jquery / jquerymobile.com

jQuery Mobile web site content
http://jquerymobile.com
Other
54 stars 65 forks source link

Nginx version disclosure via forbidden Page #140

Closed Sajibekanti closed 3 years ago

Sajibekanti commented 7 years ago

Hello I am Sajibe Kanti I Have Found A Bug on your Web .

Vulnerability : Nginx version disclosure via forbidden Page

This information might help an attacker gain a greater understanding of the systems in use and potentially develop further attacks targeted at the specific version of Nginx.

Impact: An attacker might use the disclosed information to harvest specific security vulnerabilities for the version identified.

Steps to reproduce:

Go to http://jquerymobile.com/jquery-wp-content/themes/jquerymobile.com/i/

Now the nginx version shows in bottom.

Reference : https://hackerone.com/reports/194319

Thanks Sajibe Kanti

mgol commented 3 years ago

This is no longer exposed now.