漏洞描述
WSO2 Management Console default admin credentials were discovered.
id: wso2-default-login
info:
name: WSO2 Management Console Default Login
author: cocxanh
severity: high
description: WSO2 Management Console default admin credentials were discovered.
reference:
- https://docs.wso2.com/display/UES100/Accessing+the+Management+Console
- https://is.docs.wso2.com/en/5.12.0/learn/multi-attribute-login/
tags: default-login,wso2
created: 2023/06/24
rules:
r0:
request:
method: POST
path: /carbon/admin/login_action.jsp
body: username=admin&password=admin
expression: |
response.status == 302 &&
response.raw_header.bcontains(b'/carbon/admin/index.jsp?loginStatus=true') &&
response.raw_header.bcontains(b'JSESSIONID')
expression: r0()