File producer metadata leakage
If the web application generates files (e.g. pdf), using exiftools (or other techniques), the Producer can be found which created it. If the producer is known, e.g. Producer: iText 2.1.7 or Producer: mPDF 7.1.7 the attacker can discover whether any CVEs exist for such a tool leading to successful exploitation.
Although I was able to find https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/01-Information_Gathering/, but it doesn't reference this specific need in my opinion. Therefore, I'd like to extend the Information Gathering with a new content.
Would you like to be assigned to this issue?
no
File producer metadata leakage
If the web application generates files (e.g. pdf), using exiftools (or other techniques), the Producer can be found which created it. If the producer is known, e.g.
Producer: iText 2.1.7orProducer: mPDF 7.1.7the attacker can discover whether any CVEs exist for such a tool leading to successful exploitation.Although I was able to find https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/01-Information_Gathering/, but it doesn't reference this specific need in my opinion. Therefore, I'd like to extend the Information Gathering with a new content.
Would you like to be assigned to this issue?
no