filebrowser-unauth: File Browser Dashboard - Unauthenticated Access

日期: 2025-08-01 | 影响软件: File Browser Dashboard | POC: 已公开

漏洞描述

File Browser dashboard is exposed.

PoC代码[已公开]

id: filebrowser-unauth

info:
  name: File Browser Dashboard - Unauthenticated Access
  author: ritikchaddha
  severity: medium
  description: File Browser dashboard is exposed.
  reference:
    - https://filebrowser.org/
  metadata:
    verified: true
    max-request: 2
    shodan-query: http.favicon.hash:1052926265
    product: filebrowser
    vendor: filebrowser
    fofa-query: icon_hash=1052926265
  tags: misconfig,filebrowser,unauth,vuln

http:
  - method: GET
    path:
      - "{{BaseURL}}"
      - "{{BaseURL}}/login"

    stop-at-first-match: true
    host-redirects: true
    max-redirects: 2

    matchers-condition: and
    matchers:
      - type: word
        part: body
        words:
          - 'File Browser</title>'
          - 'window.FileBrowser'
        condition: or

      - type: word
        part: body
        words:
          - 'LoginPage":false'
          - '"NoAuth":true'
        condition: and
# digest: 490a00463044022000bd94fe24d397b7676d384916bd36954137c26bdb95887068b49a014e926587022076cb33a28ac915b4d7a7825d770d19a2314113ed558ec68ffb2a883ff11f4915:922c64590222798bb761d5b6d8e72950