
Cloud Vulnerability DB
A community-led vulnerabilities database
The admin url can be discovered without prior knowledge of it's location by exploiting the X-Original-Url header on some configurations.
The bug comes from the Zend library and is patche by unsetting the header in the bootstrap process.
Unset the X-Original-Url header in the web server configuration.
The activation of these headers is coming from the Zend_Controller module. It appears this has been known to some degree since 2016 - https://peterocallaghan.co.uk/2016/12/magento-poisoning-cache/ (dead link now..)
Anees Hyder ( @anees0xdev ) via HackerOne https://hackerone.com/anees0x_dev/hacktivity
Source: NVD
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."