diff --git a/http/misconfiguration/installer/froxlor-installer.yaml b/http/misconfiguration/installer/froxlor-installer.yaml new file mode 100644 index 0000000000..7c4ba2c638 --- /dev/null +++ b/http/misconfiguration/installer/froxlor-installer.yaml @@ -0,0 +1,31 @@ +id: froxlor-installer + +info: + name: Froxlor Server Management - Installer + author: DhiyaneshDK + severity: high + description: | + Detects the Froxlor Server Management Panel installation page. + reference: + - https://www.exploit-db.com/ghdb/8397 + metadata: + verified: true + max-request: 1 + fofa-query: title="Froxlor Server Management Panel - Installation" + tags: misconfig,froxlor,installer + +http: + - method: GET + path: + - "{{BaseURL}}/install/install.php" + + matchers-condition: and + matchers: + - type: word + part: body + words: + - "Froxlor Server Management Panel - Installation" + + - type: status + status: + - 200