platformio-ini: Platformio Config File Disclosure

日期: 2025-08-01 | 影响软件: Platformio | POC: 已公开

漏洞描述

“platformio.ini” (Project Configuration File) was detected.

PoC代码[已公开]

id: platformio-ini

info:
  name: Platformio Config File Disclosure
  author: DhiyaneshDK
  severity: low
  description: “platformio.ini” (Project Configuration File) was detected.
  reference:
    - https://docs.platformio.org/en/stable/projectconf/index.html
  metadata:
    verified: true
    max-request: 1
    google-query: inurl:"/platformio.ini"
    github-query: '[platformio] language:INI'
  tags: config,exposure,platformio,vuln

http:
  - method: GET
    path:
      - "{{BaseURL}}/platformio.ini"

    matchers-condition: and
    matchers:
      - type: word
        words:
          - "[platformio]"
          - "platform ="
          - "board ="
        condition: and

      - type: status
        status:
          - 200
# digest: 4a0a00473045022024ce1600c6913b4f861566bf91089c0d8a63c8b87e5bc7e5b633808e7c9e7293022100f9186e2dd321ce752f826d6a6b2656aab6f2fd94d486cd61e7c61f84d8208601:922c64590222798bb761d5b6d8e72950