id: ioncube-loader-wizard info: name: ioncube Loader Wizard Disclosure author: Mubassirpatel severity: medium description: An ioncube Loader Wizard was discovered. reference: - https://firefart.at/post/multiple-vulnerabilities-in-ioncube-loader-wizard/ classification: cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N cvss-score: 5.3 cwe-id: CWE-200 metadata: max-request: 2 tags: ioncube,disclosure,exposure http: - method: GET path: - "{{BaseURL}}/ioncube/loader-wizard.php" - "{{BaseURL}}/loader-wizard.php" matchers-condition: and matchers: - type: word words: - "ionCube Loader Wizard" part: body - type: status status: - 200 # digest: 4b0a00483046022100d26c5bfb8332e27ad7bed1b100a58be6f1246bb71e45eb767d423486d6ec16bd022100ef875cc22b36185f43164e21c2e211028db248fac5e3a8f6a8a1379d3f0de461:922c64590222798bb761d5b6d8e72950