id: avatier-password-management
info:
name: Avatier Password Management Panel
author: praetorian-thendrickson,iamthefrogy,dhiyaneshDK
severity: info
description: An Avatier password management panel was detected.
reference:
- https://www.exploit-db.com/ghdb/6576
- https://www.avatier.com/products/identity-management/password-management/
classification:
cwe-id: CWE-200
metadata:
max-request: 1
shodan-query: http.favicon.hash:983734701
tags: edb,panel,avatier,aims
http:
- method: GET
path:
- '{{BaseURL}}/aims/ps/'
host-redirects: true
max-redirects: 2
matchers-condition: or
matchers:
- type: word
words:
- 'LabelWelcomeToPS'
- 'Avatier Corporation'
- 'Welcome to Password Management'
condition: or
- 'Password Management Client'