id: lucee-login info: name: Lucee Web and Lucee Server Admin Login Panel - Detect author: dhiyaneshDK,unp4ck severity: info description: Lucee admin login panels were detected in both Web and Server tabs. classification: cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N cvss-score: 0 cwe-id: CWE-200 metadata: max-request: 2 shodan-query: http.title:"Lucee" tags: panel,lucee http: - method: GET path: - '{{BaseURL}}/lucee/admin/web.cfm' - '{{BaseURL}}/lucee/admin/server.cfm' matchers-condition: and matchers: - type: word words: - 'Login - Lucee Web Administrator' - 'Login - Lucee Server Administrator' - "lucee-admin-search-input" - "lucee-docs-search-input" - "server-lucee-small.png.cfm" condition: or - type: status status: - 200 # digest: 4a0a0047304502202b5a0c5a0fbf61bcee73c6c6b35395bcef7e7544704a611d22f91f325ca98375022100812dc41fca9fb0cc4a3922e663aa1b972920bc42fb77bf990d33f4523dd88758:922c64590222798bb761d5b6d8e72950