id: settings-php-files info: name: settings.php - Information Disclosure author: sheikhrishad severity: medium description: settings.php source code was detected via backup files. classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N cvss-score: 5.3 cwe-id: CWE-200 metadata: max-request: 7 tags: exposure,backup http: - method: GET path: - "{{BaseURL}}/settings.php.bak" - "{{BaseURL}}/settings.php.dist" - "{{BaseURL}}/settings.php.old" - "{{BaseURL}}/settings.php.save" - "{{BaseURL}}/settings.php.swp" - "{{BaseURL}}/settings.php.txt" - "{{BaseURL}}config/settings.old.php" matchers-condition: and matchers: - type: word words: - "DB_NAME" - "DB" condition: and - type: status status: - 200 # digest: 4b0a00483046022100eba9de4436d8e08669f91da6cbd54d44279778bcf9fec5b5e930a1d6b5f8e56e022100a11699b4af7715f48e25cc159b1709c6396bf4ae8be69c37d82a477bc75689f5:922c64590222798bb761d5b6d8e72950