concrete-installer: Concrete Installer

日期: 2025-08-01 | 影响软件: Concrete Installer | POC: 已公开

漏洞描述

Concrete is susceptible to the Installation page exposure due to misconfiguration.

PoC代码[已公开]

id: concrete-installer

info:
  name: Concrete Installer
  author: pussycat0x
  severity: high
  description: Concrete is susceptible to the Installation page exposure due to misconfiguration.
  classification:
    cpe: cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:*
  metadata:
    verified: true
    max-request: 1
    vendor: concretecms
    product: concrete_cms
    shodan-query: title:"Install concrete"
  tags: misconfig,exposure,install,concrete,vuln

http:
  - method: GET
    path:
      - "{{BaseURL}}/index.php/install"

    matchers-condition: and
    matchers:
      - type: word
        part: body
        words:
          - "install concrete"
          - "choose language"
        condition: and
        case-insensitive: true

      - type: word
        part: header
        words:
          - "text/html"

      - type: status
        status:
          - 200
# digest: 490a0046304402205aba3d64c29df639ad8baf0415f06d65fde395a2666af88842d723775d57e0ed022054c356e5f67ebc331cfc8301e55c1c3f3e515e9645c5c5f162daaf2eb2c35a0f:922c64590222798bb761d5b6d8e72950