Open Source Point Of Sale 預設認證

high Nessus Plugin ID 90407

概要

遠端主機上執行的 web 應用程式使用預設的認證予以保護。

說明

針對系統管理員帳戶,遠端 web 伺服器上執行的 Open Source Point of Sale (POS) 應用程式使用預設的認證。攻擊者可惡意利用此弱點,進而取得應用程式的管理存取權。

解決方案

變更「admin」使用者的密碼。

另請參閱

https://github.com/opensourcepos/opensourcepos

Plugin 詳細資訊

嚴重性: High

ID: 90407

檔案名稱: open_source_pos_default_creds.nasl

版本: 1.10

類型: Remote

系列: CGI abuses

已發布: 2016/4/7

已更新: 2024/5/28

組態: 啟用徹底檢查 (optional)

支援的感應器: Nessus

Enable CGI Scanning: true

弱點資訊

CPE: cpe:/a:open_source_point_of_sale_project:open_source_point_of_sale

必要的 KB 項目: installed_sw/Open Source Point of Sale

排除在外的 KB 項目: Settings/disable_cgi_scanning, global_settings/supplied_logins_only