diff --git a/misconfiguration/aem/aem-crx-browser.yaml b/misconfiguration/aem/aem-crx-browser.yaml new file mode 100644 index 0000000000..d34f7a4bda --- /dev/null +++ b/misconfiguration/aem/aem-crx-browser.yaml @@ -0,0 +1,34 @@ +id: aem-crx-browser + +info: + name: Adobe AEM CRX Browser Exposure + author: dhiyaneshDk + severity: medium + reference: + - https://raw.githubusercontent.com/danielmiessler/SecLists/master/Discovery/Web-Content/aem2.txt + metadata: + shodan-query: + - http.title:"AEM Sign In" + - http.component:"Adobe Experience Manager" + tags: aem,adobe,exposure + +requests: + - method: GET + path: + - "{{BaseURL}}/crx/explorer/browser/index.jsp" + + matchers-condition: and + matchers: + - type: word + words: + - '