漏洞描述
Pritunl is susceptible to the Installation page exposure due to misconfiguration.
id: pritunl-installer
info:
name: Pritunl - Installation
author: DhiyaneshDk
severity: high
description: |
Pritunl is susceptible to the Installation page exposure due to misconfiguration.
reference:
- https://pritunl.com/
- https://docs.pritunl.com/docs/installation
metadata:
verified: true
max-request: 1
fofa-query: title="Pritunl Database Setup"
tags: pritunl,misconfig,installer,vuln
http:
- method: GET
path:
- "{{BaseURL}}/setup"
matchers:
- type: dsl
dsl:
- "contains(body, '<title>Pritunl Database Setup</title>')"
- "status_code == 200"
condition: and
# digest: 4a0a00473045022100cf46f4d5dc05ecefc1d249316b5a6717af122b813c8391dcf031e671d42a6db502206402462e0900a15a17afb814a96143641d24ddf85acd2b9798c0a6af78bfa74b:922c64590222798bb761d5b6d8e72950