2024-09-05 06:16:08 +00:00
|
|
|
id: repetier-unauth
|
|
|
|
|
|
|
|
info:
|
|
|
|
name: Repetier Server Dashboard - Unauthenticated
|
|
|
|
author: ritikchaddha
|
|
|
|
severity: high
|
|
|
|
description: |
|
|
|
|
Repetier Server Dashboard has been exposed.
|
|
|
|
classification:
|
|
|
|
cpe: cpe:2.3:a:repetier-server:repetier-server:*:*:*:*:*:*:*:*
|
|
|
|
metadata:
|
|
|
|
verified: true
|
|
|
|
max-request: 1
|
|
|
|
vendor: repetier-server
|
|
|
|
product: repetier-server
|
|
|
|
shodan-query: title:"Repetier-Server"
|
|
|
|
fofa-query: title="repetier-server"
|
2024-09-05 06:34:17 +00:00
|
|
|
tags: repetier,dashboard,unauth,misconfig
|
2024-09-05 06:16:08 +00:00
|
|
|
|
|
|
|
http:
|
|
|
|
- method: GET
|
|
|
|
path:
|
|
|
|
- "{{BaseURL}}/#!/printer/Prusa_I3/print"
|
|
|
|
|
|
|
|
matchers-condition: and
|
|
|
|
matchers:
|
|
|
|
- type: word
|
|
|
|
part: body
|
|
|
|
words:
|
|
|
|
- 'Global Settings'
|
|
|
|
- 'Edit Profile'
|
|
|
|
- 'Logout'
|
|
|
|
- 'Clear all Messages'
|
|
|
|
condition: and
|
|
|
|
|
|
|
|
- type: status
|
|
|
|
status:
|
|
|
|
- 200
|
2024-09-05 07:57:04 +00:00
|
|
|
# digest: 490a0046304402205819f5c52118748c051b0a084a9f914f22be45d4305f75994a9f40e7c29906cc02201a99709aa9e921b49411fddda46d2aa681861c95c44c7be8d866c024072dadaf:922c64590222798bb761d5b6d8e72950
|