漏洞描述
Odoo database manager was discovered.
id: odoo-database-manager
info:
name: Odoo - Database Manager Discovery
author: __Fazal,R3dg33k
severity: low
description: Odoo database manager was discovered.
classification:
cpe: cpe:2.3:a:odoo:odoo:*:*:*:*:*:*:*:*
metadata:
verified: true
max-request: 1
vendor: odoo
product: odoo
shodan-query:
- title:"Odoo"
- http.title:"odoo"
- cpe:"cpe:2.3:a:odoo:odoo"
fofa-query: title="odoo"
google-query: intitle:"odoo"
tags: panel,odoo,backup,discovery
http:
- method: GET
path:
- '{{BaseURL}}/web/database/manager'
matchers-condition: and
matchers:
- type: word
words:
- "<title>Odoo</title>"
- ".o_database_delete"
condition: and
- type: status
status:
- 200
# digest: 4b0a00483046022100ca6a0ca66c7b19272f792ff9de876f168491c0df6b469fc3fa6596a90dd89eb2022100e97e90b37136ae4355dd35be4af89557e27810907414e1f4cddf55dd30096c3b:922c64590222798bb761d5b6d8e72950