id: limesurvey-installer info: name: Limesurvey Installer Exposure author: DhiyaneshDk severity: high description: Limesurvey is susceptible to the Installation page exposure due to misconfiguration. metadata: verified: true max-request: 1 shodan-query: html:"Limesurvey Installer" tags: misconfig,limesurvey,install http: - method: GET path: - '{{BaseURL}}/index.php?r=installer/welcome' matchers-condition: and matchers: - type: word part: body words: - 'LimeSurvey installer' - 'Progress' - 'Your preferred language will be used through out the installation process' condition: and - type: word part: header words: - "text/html" - type: status status: - 200 # digest: 4a0a00473045022100a3e22ceb23b87ef2b520167a256c38eaa46854119b124bacbea68402cd92185002203fa3b9a8e87a25025a9980a181d9b5f66db1b7d70f1dac7b41a0aa93bc91d6be:922c64590222798bb761d5b6d8e72950