id: bigant-db-install info: name: Bigant DataBase - Exposed Installation author: pussycat0x severity: high description: | Bigant DataBase Installation page exposure due to misconfiguration. metadata: verified: true fofa-query: body="BigAntSetup" max-request: 1 tags: misconfig,install,bigant,database http: - raw: - | GET /install/update.html HTTP/1.1 Host: {{Hostname}} matchers-condition: and matchers: - type: word part: body words: - "BigAnt Database Upgrade Wizard1" - "//DB-MS" - "BigAntSetup" condition: and - type: status status: - 200 # digest: 4a0a00473045022100afa935969b8caf63c781fb85607a809c0dba17e14e157d1cd1ea1bd605f5d1b1022037fe370a2b737aac6d34ce4c27226bb808550b7eb424bf96781ccbf891e55d50:922c64590222798bb761d5b6d8e72950