joomla-file-listing: Joomla! Database File List

日期: 2025-08-01 | 影响软件: Joomla Database File List | POC: 已公开

漏洞描述

A Joomla! database directory /libraries/joomla/database/ was found exposed and has directory indexing enabled.

PoC代码[已公开]

id: joomla-file-listing

info:
  name: Joomla! Database File List
  author: iampritam
  severity: medium
  description: A Joomla! database directory /libraries/joomla/database/ was found exposed and has directory indexing enabled.
  remediation: Disable directory indexing on the /libraries/joomla/database/ directory or remove the content from the web root. If the databases can be download, rotate any credentials contained in the databases.
  reference:
    - https://www.exploit-db.com/ghdb/6377
  classification:
    cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
    cvss-score: 5.3
    cwe-id: CWE-548
  metadata:
    max-request: 1
  tags: exposure,joomla,listing,database,edb,vuln

http:
  - method: GET
    path:
      - "{{BaseURL}}/libraries/joomla/database/"

    matchers-condition: and
    matchers:
      - type: word
        words:
          - "Index of /libraries/joomla/database"
          - "Parent Directory"
        condition: and

      - type: status
        status:
          - 200
# digest: 4a0a0047304502207d0c388739af82de3d2382af80ff6d1c20202f648bafc3476e963d02a0dcfc75022100b9ac5aefc6996cb53b4c98abf563f5e41d032caed99a884bcb5683aa1c09b220:922c64590222798bb761d5b6d8e72950