id: phinx-config info: name: Phinx Configuration Exposure author: DhiyaneshDk severity: medium description: Phinx configuration file was exposed. reference: - https://book.cakephp.org/phinx/0/en/configuration.html - https://github.com/cakephp/phinx - https://www.tenable.com/plugins/was/113433 - https://phinx.org/ metadata: verified: true max-request: 1 shodan-query: html:"phinx.yml" tags: devops,exposure,files http: - method: GET path: - "{{BaseURL}}/phinx.yml" matchers-condition: and matchers: - type: word part: body words: - 'paths:' - 'environments:' - 'development:' condition: and - type: status status: - 200 # digest: 4a0a004730450220755f5e2ccb86cfda5f8669d6051fe333574dd231a446536c4a49cc2d2c62a2ef022100f40d98a64ec736cb3b50bdcd02a43a08cb71c054a353da2297a06799a74cf89f:922c64590222798bb761d5b6d8e72950