漏洞描述
Supervisor Dashboard was detected and appeared to be accessible without authentication.
id: unauth-supervisor-dashboard
info:
name: Unauth Supervisor Dashboard - Detect
author: DhiyaneshDk
severity: high
description: |
Supervisor Dashboard was detected and appeared to be accessible without authentication.
classification:
cwe-id: CWE-200
metadata:
verified: true
max-request: 1
shodan-query: title:"Supervisor Status"
tags: supervisor,misconfig,unauth,dashboard,vuln
http:
- method: GET
path:
- "{{BaseURL}}"
matchers:
- type: dsl
dsl:
- 'contains_all(body, "Supervisor Status","State","Action")'
- 'status_code == 200'
condition: and
# digest: 490a004630440220749eddd13d8c4eba8cca793cf4958d28147c55dacf93dc1aa5df66e8301ff3ed0220171d0b5aaea6d878eae25d3067343d7720547483144ecf3a44878023e3da84e6:922c64590222798bb761d5b6d8e72950