漏洞描述
Detects exposed GLPI Setup page.
id: glpi-installer
info:
name: GLPI Installation Page - Exposure
author: DhiyaneshDK
severity: high
description: |
Detects exposed GLPI Setup page.
reference:
- https://glpi-project.org/
classification:
cpe: cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:*
metadata:
verified: true
max-request: 1
vendor: glpi-project
product: glpi
shodan-query: html:"Setup GLPI"
tags: misconfig,install,exposure,glpi,vuln
http:
- method: GET
path:
- "{{BaseURL}}/install/install.php"
matchers-condition: and
matchers:
- type: word
part: body
words:
- "Setup GLPI"
- type: status
status:
- 200
# digest: 4a0a00473045022079984e5ab08cd1a78c9210a78f6b69acd84208a155c35e8a71b256677f128c2302210082bde2987de32d3ce7403f95a90776ee1437fbe4e27df182c6fd7d502200260a:922c64590222798bb761d5b6d8e72950