msmtp-config: Msmtp - Config Exposure

日期: 2025-08-01 | 影响软件: msmtp config | POC: 已公开

漏洞描述

Msmtp configuration was discovered.

PoC代码[已公开]

id: msmtp-config

info:
  name: Msmtp - Config Exposure
  author: geeknik
  severity: high
  description: Msmtp configuration was discovered.
  reference:
    - https://wiki.archlinux.org/title/Msmtp
  metadata:
    verified: true
    max-request: 1
  tags: exposure,msmtp,vuln

http:
  - method: GET
    path:
      - "{{BaseURL}}/.msmtprc"

    matchers-condition: and
    matchers:
      - type: word
        words:
          - 'account'
          - 'host'
          - 'from'
          - 'auth'
          - 'tls'
        condition: and

      - type: word
        part: header
        words:
          - 'text/plain'
          - 'octet-stream'
        condition: or

      - type: status
        status:
          - 200
# digest: 480a00453043021f3d77bbd9df375e5aefe187e3ab15b28afedddc32f930bf420c5400a65f10a6022018ffdac74f35c2640ed28929f6ba08864e1b54a54a3ef1549515049dd0ab9345:922c64590222798bb761d5b6d8e72950