漏洞描述
Next JS Config file is exposed.
id: next-js-config-file
info:
name: Next JS Config - File Disclosure
author: DhiyaneshDk
severity: low
description: |
Next JS Config file is exposed.
reference:
- https://nextjs.org/docs/app/api-reference/config/next-config-js
metadata:
verified: true
max-request: 1
shodan-query: html:"next.config.js"
tags: exposure,files,nextjs,vuln
http:
- method: GET
path:
- '{{BaseURL}}/next.config.js'
matchers-condition: and
matchers:
- type: word
part: body
words:
- 'nextConfig'
- 'module.exports ='
condition: and
case-insensitive: true
- type: status
status:
- 200
# digest: 4a0a0047304502205c4508bd68905d224dd1a9f1af0dbc6bb2501d38b6ebc23fe93c2e344b4fc9550221008ddb77dfba216bfea4ab6dd019d5bb1c01fe300cb1e70552cfaf71c407fa3f6f:922c64590222798bb761d5b6d8e72950