sensitive-storage-data-expose: Sensitive Storage Data - Detect

日期: 2025-08-01 | 影响软件: sensitive-storage | POC: 已公开

漏洞描述

A generic search for 'storage' in sensitive key files, file names, logs, etc., returned a match.

PoC代码[已公开]

id: sensitive-storage-data-expose

info:
  name: Sensitive Storage Data - Detect
  author: pussycat0x
  severity: medium
  description: A generic search for 'storage' in sensitive key files, file names, logs, etc., returned a match.
  reference:
    - https://www.exploit-db.com/ghdb/6304
  classification:
    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
    cvss-score: 5.3
    cwe-id: CWE-200
  metadata:
    max-request: 6
  tags: expose,listing,config,logs,storage,edb,files,exposure,vuln

http:
  - method: GET
    path:
      - "{{BaseURL}}/storage/"
      - "{{BaseURL}}/api_smartapp/storage/"
      - "{{BaseURL}}/equipbid/storage/"
      - "{{BaseURL}}/server/storage/"
      - "{{BaseURL}}/intikal/storage/"
      - "{{BaseURL}}/elocker_old/storage/"

    stop-at-first-match: true

    matchers-condition: and
    matchers:
      - type: word
        words:
          - "Index of"
          - "oauth-private.key"
          - "oauth-private.key"
        condition: and

      - type: status
        status:
          - 200
# digest: 4b0a00483046022100aaaf0580a47c061115e5ea083e115e1dd131c484ef01155276a32a9ad2c2b410022100b7d103471a06e8c7364e2fbcee40b458d8ebb959b09ba62309de43d6e029206d:922c64590222798bb761d5b6d8e72950