id: settings-php-files info: name: settings.php - Information Disclosure author: sheikhrishad severity: medium description: settings.php source code was detected via backup files. classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N cvss-score: 5.3 cwe-id: CWE-200 metadata: max-request: 6 tags: exposure,backup http: - method: GET path: - "{{BaseURL}}/settings.php.bak" - "{{BaseURL}}/settings.php.dist" - "{{BaseURL}}/settings.php.old" - "{{BaseURL}}/settings.php.save" - "{{BaseURL}}/settings.php.swp" - "{{BaseURL}}/settings.php.txt" matchers-condition: and matchers: - type: word words: - "DB_NAME" - "DB" condition: and - type: status status: - 200 # digest: 4a0a0047304502205d01111f8104897ec14d420d10fe452a20511e65a49461f220716997903363e9022100d7e2b69aa7cca6943256c9ffa70af615558a17df2690daad67082d6343a55601:922c64590222798bb761d5b6d8e72950