id: dompdf-config info: name: DomPDF - Configuration Page author: kazet severity: low description: | DOMPDF Configuration page was detected, which contains paths, library versions and other potentially sensitive information classification: cwe-id: CWE-200 metadata: verified: true max-request: 6 fofa-query: title="dompdf - The PHP 5 HTML to PDF Converter" tags: config,exposure,dompdf http: - method: GET path: - "{{BaseURL}}/www/setup.php" - "{{BaseURL}}/dompdf/dompdf/www/setup.php" - "{{BaseURL}}/js/dompdf/www/setup.php" - "{{BaseURL}}/portal/application/libraries/dompdf/www/setup.php" - "{{BaseURL}}/sites/all/libraries/dompdf/www/setup.php" - "{{BaseURL}}/vendor/dompdf/dompdf/www/setup.php" stop-at-first-match: true matchers-condition: and matchers: - type: word part: body words: - 'HTML to PDF Converter' - 'DOMPDF_PDF_BACKEND' condition: and - type: status status: - 200 # digest: 4a0a00473045022019ae7446da8cf0c57c637cecd750773679e29ca526116d27a32b066d44aa735d022100d6965160cb2f94abccbd3d1cad0431a1b9cf64c94b1ab9f758c3e0d743993699:922c64590222798bb761d5b6d8e72950