nuclei-templates/misconfiguration/phpmyadmin/phpmyadmin-server-import.yaml

36 lines
984 B
YAML
Raw Normal View History

id: pma-server-import
info:
name: PhpMyAdmin Server Import
author: Cristi vlad (@cristivlad25)
severity: high
description: Finds Unauthenticated PhpMyAdmin Server Import Pages.
2021-10-15 19:39:19 +00:00
tags: phpmyadmin,misconfig
requests:
- method: GET
path:
- "{{BaseURL}}/pma/server_import.php"
- "{{BaseURL}}/phpmyadmin/server_import.php"
- "{{BaseURL}}/phpMyAdmin 2/server_import.php"
- "{{BaseURL}}/db/server_import.php"
2021-10-15 19:40:48 +00:00
- "{{BaseURL}}/server_import.php"
- "{{BaseURL}}/PMA/server_import.php"
- "{{BaseURL}}/admin/server_import.php"
- "{{BaseURL}}/admin/pma/server_import.php"
- "{{BaseURL}}/phpMyAdmin/server_import.php"
- "{{BaseURL}}/admin/phpMyAdmin/server_import.php"
2021-10-15 19:39:19 +00:00
stop-at-first-match: true
matchers-condition: and
matchers:
- type: word
2021-10-15 19:39:19 +00:00
condition: and
words:
- "File to import"
- "Location of the text file"
2021-10-15 19:39:19 +00:00
- type: status
status:
2021-10-15 19:35:33 +00:00
- 200