info: name: Saltbo/zpan Installer - Exposure author: ritikchaddha severity: high description: | Detects the exposure of the Saltbo/zpan installer page, which could allow unauthorized setup or reinstallation of the application. reference: - https://github.com/saltbo/zpan metadata: verified:true product: zpan vendor: saltbo fofa-query: body="zpan" tags: saltbo,zpan,installer,exposure,misconfig
http: -method: GET path: -"{{BaseURL}}/api/system/options/core.email" -"{{BaseURL}}/install"
matchers-condition: and matchers: -type: word part: body_2 words: -"<title>ZPan"
-type: word part: body_1 words: -"system is not initialized"