id: dialogic-xms-default-login info: name: Dialogic XMS Admin Console - Default Login author: ritikchaddha severity: high description: | Dialogic XMS Admin Console was using default credentials and it was discovered. metadata: verified: true max-request: 1 shodan-query: title:"Dialogic XMS Admin Console" tags: dialogic,admin,default-login http: - raw: - | POST /index.php/verifyLogin/login HTTP/1.1 Host: {{Hostname}} Content-Type: application/x-www-form-urlencoded usernameId={{username}}&passwordId={{password}} attack: pitchfork payloads: username: - admin password: - admin matchers-condition: and matchers: - type: word part: body words: - 'DialogicDojo' - 'userId">user:' - 'var downloads' - 'onclick="logout' condition: and - type: status status: - 200 # digest: 490a00463044022100bb438b77aab69bf23ecaff901d2ae764492c3198dd258f86807c090d548a7f79021f762e3ac6e41662c24d0986e227981aa1621ba654bcf0a95b88be934e4a15ef:922c64590222798bb761d5b6d8e72950