django-debug-exposure: Django Debug Exposure

日期: 2025-08-01 | 影响软件: django-debug-exposure | POC: 已公开

漏洞描述

Django debug mode enabled exposes internal information.

PoC代码[已公开]

id: django-debug-exposure

info:
  name: Django Debug Exposure
  author: geeknik
  severity: high
  description: Django debug mode enabled exposes internal information.
  reference:
    - https://twitter.com/Alra3ees/status/1397660633928286208
  metadata:
    max-request: 1
  tags: django,exposure,vuln

http:
  - method: POST
    path:
      - "{{BaseURL}}/admin/login/?next=/admin/"

    matchers-condition: and
    matchers:
      - type: status
        status:
          - 500

      - type: word
        part: body
        words:
          - "DB_HOST"
          - "DB_NAME"
          - "DJANGO"
          - "ADMIN_PASSWORD"
        condition: and
# digest: 4b0a0048304602210099fc520723bbf72c75d6f36c89b9a5f497567410daa64cc34464276a02bbac73022100bb9e7b175895be06e6a85684fe75e4df684f15d7df10fad615f55e4777211e3b:922c64590222798bb761d5b6d8e72950