grails-database-admin-console: Grails Admin Console Panel - Detect

日期: 2025-08-01 | 影响软件: grails database admin console | POC: 已公开

漏洞描述

Grails Admin Console panel was detected.

PoC代码[已公开]

id: grails-database-admin-console

info:
  name: Grails Admin Console Panel - Detect
  author: emadshanab
  severity: medium
  description: Grails Admin Console panel was detected.
  reference:
    - https://www.acunetix.com/vulnerabilities/web/grails-database-console/
    - http://h2database.com/html/quickstart.html#h2_console
  classification:
    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
    cvss-score: 5.3
    cwe-id: CWE-200
    cpe: cpe:2.3:a:grails:grails:*:*:*:*:*:*:*:*
  metadata:
    max-request: 2
    vendor: grails
    product: grails
  tags: grails,panel,discovery

http:
  - method: GET
    path:
      - '{{BaseURL}}/dbconsole/'
      - '{{BaseURL}}/h2-console/'

    matchers-condition: and
    matchers:
      - type: word
        words:
          - "<title>H2 Console</title>"

      - type: word
        words:
          - "Sorry, remote connections ('webAllowOthers') are disabled on this server"
        negative: true
# digest: 4a0a00473045022021fe6e0ef72f15fffda92875e92f89abdf9291e0b1e64f435765dd9564874cf8022100b7423fc8c549f6a3334d56ab6cf0a0b8c82c39da24f5f01894776cdd701e1008:922c64590222798bb761d5b6d8e72950