nuclei-templates/misconfiguration/glpi-directory-listing.yaml

31 lines
620 B
YAML

id: glpi-directory-listing
info:
name: GLPI Directory Listing
author: RedTeamBrasil,ImNightmaree
description: In certain cases, system administrators leave directory listing enabled which can sometimes expose sensitive files.
severity: low
tags: glpi,misconfig
requests:
- raw:
- |
GET {{expose_data}} HTTP/1.1
Host: {{Hostname}}
payloads:
expose_data:
- /glpi/files/
- /glpi/
matchers-condition: and
matchers:
- type: word
part: body
words:
- "Index of /glpi/"
- type: status
status:
- 200