id: phpmyadmin-misconfiguration info: name: Sensitive data exposure author: pussycat0x severity: high description: Unauthenticated phpmyadmin leads expose sensitive information reference: https://www.exploit-db.com/ghdb/6997 tags: phpmyadmin,misconfig requests: - method: GET path: - "{{BaseURL}}/phpmyadmin/sql.php?server=1" matchers-condition: and matchers: - type: word words: - "Database" - type: status status: - 200