id: webcalendar-install info: name: WebCalendar Exposed Installation author: ritikchaddha severity: high description: WebCalendar is susceptible to the Installation page exposure due to misconfiguration. classification: cpe: cpe:2.3:a:k5n:webcalendar:*:*:*:*:*:*:*:* metadata: verified: true max-request: 1 vendor: k5n product: webcalendar shodan-query: title:"WebCalendar Setup Wizard" fofa-query: title="WebCalendar Setup Wizard" tags: misconfig,webcalendar,install http: - method: GET path: - "{{BaseURL}}/install/index.php" matchers-condition: and matchers: - type: word words: - 'WebCalendar Setup Wizard' - '>WebCalendar Installation Wizard' condition: or - type: status status: - 200 # digest: 4a0a0047304502203f9f9d0530a6128882d754e1bf7bdf02d01b355f189a08b28daeb95a1f748c71022100cef8e90c908df68dc0f8289901f9eca3896612e38649ba5edf5058132bce0b5f:922c64590222798bb761d5b6d8e72950