nuclei-templates/http/default-logins/idemia/idemia-biometrics-default-l...

47 lines
975 B
YAML

id: idemia-biometrics-default-login
info:
name: IDEMIA BIOMetrics Default Login
author: Techryptic (@Tech)
severity: medium
description: IDEMIA BIOMetrics application default login credentials were discovered.
reference:
- https://www.google.com/search?q=idemia+password%3D+"12345"
classification:
cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
cvss-score: 5.8
cwe-id: CWE-522
tags: idemia,biometrics,default-login
metadata:
max-request: 1
http:
- raw:
- |
POST /cgi-bin/login.cgi HTTP/1.1
Host: {{Hostname}}
password={{password}}
payloads:
password:
- "12345"
matchers-condition: and
matchers:
- type: word
condition: and
words:
- "session_id="
- "resource"
- type: word
part: body
negative: true
words:
- "Invalid Password"
- type: status
status:
- 200