id: webalizer-xtended-stats info: name: Webalizer Xtended Statistics Exposed author: ritikchaddha severity: low description: Webalizer Xtended Statistics is exposed. reference: - https://www.patrickfrei.ch/webalizer/ metadata: verified: true max-request: 1 google-query: inurl:"/usage/error_202109.html" tags: exposure,stats,webalizer http: - method: GET path: - "{{BaseURL}}/usage/" matchers-condition: and matchers: - type: word part: body words: - '