id: liferay-axis info: name: Liferay /api/axis - API Exposed author: DhiyaneshDk severity: info reference: https://github.com/ilmila/J2EEScan/blob/master/src/main/java/burp/j2ee/issues/impl/LiferayAPI.java metadata: verified: true max-request: 1 shodan-query: title:"Liferay" tags: misconfig,exposure,liferay,api http: - method: GET path: - "{{BaseURL}}/api/axis" matchers-condition: and matchers: - type: regex part: body regex: - ".*

And now\\.\\.\\. Some Services<\\/h2>.*" - type: word part: header words: - "text/html" - type: status status: - 200 # digest: 4b0a00483046022100844cea6b891f1e88f60abea8ef53b09b843c7da579b44dccc51cc0e98e1e27010221008d720a018887c0d09cf1957815849fae34ddfd6faf0381e741705a1270fe8e31:922c64590222798bb761d5b6d8e72950