nuclei-templates/default-logins/alphaweb/alphaweb-default-login.yaml

44 lines
923 B
YAML
Raw Normal View History

2021-10-06 12:44:12 +00:00
id: alphaweb-default-login
info:
name: AlphaWeb XE Default Login
author: Lark Lab
severity: medium
description: An AlphaWeb XE default login was discovered.
reference:
- https://wiki.zenitel.com/wiki/AlphaWeb
classification:
cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
cvss-score: 5.8
cwe-id: CWE-522
tags: default-login,AlphaWeb
2021-10-06 12:44:12 +00:00
requests:
- raw:
- |
GET /php/node_info.php HTTP/1.1
Host: {{Hostname}}
Authorization: Basic {{base64(username + ':' + password)}}
Referer: {{BaseURL}}
attack: pitchfork
payloads:
username:
- admin
password:
- alphaadmin
matchers-condition: and
matchers:
- type: word
words:
- "HW Configuration"
- "SW Configuration"
condition: and
- type: status
status:
- 200
# Enhanced by mp on 2022/03/22