id: plesk-stat info: name: Webalizer Log Analyzer Configuration - Detect author: th3.d1p4k severity: medium description: Webalizer log analyzer configuration was detected. reference: - https://webalizer.net/ classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N cvss-score: 5.3 cwe-id: CWE-200 metadata: max-request: 1 tags: config,exposure,plesk http: - method: GET path: - "{{BaseURL}}/plesk-stat/" matchers-condition: and matchers: - type: status status: - 200 - type: word words: - 'Index of /plesk-stat' - 'Parent Directory' condition: and - type: word words: - 'anon_ftpstat' - 'ftpstat' - 'webstat-ssl' - 'webstat' condition: or # digest: 4a0a004730450221009d0c702a377c5041bcf90bbca246a8753effe21d960dfc87ded62eb3d9d1a6710220081bd5a2083521a52fcab302621693e6edda51c1d6bd2198119b30d0a199e57a:922c64590222798bb761d5b6d8e72950