id: phpmyadmin-panel info: name: phpMyAdmin Panel - Detect author: pdteam,righettod severity: info description: phpMyAdmin panel was detected. classification: cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N cwe-id: CWE-200 cpe: cpe:2.3:a:phpmyadmin:phpmyadmin:*:*:*:*:*:*:*:* metadata: max-request: 14 vendor: phpmyadmin product: phpmyadmin shodan-query: - "http.title:phpMyAdmin" - http.title:"phpmyadmin" - http.component:"phpmyadmin" - cpe:"cpe:2.3:a:phpmyadmin:phpmyadmin" fofa-query: - body="pma_servername" && body="4.8.4" - title="phpmyadmin" google-query: intitle:"phpmyadmin" hunter-query: app.name="phpmyadmin"&&web.body="pma_servername"&&web.body="4.8.4" tags: panel,phpmyadmin http: - method: GET path: - "{{BaseURL}}{{paths}}" payloads: paths: - "" - "/phpmyadmin/" - "/admin/phpmyadmin/" - "/_phpmyadmin/" - "/administrator/components/com_joommyadmin/phpmyadmin/" - "/apache-default/phpmyadmin/" - "/blog/phpmyadmin/" - "/forum/phpmyadmin/" - "/php/phpmyadmin/" - "/typo3/phpmyadmin/" - "/web/phpmyadmin/" - "/xampp/phpmyadmin/" - "/phpMyAdmin/" - "/phpma/" - "/phpMyAdmin/index.php" stop-at-first-match: true matchers: - type: word words: - "phpMyAdmin" - "pmahomme" extractors: - type: regex part: body group: 1 regex: - 'v=([a-z0-9-._]+)' # digest: 490a004630440220722f0389c7c04acc81fc50271521330e06cc1892b6d0978221b61b7c8566f79f02202c408aef3764fd5cbb398ab90944e34e4900f42c8c8c2f9b66b837ab4fb3fc50:922c64590222798bb761d5b6d8e72950