apache-config: Apache Configuration File - Detect

日期: 2025-08-01 | 影响软件: apache-config | POC: 已公开

漏洞描述

Apache configuration file was detected.

PoC代码[已公开]

id: apache-config

info:
  name: Apache Configuration File - Detect
  author: sheikhrishad
  severity: medium
  description: Apache configuration file was detected.
  remediation: Remove the configuration file from the web root.
  reference:
    - https://httpd.apache.org/docs/2.4/configuring.html
  classification:
    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
    cvss-score: 5.3
    cwe-id: CWE-200
  metadata:
    max-request: 1
  tags: config,exposure,apache,vuln

http:
  - method: GET
    path:
      - "{{BaseURL}}/apache.conf"

    matchers:
      - type: dsl
        dsl:
          - "contains(body, '<Directory') && contains(body, '</Directory>') && status_code == 200"
          - "contains(body, '<VirtualHost') && contains(body, '</VirtualHost>') && status_code == 200"
        condition: or
# digest: 4a0a0047304502204f30bbe0416c7bd0a3ade832a39a914ecec53a46f9a9d3ab52f5e0298ac4adcb022100c376674a69dfad9bed032b41ba3e0c6cd6468ceda922c31024fc6917921dccf0:922c64590222798bb761d5b6d8e72950