漏洞描述
Limesurvey is susceptible to the Installation page exposure due to misconfiguration.
id: limesurvey-installer
info:
name: Limesurvey Installer Exposure
author: DhiyaneshDk
severity: high
description: Limesurvey is susceptible to the Installation page exposure due to misconfiguration.
classification:
cpe: cpe:2.3:a:limesurvey:limesurvey:*:*:*:*:*:*:*:*
metadata:
verified: true
max-request: 1
shodan-query: html:"Limesurvey Installer"
product: limesurvey
vendor: limesurvey
tags: misconfig,limesurvey,install,vuln
http:
- method: GET
path:
- '{{BaseURL}}/index.php?r=installer/welcome'
matchers-condition: and
matchers:
- type: word
part: body
words:
- 'LimeSurvey installer'
- 'Progress'
- 'Your preferred language will be used through out the installation process'
condition: and
- type: word
part: header
words:
- "text/html"
- type: status
status:
- 200
# digest: 4b0a004830460221009154e774d079a9b2ba130d3baec9517f3b663831d5e0e26cb64e151411532d34022100f4b10b34919ca37cc28e321c9b2d43745fa6d85449824ed24495288cc1925c70:922c64590222798bb761d5b6d8e72950