漏洞描述
fofa: title="Jeecg-Boot"
id: jeecg-boot-unauth
info:
name: Jeecg Boot Unauth
author: zan8in
severity: high
verified: true
description: |
fofa: title="Jeecg-Boot"
rules:
r0:
request:
method: GET
path: /jeecg-boot/
expression: response.status == 200 && response.body.bcontains(b'<title>Swagger-Bootstrap-UI</title>')
r1:
request:
method: GET
path: /jeecg-boot/swagger-resources
expression: |
response.status == 200 &&
response.body.bcontains(b'"name":') &&
response.body.bcontains(b'"url":') &&
response.body.bcontains(b'"swaggerVersion":') &&
response.body.bcontains(b'"location":')
expression: r0() || r1()