xoops-installation-wizard: XOOPS Installation Wizard Panel - Detect

日期: 2025-08-01 | 影响软件: xoops installation wizard | POC: 已公开

漏洞描述

XOOPS Installation Wizard panel was detected.

PoC代码[已公开]

id: xoops-installation-wizard

info:
  name: XOOPS Installation Wizard Panel - Detect
  author: princechaddha
  severity: low
  description: XOOPS Installation Wizard panel was detected.
  classification:
    cpe: cpe:2.3:a:xoops:xoops:*:*:*:*:*:*:*:*
  metadata:
    max-request: 1
    vendor: xoops
    product: xoops
  tags: panel,xoops,discovery

http:
  - method: GET
    path:
      - "{{BaseURL}}/install/page_start.php"

    matchers-condition: and
    matchers:
      - type: regex
        regex:
          - "(?i)(<title>(.*)XOOPS Installation Wizard(.*)</title>)"
          - "(?i)(<title>(.*)XOOPS 安裝精靈(.*)</title>)"
        condition: or
# digest: 4b0a00483046022100fbe4198dedce406709692594ce470948585ef9e91db9b6815a5132d3874535bc022100ffcbb4cc86ed6f0b514696f73b70c45ec216db54c1d68dc5f416ea59b608ce28:922c64590222798bb761d5b6d8e72950