nuclei-templates/http/exposed-panels/jfrog-login.yaml

33 lines
967 B
YAML

id: jfrog-login
info:
name: JFrog Login Panel - Detect
author: dhiyaneshDK
severity: info
description: |
JFrog login panel was detected.
reference:
- https://www.exploit-db.com/ghdb/6797
classification:
cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N
cwe-id: CWE-200
metadata:
verified: true
max-request: 2
shodan-query: "http.title:\"JFrog\""
tags: panel,jfrog,edb,detect,login
http:
- method: GET
path:
- '{{BaseURL}}/ui/login/'
- '{{BaseURL}}/ui/favicon.ico'
stop-at-first-match: true
matchers:
- type: dsl
dsl:
- 'status_code==200 && contains(body, "<title>JFrog")'
- "status_code==200 && (\"-595620639\" == mmh3(base64_py(body)))"
condition: or
# digest: 490a004630440220469671ce8c64f6c9c8fa36551da19ca159c2208d12f3484b7ad902b866ed5a4202201484f958ba1088c3c2e3a05a4d01d770d84d2533c52005170981bd0079a48b58:922c64590222798bb761d5b6d8e72950