server-monitor-installer: Server Monitor Installer

日期: 2025-08-01 | 影响软件: servermonitorinstaller | POC: 已公开

漏洞描述

Server Monitor is susceptible to the Installation page exposure due to misconfiguration.

PoC代码[已公开]

id: server-monitor-installer

info:
  name: Server Monitor Installer
  author: tess
  severity: high
  description: Server Monitor is susceptible to the Installation page exposure due to misconfiguration.
  classification:
    cpe: cpe:2.3:a:poweradmin:pa_server_monitor:*:*:*:*:*:*:*:*
  metadata:
    verified: true
    max-request: 1
    vendor: poweradmin
    product: pa_server_monitor
    shodan-query: title:"SERVER MONITOR - Install"
  tags: misconfig,monitor,exposure,install,vuln

http:
  - method: GET
    path:
      - '{{BaseURL}}/install.php'

    matchers-condition: and
    matchers:
      - type: word
        part: body
        words:
          - "<title>SERVER MONITOR - Install</title>"
          - "PHP Server Monitor - Install"
          - "install.php?action=config"
        condition: and

      - type: word
        part: header
        words:
          - "text/html"

      - type: status
        status:
          - 200
# digest: 4a0a00473045022100abdb010f8f6c47972f846e90127a3cbb6c3472a8beaf1ec2ffcf6e8edc329dfc022021dcff512bb77ee019c6946e9ff888fc5dcc53646568182a8cd9a0c0538eae97:922c64590222798bb761d5b6d8e72950