id: mercurial-hgignore info: name: Mercurial Ignore - File Disclosure author: DhiyaneshDK severity: info description: Mercurial Ignore file disclosure was detected. reference: - https://swcarpentry.github.io/hg-novice/08-ignore/ classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N cvss-score: 0 cwe-id: CWE-200 metadata: verified: true max-request: 1 shodan-query: html:"hgignore" tags: exposure,hgignore,config,mercurial http: - method: GET path: - "{{BaseURL}}/.hgignore" matchers-condition: and matchers: - type: dsl dsl: - 'len(body) > 50' - 'status_code == 200' condition: and - type: word words: - "MongoDB over HTTP on the native" - "application/javascript" - "application/x-javascript" - "application/json" - "application/xml" - "html" - "