Skip to content

False positive in PHP frameworks with verbose debugging enabled #14248

@aushack

Description

@aushack

https://github.com/projectdiscovery/nuclei-templates/blob/85577670d2f4a8e6037752c87ca113803d6a2213/http/misconfiguration/ingress-nginx-valid-admission.yaml#L55C5-L55C14

Should this match include an 'and' for status code 200? I don't have an environment to check the correct HTTP response.

Observed false detection in PHP environments with 405 Method Not Allowed with verbose debugging enabled that will return true for all 3 matchers.

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions