漏洞描述
Detects the exposure of the StrongShop installer page, which could allow unauthorized setup or reinstallation of the application.
id: strongshop-installer
info:
name: StrongShop Installer - Exposure
author: ritikchaddha
severity: high
description: |
Detects the exposure of the StrongShop installer page, which could allow unauthorized setup or reinstallation of the application.
metadata:
verified: true
max-request: 1
product: strongshop
shodan-query: title:"StrongShop"
fofa-query: title="StrongShop"
tags: strongshop,installer,exposure,misconfig,vuln
http:
- method: GET
path:
- "{{BaseURL}}/install/index.html"
matchers-condition: and
matchers:
- type: word
part: body
words:
- 'StrongShop'
- 'id="install'
condition: and
- type: status
status:
- 200
# digest: 4a0a00473045022100a5adeef2c3792f516e10d6477773b90ac91ddf1ce78707c75bf6147932d26ae602204a039e30358e27ab90a76dfa358b59fc0e61465ee07f75342e08f7aa4d872a29:922c64590222798bb761d5b6d8e72950