漏洞描述
Detects exposed Virtual SmartZone Installation page.
id: virtual-smartzone-installer
info:
name: Virtual SmartZone Setup Wizard - Exposure
author: DhiyaneshDK
severity: high
description: |
Detects exposed Virtual SmartZone Installation page.
reference:
- https://support.ruckuswireless.com/products/83-virtual-smartzone-vsz
metadata:
verified: true
max-request: 1
shodan-query: html:"Virtual SmartZone"
tags: misconfig,install,exposure,virtual-smartzone,vuln
http:
- method: GET
path:
- "{{BaseURL}}/adminweb/"
matchers-condition: and
matchers:
- type: word
part: body
words:
- "Virtual SmartZone"
- "Setup Wizard"
condition: and
- type: status
status:
- 200
# digest: 4a0a0047304502202444a6ebbec48a38450a82280f9099de0a310073f1d76687a908bfcd9362db35022100e3b90c20f6741eae0363c48d9d79fb814dd5c409c493561d8335e307ea52db5d:922c64590222798bb761d5b6d8e72950