id: gibbon-installer info: name: Gibbon Installer - Exposure author: DhiyaneshDK severity: high description: Gibbon is susceptible to the Installation page exposure due to misconfiguration. metadata: verified: true max-request: 1 fofa-query: icon_hash="-165631681" product: gibbon vendor: gibbonedu shodan-query: http.favicon.hash:"-165631681" tags: misconfig,gibbon,install,exposure http: - method: GET path: - '{{BaseURL}}/installer/install.php' matchers-condition: and matchers: - type: word part: body words: - 'Gibbon Installer' - type: word part: header words: - "text/html" - type: status status: - 200 # digest: 4a0a00473045022100f162237b67b399c00f656cadc0234e6c50d23b35505a03aa63406f44038f5ac402204ba6621013d289e37f17e0833e554936aee105b80e6b837cc2b491e6cbb005ff:922c64590222798bb761d5b6d8e72950