漏洞描述
Express Stack trace is exposed.
id: express-stack-trace
info:
name: Express Stack Trace
author: DhiyaneshDk
severity: low
description: Express Stack trace is exposed.
metadata:
verified: true
max-request: 1
shodan-query: html:"Welcome to Express"
tags: misconfig,express,intrusive,vuln
http:
- method: GET
path:
- '{{BaseURL}}/{{randstr}}'
matchers-condition: and
matchers:
- type: word
part: body
words:
- "NotFoundError: Not Found"
- "at Function.handle"
condition: and
- type: word
part: header
words:
- "text/html"
- type: status
status:
- 404
# digest: 4b0a00483046022100cadb52e9d1f4202aa2bbc0bf65ae23afead90748aa8f686d8d6eeb92694ffc7c022100beefa6922b3bfff3a1ed9f301d2cd5f571bebf9fcd85d192c37e3e88c88d5e67:922c64590222798bb761d5b6d8e72950