id: tomcat-scripts info: name: Detect Tomcat Exposed Scripts author: Co0nan severity: info tags: apache,tomcat requests: - method: GET path: - "{{BaseURL}}/examples/servlets/index.html" - "{{BaseURL}}/examples/jsp/index.html" - "{{BaseURL}}/examples/websocket/index.xhtml" - "{{BaseURL}}/..;/examples/servlets/index.html" - "{{BaseURL}}/..;/examples/jsp/index.html" - "{{BaseURL}}/..;/examples/websocket/index.xhtml" matchers: - type: word words: - "JSP Examples" - "JSP Samples" - "Servlets Examples" - "WebSocket Examples" condition: or