @@ info:
max-request: 1 max-request: 1
verified: true verified: true
shodan-query: html:"Sorry, the requested URL" shodan-query: html:"Sorry, the requested URL"
tags: bottle,exposure,debug tags: bottle,exposure,debug,misconfig
http: http:
- method: GET - method: GET

View File

@ -8,7 +8,7 @@ info:
max-request: 1 max-request: 1
verified: true verified: true
shodan-query: html:"Werkzeug powered traceback interpreter" shodan-query: html:"Werkzeug powered traceback interpreter"
tags: werkzeug,exposure,debug tags: werkzeug,exposure,debug,misconfig
http: http:
- method: GET - method: GET

View File

@ -10,7 +10,7 @@ info:
cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
cvss-score: 8.6 cvss-score: 8.6
cwe-id: CWE-284 cwe-id: CWE-284
tags: openview,disclosure,panel tags: openview,disclosure,panel,misconfig
metadata: metadata:
max-request: 1 max-request: 1

View File

@ -12,7 +12,7 @@ info:
metadata: metadata:
max-request: 1 max-request: 1
shodan-query: http.title:"Dgraph Ratel Dashboard" shodan-query: http.title:"Dgraph Ratel Dashboard"
tags: exposure,unauth,panel tags: exposure,unauth,panel,misconfig
http: http:
- method: GET - method: GET

View File

@ -4,7 +4,7 @@ info:
name: Django Debug Method Enabled name: Django Debug Method Enabled
author: dhiyaneshDK,hackergautam author: dhiyaneshDK,hackergautam
severity: medium severity: medium
tags: django,debug tags: django,debug,misconfig
metadata: metadata:
max-request: 1 max-request: 1

Some files were not shown because too many files have changed in this diff Show More