id: CNVD-2019-01348 info: name: Xiuno BBS CNVD-2019-01348 author: princechaddha severity: medium description: Xiuno BBS system has a system reinstallation vulnerability that could allow an attacker to directly reinstall the system through the installation page. reference: https://www.cnvd.org.cn/flaw/show/CNVD-2019-01348 tags: xiuno,cnvd,cnvd2019 remediation: There is currently no patch available. classification: cvss-metrics: CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H cvss-score: 6.5 cwe-id: CWE-276 requests: - method: GET path: - "{{BaseURL}}/install/" headers: Accept-Encoding: deflate matchers-condition: and matchers: - type: status status: - 200 - type: word part: body words: - "/view/js/xiuno.js" - "Choose Language (选择语言)" condition: and # Enhanced by mp on 2022/01/26