漏洞描述
Chamilo is susceptible to the Installation page exposure due to misconfiguration.
id: chamilo-installer
info:
name: Chamilo Installer Exposure
author: DhiyaneshDk
severity: high
description: Chamilo is susceptible to the Installation page exposure due to misconfiguration.
classification:
cpe: cpe:2.3:a:chamilo:chamilo:*:*:*:*:*:*:*:*
metadata:
verified: true
max-request: 2
vendor: chamilo
product: chamilo
shodan-query: title:"Chamilo has not been installed"
tags: misconfig,chamilo,install,exposure,vuln
http:
- method: GET
path:
- '{{BaseURL}}'
- '{{BaseURL}}/main/install/index.php'
stop-at-first-match: true
matchers-condition: or
matchers:
- type: word
part: body
words:
- 'Chamilo installation'
- 'Installation Language'
condition: and
- type: word
part: body
words:
- '<title>Chamilo has not been installed</title>'
# digest: 4a0a00473045022100c969537ba9f44ee924d6a11012b2d7376f500adff93fc7c18e09584e03e03f7802204f1cbd5d5262983713ccae2f641d44daff8294d7d4c8230bbceb5106bc466a96:922c64590222798bb761d5b6d8e72950