diff --git a/misconfiguration/symfony-fosjrouting-bundle.yaml b/misconfiguration/symfony-fosjrouting-bundle.yaml new file mode 100644 index 0000000000..89776e7bcc --- /dev/null +++ b/misconfiguration/symfony-fosjrouting-bundle.yaml @@ -0,0 +1,35 @@ +id: symfony-fosjrouting-bundle + +info: + name: Symfony FOSJsRoutingBundle + author: DhiyaneshDk + severity: low + reference: + - https://packagist.org/packages/friendsofsymfony/jsrouting-bundle + metadata: + verified: true + shodan-query: http.html:"symfony Profiler" + tags: misconfig,symfony + +requests: + - method: GET + path: + - '{{BaseURL}}/js/routing?callback=fos.Router.setDatafoobarfoo' + + matchers-condition: and + matchers: + - type: word + part: body + words: + - '/**/fos.Router.setDatafoobarfoo({' + - 'routes' + condition: and + + - type: word + part: header + words: + - "application/javascript" + + - type: status + status: + - 200