id: dompdf-config info: name: DomPDF - Configuration Page author: kazet severity: low description: | DOMPDF Configuration page was detected, which contains paths, library versions and other potentially sensitive information classification: cwe-id: CWE-200 metadata: verified: true max-request: 6 fofa-query: title="dompdf - The PHP 5 HTML to PDF Converter" tags: config,exposure,dompdf http: - method: GET path: - "{{BaseURL}}/www/setup.php" - "{{BaseURL}}/dompdf/dompdf/www/setup.php" - "{{BaseURL}}/js/dompdf/www/setup.php" - "{{BaseURL}}/portal/application/libraries/dompdf/www/setup.php" - "{{BaseURL}}/sites/all/libraries/dompdf/www/setup.php" - "{{BaseURL}}/vendor/dompdf/dompdf/www/setup.php" stop-at-first-match: true matchers-condition: and matchers: - type: word part: body words: - 'HTML to PDF Converter' - '