id: avatier-password-management
info:
name: Avatier Password Management Panel
author: praetorian-thendrickson,iamthefrogy,dhiyaneshDK
severity: info
description: An Avatier password management panel was detected.
reference:
- https://www.exploit-db.com/ghdb/6576
- https://www.avatier.com/products/identity-management/password-management/
classification:
cwe-id: CWE-200
metadata:
max-request: 1
shodan-query: http.favicon.hash:983734701
tags: edb,panel,avatier,aims
http:
- method: GET
path:
- '{{BaseURL}}/aims/ps/'
host-redirects: true
max-redirects: 2
matchers-condition: or
matchers:
- type: word
words:
- 'LabelWelcomeToPS'
- 'Avatier Corporation'
- 'Welcome to Password Management'
condition: or
- 'Password Management Client'
# digest: 4b0a00483046022100e1eacbb28776488dbae4033987f670b282631746a55dd5e2b3ad8002791b3ce4022100bb3bacf8ae87c87dfc04779d72c3bba1f605196dd7d9b6b698360853ad8d3c61:922c64590222798bb761d5b6d8e72950