漏洞描述
MemTracker was detected and appeared to be accessible without authentication.
id: memtracker-exposure
info:
name: MemTracker - Exposure
author: DhiyaneshDk
severity: high
description: |
MemTracker was detected and appeared to be accessible without authentication.
classification:
cwe-id: CWE-200
metadata:
verified: true
max-request: 1
shodan-query: html:"memtracker"
tags: memtracker,misconfig,unauth,vuln
http:
- method: GET
path:
- "{{BaseURL}}/mem_tracker"
matchers:
- type: dsl
dsl:
- 'contains_all(body, "MemTracker","Configs")'
- 'status_code == 200'
condition: and
# digest: 490a00463044021f4e06fcc1b4859ab1c06a7dc9e18ae8bf0e233766432f07e1f81ec77cc29c9c022100c9b39295404c899b5d9c482c537e8e792544c04de75a7281411ea3e573716604:922c64590222798bb761d5b6d8e72950