websheets-config: Websheets Configuration File - Detect

日期: 2025-08-01 | 影响软件: websheets | POC: 已公开

漏洞描述

Websheets configuration file was detected.

PoC代码[已公开]

id: websheets-config

info:
  name: Websheets Configuration File - Detect
  author: geeknik
  severity: high
  description: Websheets configuration file was detected.
  reference:
    - https://github.com/daveagp/websheets
  classification:
    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
    cvss-score: 7.5
    cwe-id: CWE-200
  metadata:
    verified: true
    max-request: 2
  tags: websheets,config,exposure,files,vuln

http:
  - method: GET
    path:
      - '{{BaseURL}}/ws-config.json'
      - '{{BaseURL}}/ws-config.example.json'

    stop-at-first-match: true

    matchers-condition: and
    matchers:
      - type: word
        words:
          - '"db-password":'
          - '"db-database":'
        condition: and

      - type: status
        status:
          - 200
# digest: 4a0a0047304502204d68e5a05883979f97d0895957da9cd0aa8cd832bde34af46eeb233b9f195265022100b52eca26de44430abccc25b2169e0f87beb696280be9af8678f4c3e8233631e9:922c64590222798bb761d5b6d8e72950