id: woodwing-git info: name: Woodwing Studio Server - Git Config author: pdteam severity: medium description: Woodwing Studio Server .git/config file exposed. reference: - https://twitter.com/ynsmroztas/status/1680961398011047936 metadata: max-request: 2 shodan-query: http.title:"WoodWing Studio Server" fofa-query: title=="WoodWing Studio Server" tags: misconfig,woodwing,git,config http: - method: GET path: - "{{BaseURL}}/Server/.git/config" - "{{BaseURL}}/StudioServer/.git/config" stop-at-first-match: true matchers: - type: dsl dsl: - "!contains_all(tolower(body), '