漏洞描述
mantisbt Anonymous login were discovered.
id: mantisbt-anonymous-login
info:
name: mantisbt - Anonymous Login
author: pussycat0x
severity: medium
description: |
mantisbt Anonymous login were discovered.
classification:
cpe: cpe:2.3:a:mantisbt:mantisbt:*:*:*:*:*:*:*:*
metadata:
verified: true
max-request: 1
vendor: mantisbt
product: mantisbt
shodan-query: http.favicon.hash:662709064
tags: default-logins,anonymous,mantisbt,default-login,vuln
http:
- method: GET
path:
- '{{BaseURL}}/my_view_page.php'
matchers-condition: and
matchers:
- type: word
part: body
words:
- '"user-info">anonymous</span>'
- 'My View'
- 'Roadmap'
condition: and
- type: status
status:
- 200
# digest: 4a0a004730450220044139056960bdde189f0be82e3932d8dcd52bebf82e78e3cb0ba1099c1b060e022100ee5001cf0811625f0358e965b3375e015fcfced200b13169261feee05e4de6f8:922c64590222798bb761d5b6d8e72950