漏洞描述
QloApps Installation Assistant panel exposure.
id: qloapps-installer
info:
name: QloApps - Installation
author: ritikchaddha
severity: high
description: |
QloApps Installation Assistant panel exposure.
classification:
cpe: cpe:2.3:a:webkul:qloapps:*:*:*:*:*:*:*:*
metadata:
verified: true
max-request: 1
vendor: webkul
product: qloapps
fofa-query: title="QloApps Installation"
tags: install,qloapps,misconfig,exposure,vuln
http:
- method: GET
path:
- "{{BaseURL}}/install/"
host-redirects: true
max-redirects: 2
matchers-condition: and
matchers:
- type: word
part: body
words:
- "<title>QloApps Installation"
case-insensitive: true
- type: status
status:
- 200
# digest: 490a0046304402207aa32eb051e184c33c646f43c912117db0025f81000a9f4918d724762d8fb3e502205d9b5b102aa4a6f2dd8cf7e761459d584b4d22b5c00cd1f8ecb26f94f0804011:922c64590222798bb761d5b6d8e72950