id: phpmyadmin-misconfiguration info: name: Sensitive data exposure author: pussycat0x severity: high description: Unauthenticated phpmyadmin leads to exposure of sensitive information reference: https://www.exploit-db.com/ghdb/6997 tags: phpmyadmin,misconfig requests: - method: GET path: - "{{BaseURL}}/phpmyadmin/index.php?db=information_schema" - "{{BaseURL}}/phpMyAdmin/index.php?db=information_schema" matchers-condition: and matchers: - type: word words: - "var db = 'information_schema';" - "var opendb_url = 'db_structure.php';" condition: and - type: status status: - 200