nuclei-templates/default-logins/others/kingsoft-v8-default-login.yaml

39 lines
777 B
YAML

id: kingsoft-v8-default-login
info:
name: Kingsoft V8 Default Login
author: ritikchaddha
severity: medium
reference:
- https://idc.wanyunshuju.com/aqld/2123.html
tags: kingsoft,default-login
requests:
- raw:
- |
POST /inter/ajax.php?cmd=get_user_login_cmd HTTP/1.1
Host: {{Hostname}}
{"get_user_login_cmd":{"name":"{{username}}","password":"{{md5("{{password}}")}}"}}
attack: pitchfork
payloads:
username:
- admin
password:
- admin
redirects: true
max-redirects: 2
matchers-condition: and
matchers:
- type: word
part: body
words:
- "ADMIN"
- "userSession"
condition: and
- type: status
status:
- 200