id: h2console-panel info: name: H2 Console Web Login Panel - Detect author: righettod severity: info description: H2 Console Web login panel was detected. reference: - https://mp.weixin.qq.com/s/Yn5U8WHGJZbTJsxwUU3UiQ - https://jfrog.com/blog/the-jndi-strikes-back-unauthenticated-rce-in-h2-database-console classification: cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N cwe-id: CWE-200 cpe: cpe:2.3:a:h2database:h2:*:*:*:*:*:*:*:* metadata: max-request: 1 vendor: h2database product: h2 shodan-query: - http.title:"H2 Console" - http.title:"h2 console" - cpe:"cpe:2.3:a:h2database:h2" fofa-query: title="h2 console" google-query: intitle:"h2 console" tags: panel,h2,console,h2database http: - method: GET path: - '{{BaseURL}}/h2-console/login.jsp' matchers: - type: dsl dsl: - "status_code==200" - "contains(tolower(body), 'h2 console')" condition: and # digest: 4a0a00473045022100f6774e325afc8377c86aa638bc23944157ba65ed187c834785dee84e995da71e022019ce6718de1b26c1c0b6f7c7c450a78ddc4f31ab3c71e55b0eaf0f72eabb92d7:922c64590222798bb761d5b6d8e72950