id: webcalendar-install info: name: WebCalendar Exposed Installation author: ritikchaddha severity: high description: WebCalendar is susceptible to the Installation page exposure due to misconfiguration. classification: cpe: cpe:2.3:a:k5n:webcalendar:*:*:*:*:*:*:*:* metadata: verified: true max-request: 1 vendor: k5n product: webcalendar shodan-query: title:"WebCalendar Setup Wizard" fofa-query: title="WebCalendar Setup Wizard" tags: misconfig,webcalendar,install http: - method: GET path: - "{{BaseURL}}/install/index.php" matchers-condition: and matchers: - type: word words: - 'WebCalendar Setup Wizard' - '>WebCalendar Installation Wizard' condition: or - type: status status: - 200 # digest: 4b0a00483046022100a1a64046c392fd38e4b873f40b280e840561769c2b7e08e3c3156aea63a77ce8022100f9796d916584c88fa73d41471f04cae330d675a71c3cd8f70457e7f6f2fc2ae8:922c64590222798bb761d5b6d8e72950