diff --git a/misconfiguration/jkstatus-manager.yaml b/misconfiguration/jkstatus-manager.yaml index d5d0a1d1f3..c6eb6b4288 100644 --- a/misconfiguration/jkstatus-manager.yaml +++ b/misconfiguration/jkstatus-manager.yaml @@ -2,17 +2,32 @@ id: jkstatus-manager info: name: JK Status Manager - author: pdteam + author: pdteam,DhiyaneshDk severity: low + reference: + - https://github.com/PortSwigger/j2ee-scan/blob/master/src/main/java/burp/j2ee/issues/impl/JKStatus.java + metadata: + verified: "true" + shodan-query: html:"JK Status Manager" tags: config,status requests: - method: GET headers: X-Forwarded-For: "127.0.0.1" + path: - - "{{BaseURL}}/jkstatus/" + - "{{BaseURL}}" + - "{{BaseURL}}/status" + - "{{BaseURL}}/jkstatus" + - "{{BaseURL}}/jkstatus-auth" + - "{{BaseURL}}/jk-status" + - "{{BaseURL}}/jkmanager" + - "{{BaseURL}}/jkmanager-auth" + - "{{BaseURL}}/jdkstatus" + + stop-at-first-match: true matchers: - type: word words: - - "