Skip to content

Commit

Permalink
Merge pull request #10387 from NoelV11/main
Browse files Browse the repository at this point in the history
Added Template to detect Exposed Instances of RLOS Cabinet Management…
  • Loading branch information
ritikchaddha authored Jul 30, 2024
2 parents fbc0fa8 + 8cf57b8 commit 75886b8
Showing 1 changed file with 31 additions and 0 deletions.
31 changes: 31 additions & 0 deletions http/misconfiguration/manage-cabinet-register.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,31 @@
id: manage-cabinet-register

info:
name: Manage Cabinet Register - Exposed
author: noel
severity: low
description: |
The path to the Cabinet Storage is omniapp/pages/cabinet/managecabinet.jsf?Action=1. If exposed, it gives an attacker insight into information such as Storage Volume Name, Cabinet Name, it's alias, Deployed AppServer IP Address and Port
reference:
- https://www.edms-consultants.com/newgen-rlos/
metadata:
verified: true
shodan-query: html:"omniapp"
max-request: 1
tags: misconfig,cabinet,exposure

http:
- method: GET
path:
- '{{BaseURL}}/omniapp/pages/cabinet/managecabinet.jsf?Action=1'

matchers-condition: and
matchers:
- type: word
part: body
words:
- 'Manage Cabinet [Register Cabinet]'

- type: status
status:
- 200

0 comments on commit 75886b8

Please sign in to comment.