漏洞描述
DOMPDF Configuration page was detected, which contains paths, library versions and other potentially sensitive information
id: dompdf-config
info:
name: DomPDF - Configuration Page
author: kazet
severity: low
description: |
DOMPDF Configuration page was detected, which contains paths, library versions and other potentially sensitive information
classification:
cwe-id: CWE-200
cpe: cpe:2.3:a:dompdf_project:dompdf:*:*:*:*:*:*:*:*
metadata:
verified: true
max-request: 6
fofa-query: title="dompdf - The PHP 5 HTML to PDF Converter"
product: dompdf
vendor: dompdf_project
tags: config,exposure,dompdf,vuln
http:
- method: GET
path:
- "{{BaseURL}}/www/setup.php"
- "{{BaseURL}}/dompdf/dompdf/www/setup.php"
- "{{BaseURL}}/js/dompdf/www/setup.php"
- "{{BaseURL}}/portal/application/libraries/dompdf/www/setup.php"
- "{{BaseURL}}/sites/all/libraries/dompdf/www/setup.php"
- "{{BaseURL}}/vendor/dompdf/dompdf/www/setup.php"
stop-at-first-match: true
matchers-condition: and
matchers:
- type: word
part: body
words:
- 'HTML to PDF Converter</title>'
- '<td class="title">DOMPDF_PDF_BACKEND</td>'
condition: and
- type: status
status:
- 200
# digest: 490a00463044022013a3e6473cee1de1146b920ee4930ce161fe2964a5bcca4b869726733df8e741022024670bd41976c73f14d77e4e07384629e03da87d4091edd1bb7c072be22b21a3:922c64590222798bb761d5b6d8e72950