bigant-db-install: Bigant DataBase - Exposed Installation

日期: 2025-08-01 | 影响软件: Bigant DataBase | POC: 已公开

漏洞描述

Bigant DataBase Installation page exposure due to misconfiguration.

PoC代码[已公开]

id: bigant-db-install

info:
  name: Bigant DataBase - Exposed Installation
  author: pussycat0x
  severity: high
  description: |
    Bigant DataBase Installation page exposure due to misconfiguration.
  metadata:
    verified: true
    fofa-query: body="BigAntSetup"
    max-request: 1
  tags: misconfig,install,bigant,database,vuln

http:
  - raw:
      - |
        GET /install/update.html  HTTP/1.1
        Host: {{Hostname}}

    matchers-condition: and
    matchers:
      - type: word
        part: body
        words:
          - "BigAnt Database Upgrade Wizard1"
          - "//DB-MS"
          - "<title>BigAntSetup"
        condition: and

      - type: status
        status:
          - 200
# digest: 4b0a00483046022100ae56518704ac7f17e64b58e3535721c052df197758bc3ddb8db483acd3e7872c0221009c928202df58248847dd980f3ab300f2c56e4582cefdad33303906871fb3dc81:922c64590222798bb761d5b6d8e72950