36 lines
1.5 KiB
YAML
36 lines
1.5 KiB
YAML
id: wp-superstorefinder-misconfig
|
|
|
|
info:
|
|
name: Superstorefinder WP-plugin - Security Misconfigurations
|
|
author: r3Y3r53
|
|
severity: medium
|
|
description: |
|
|
Security misconfiguration is a common security issue that occurs when a system, application, or network is not properly configured to protect against threats and vulnerabilities.
|
|
reference:
|
|
- https://cxsecurity.com/issue/WLB-2021010145
|
|
- https://www.exploitalert.com/view-details.html?id=36983
|
|
classification:
|
|
cpe: cpe:2.3:a:superstorefinder:super_store_finder:*:*:*:*:wordpress:*:*:*
|
|
metadata:
|
|
verified: true
|
|
max-request: 1
|
|
vendor: superstorefinder
|
|
product: super_store_finder
|
|
publicwww-query: /wp-content/plugins/superstorefinder-wp/
|
|
google-query: inurl:"wp-content/plugins/superstorefinder-wp/ssf-wp-admin/pages/exportAjax.php"
|
|
tags: wordpress,wp-plugin,superstorefinder-wp,wp,misconfig
|
|
|
|
http:
|
|
- raw:
|
|
- |
|
|
GET /wp-content/plugins/superstorefinder-wp/ssf-wp-admin/pages/exportAjax.php HTTP/1.1
|
|
Host: {{Hostname}}
|
|
|
|
matchers:
|
|
- type: dsl
|
|
dsl:
|
|
- 'status_code == 200'
|
|
- 'contains(body, "Name") && contains(body, "CategoriesTags") && contains(body, "email")'
|
|
- 'contains(content_type, "text/html")'
|
|
condition: and
|
|
# digest: 490a0046304402203e9e6acc6b1d39f9b019e6b10dbc07b8ba003029ad01f799cf68b13c1cf36d920220522a7fa766858ff60d0beab9ce2ba635879079a14b277a206e578103086fbe62:922c64590222798bb761d5b6d8e72950 |