id: adminer-panel info: name: Adminer Login Panel - Detect author: random_robbie,meme-lord,ritikchaddha severity: info description: An Adminer login panel was detected. reference: - https://blog.sorcery.ie/posts/adminer/ classification: cwe-id: CWE-200 cpe: cpe:2.3:a:adminer:adminer:*:*:*:*:*:*:*:* metadata: verified: true max-request: 8 vendor: adminer product: adminer shodan-query: - title:"Login - Adminer" - cpe:"cpe:2.3:a:adminer:adminer" - http.title:"login - adminer" fofa-query: - title="login - adminer" - app="adminer" && body="4.7.8" hunter-query: app.name="adminer"&&web.body="4.7.8" google-query: intitle:"login - adminer" tags: panel,adminer http: - method: GET path: - '{{BaseURL}}/adminer.php' - '{{BaseURL}}/_adminer.php' - '{{BaseURL}}/adminer/' - '{{BaseURL}}/editor.php' - '{{BaseURL}}/mysql.php' - '{{BaseURL}}/sql.php' - '{{BaseURL}}/wp-content/plugins/adminer/adminer.php' - '{{BaseURL}}/admin.php' headers: Accept-Language: en-US,en;q=0.5 stop-at-first-match: true matchers-condition: and matchers: - type: word words: - "Adminer" - "Adminer" condition: or - type: status status: - 200 extractors: - type: regex part: body group: 1 regex: - '([0-9.]+)' # digest: 4a0a0047304502206ce0b5960f5fe32a8e390234c8a7c22b5a542baee68cda8e707f2206ecb06087022100fdd8f01155bc72d801c1699b299a664478f5bc3b4c62096d65c5f595a1f2d1e9:922c64590222798bb761d5b6d8e72950