id: yzmcms-installer info: name: YzmCMS - Installer author: ritikchaddha severity: high description: YzmCMS is susceptible to the Installation page exposure due to misconfiguration. classification: cpe: cpe:2.3:a:yzmcms:yzmcms:*:*:*:*:*:*:*:* metadata: verified: true max-request: 1 vendor: yzmcms product: yzmcms shodan-query: title:"YzmCMS" fofa-query: title="YzmCMS" tags: misconfig,yzmcms,install,exposure http: - method: GET path: - '{{BaseURL}}/application/install/index.php' matchers-condition: and matchers: - type: word part: body words: - '安装程序 - YzmCMS' - 'YzmCMS' condition: or - type: word part: body words: - '/index.php?step=2' - '/install.css' condition: or - type: status status: - 200 # digest: 4a0a00473045022100e9983ac94d89666703dd4fb5551e06c227f50f06cdfabfe22f748486dda127370220061122794e4f1f3548512deb0bdb933734821b17563dfc822da1eeb331175b24:922c64590222798bb761d5b6d8e72950