nuclei-templates/misconfiguration/tomcat-scripts.yaml

24 lines
613 B
YAML

id: tomcat-scripts
info:
name: Detect Tomcat Exposed Scripts
author: Co0nan
severity: info
requests:
- method: GET
path:
- "{{BaseURL}}/examples/servlets/index.html"
- "{{BaseURL}}/examples/jsp/index.html"
- "{{BaseURL}}/examples/websocket/index.xhtml"
- "{{BaseURL}}/..;/examples/servlets/index.html"
- "{{BaseURL}}/..;/examples/jsp/index.html"
- "{{BaseURL}}/..;/examples/websocket/index.xhtml"
matchers:
- type: word
words:
- "JSP Examples"
- "JSP Samples"
- "Servlets Examples"
- "WebSocket Examples"