ProjectDiscovery's nuclei-templates repository received new pull requests to detect exposed installation interfaces in ModX CMS and Revive Adserver, highlighting a common web misconfiguration that can leave setup pages accessible after deployment. The ModX submission, pull request #15757, adds a template for identifying an unfinished installation page, while pull request #15759 targets Revive Adserver instances exposing installer endpoints through two common installation wizard paths.
Both templates were submitted by DhiyaneshGeek and were described as validated against vulnerable and non-vulnerable targets to improve true-positive accuracy and reduce false positives. Automated review reported no security issues in the Revive Adserver template, and the ModX template was marked Done and Ready to merge, while the Revive Adserver detection remained open pending human review from theamanrawat.

See real exploitation activity before you spend the cycle.
4 events from the most recent confirmed update back to the earliest known activity.
A GitHub pull request (#15785) was opened by pussycat0x to add an icinga-installer.yaml Nuclei template for detecting exposed Icinga installer pages. The submission states it was validated against vulnerable and patched hosts to confirm true positives and reduce false positives, and it was marked ready to merge.
A GitHub pull request (#15759) was opened by DhiyaneshGeek to add a Nuclei template for detecting exposed Revive Adserver installer pages. The template targeted common installation wizard paths and was described as validated against vulnerable and patched configurations.
A GitHub pull request (#15758) was opened by DhiyaneshGeek to add a Nuclei template for detecting unfinished AzuraCast installation pages. The submission was described as a detection template contribution and was marked ready to merge pending human review.
A GitHub pull request (#15757) was opened by DhiyaneshGeek to add a Nuclei template that detects unfinished installation pages in ModX CMS. The submission states it was validated against both vulnerable or misconfigured and patched or non-vulnerable hosts to reduce false positives.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
4 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.