umbraco-directory-listing: Umbraco CMS - Directory Listing Exposure

日期: 2026-01-24 | 影响软件: Umbraco CMS | POC: 已公开

漏洞描述

Detected directory listing enabled on sensitive Umbraco CMS directories, potentially exposing configuration files, logs, backups, and other sensitive data.

PoC代码[已公开]

id: umbraco-directory-listing

info:
  name: Umbraco CMS - Directory Listing Exposure
  author: DhiyaneshDk
  severity: medium
  description: |
    Detected directory listing enabled on sensitive Umbraco CMS directories, potentially exposing configuration files, logs, backups, and other sensitive data.
  reference:
    - https://docs.umbraco.com/umbraco-cms/reference/security/security-hardening
  classification:
    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
    cvss-score: 5.3
    cwe-id: CWE-548
  metadata:
    max-request: 2
    verified: true
    shodan-query: http.html:"umbraco"
  tags: umbraco,misconfig,exposure,cms,vuln

http:
  - method: GET
    path:
      - "{{BaseURL}}/App_Data/"
      - "{{BaseURL}}/App_Plugins/"

    stop-at-first-match: true

    matchers:
      - type: dsl
        dsl:
          - 'status_code == 200'
          - 'contains_all(body, "/App_Plugins/", "[To Parent Directory]")'
        condition: and
# digest: 4a0a0047304502205d789351294aee1cff416c17d09d17c7dabff2566126e1d494f5f94eedf71d24022100c7468a9a15dc89f7313989881e8c5fa40c94c7ad65c0de0adbbfe8f66059aa9d:922c64590222798bb761d5b6d8e72950

相关漏洞推荐