id: nextcloud-install info: name: Nextcloud Exposed Installation author: skeltavik severity: high reference: - https://docs.nextcloud.com/server/latest/admin_manual/installation/installation_wizard.html metadata: max-request: 1 tags: tech,nextcloud,storage,misconfig http: - method: GET path: - '{{BaseURL}}' host-redirects: true max-redirects: 2 matchers-condition: and matchers: - type: word part: body words: - '
Create an admin account' - 'Storage & database' condition: and - type: status status: - 200 # digest: 4a0a004730450220796b9ce200aa567eeb7420b5d85cdf097b870756fa298364c04fe1335a2a36b1022100ceba84facff4ec69b95a9e65ecf01f3700b49804fb9910f93e66c214a9103d21:922c64590222798bb761d5b6d8e72950