id: oxid-eshop-installer info: name: Oxid EShop Installer Exposure description: Oxid EShop setup page is susceptible to sensitive information disclosure due to misconfiguration. author: ritikchaddha severity: high metadata: verified: true max-request: 1 shodan-query: title:"OXID eShop installation" tags: misconfig,oxid,eshop,install,exposure http: - method: GET path: - '{{BaseURL}}/Setup/index.php/' matchers-condition: and matchers: - type: word part: body words: - 'OXID eShop installation' - 'System Requirements' condition: and - type: status status: - 200 # digest: 4b0a00483046022100829ecb9f9fc34a00f0f1ead04fa405c32cc73fae5eff15399f41f27b5250b51c0221009d8560624e592c2dd0673af64422fcd1fffca54d63a0f0d7cb91e775c7854689:922c64590222798bb761d5b6d8e72950