Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Updates to webappdefaultsdb #4

Open
wants to merge 23 commits into
base: master
Choose a base branch
from
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
176 changes: 162 additions & 14 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -9,17 +9,17 @@ Updated and released by the Web App Defaults DB Group

If you have info and don't want to trouble with Git, please feel free to shoot the info to:

webappdefaultsdb_submissions@room362.com
webappdefaultsdb@gmail.com

and let us worry about the repo voodoo.

If you wish to submit via git, please use the following field types:

* ADMINURL:
* USERPASS:
* INTERESTINGURL:
* EXPLOITLINK:
* COMMENT:
* AdminURL:
* User
* Pass:
* Comment:
* Link:

This will make it much easier for people to parse the entire db for information.

Expand All @@ -29,10 +29,10 @@ For example:
Info: This webapp falls over if you hit /dos.php on version 1.0 and prior

* ADMINURL: /admin/uberleet.php
* USERPASS: root:toor
* INTERESTINGURL: /database_test.php
* EXPLOITLINK: [http://exploitsdownload.com/search/cms](http://exploitsdownload.com/search/cms)
* USER: root
* PASS: toor
* COMMENT: Usernames with be [email protected]
* LINK: [http://exploitsdownload.com/search/cms](http://exploitsdownload.com/search/cms)

Documentation: [http://www.wikipedia.org/](http:/www.wikipedia.org/)

Expand All @@ -53,10 +53,153 @@ API Documentation: [https://apigee.com/console](https://apigee.com/console)
* BLOG:CMS
* blosxom
* Bricolage
* Barracuda SSL VPN
* Barracuda SSL VPN Admin
* Cascade Server
* CivicSpace
* Clickability (Limelight Networks)
* CMS Made Simple
* CMSimple
* Composite C1
* Computhink ViewWise
* Concrete5
* Contegro
* Content SORT
* CoreMedia WCM
* Cotonti
* Daisy
* Django-cms
* Dokuwiki
* Dotclear
* dotCMS
* DotNetNuke
* Drupal
* DSpace
* DynPG
* e107
* Ektron CMS400.Net
* Ektron CMS400.Net
* Ektron CMS400.Net
* Ektron CMS400.Net
* Elcom CMS
* EMC Documentum ECM
* EPrints
* Escenic Content Engine
* Exponent CMS
* ExpressionEngine
* Exsite Webware
* eZ Publish
* Fedora
* Flagship Docs
* Foswiki
* Frog CMS
* Geeklog
* Habari
* Hippo CMS
* Hyland OnBase ECM
* IBM Enterprise Content Management
* IBM Lotus Web Content Management
* Ikiwiki
* ImpressCMS
* Quest Software inSync
* Jadu
* JCore
* Joomla!
* Jumbo
* Kajona
* Kentico CMS
* KnowledgeTree Community Edition
* Liferay Community Edition
* LogicalDOC
* Lyceum
* Magnolia
* Mambo
* Mediawiki
* MiaCMS
* Microsoft Office 365
* Microsoft SharePoint Foundation
* Microsoft SharePoint Server
* Midgard CMS
* MODx
* mojoPortal
* Movable Type
* Mura CMS
* Nucleus CMS
* Nuxeo EP
* O3spaces
* Ocportal
* OpenACS
* OpenCms
* OpenKM
* OpenText ECM Suite
* OpenText Web Experience Management
* OpenText Web Site Management
* OpenWGA
* Opus
* Oracle ECM Suite
* Orchard Project
* papaya CMS
* Peardrop(CMS)
* Percussion Software CM1
* Phire CMS
* PHP-Fusion
* PHP-Nuke
* PHPSlash
* Phpweblog
* phpWebSite
* phpWiki
* Pier
* pimcore
* PivotX
* Pixie (CMS)
* PmWiki
* Polopoly Web CMS
* Prestashop
* ProcessWire
* Pulse CMS
* Radiant
* RavenNuke CMS
* Refinery CMS
* RenovatioCMS
* Scoop
* Serendipity
* SilverStripe
* Sitecore Professional Edition
* Sitefinity CMS
* Sitekit CMS
* SMW+
* Solarwinds Web HelpDesk
* SPIP
* Squiz CMS
* Squiz Matrix
* TangoCMS
* Telligent Community
* Textpattern
* Tiki Wiki CMS Groupware
* Titan CMS
* Tribiq CMS
* TWiki
* Typo
* TYPO3
* uCoz
* Umbraco
* VosaoCMS
* WebGUI
* Webnodes CMS
* WolfCMS
* WordPress
* Wuzly
* Xaraya
* XOOPS
* Xpress Engine
* Yanel
* Zikula
* Zotonic

<table>


<tr><td><b>Name</b></td><td><b>URL</b></td><td><b>Username</b></td><td><b>Password</b></td><td><b>Comment</b></td><td><b>Link</b></td>
<tr><td>Barracuda SSL VPN</td><td>/default/showLogon.do</td><td>ssladmin</td><td>ssladmin</td><td></td><td>&nbsp;</td><td>https://techlib.barracuda.com/sslvpn/admininterfaces</td></tr>
<tr><td>Barracuda SSL VPN Admin</td><td>.com:8000/cgi-mod/index.cgi</td><td>admin</td><td>admin</td><td></td><td>&nbsp;</td><td>https://techlib.barracuda.com/sslvpn/admininterfaces</td></tr>
<tr><td>Cascade Server</td><td>/login.act</td><td>&nbsp;</td><td>&nbsp;</td><td>http://help.hannonhill.com/kb/security</td><td>&nbsp;</td><td>&nbsp;</td></tr>
<tr><td>CivicSpace</td><td>To be determined</td><td>&nbsp;</td><td>&nbsp;</td><td>&nbsp;</td><td>&nbsp;</td><td>&nbsp;</td></tr>
<tr><td>Clickability (Limelight Networks)</td><td>hosted by limelight?</td><td>&nbsp;</td><td>&nbsp;</td><td>&nbsp;</td><td>&nbsp;</td><td>&nbsp;</td></tr>
Expand All @@ -70,6 +213,7 @@ API Documentation: [https://apigee.com/console](https://apigee.com/console)
<tr><td>CoreMedia WCM</td><td>&nbsp;</td><td>&nbsp;</td><td>&nbsp;</td><td>&nbsp;</td><td><- Magic Quadrant Masterbaters</td><td>&nbsp;</td></tr>
<tr><td>Cotonti</td><td>/admin.php</td><td>&nbsp;</td><td>&nbsp;</td><td>&nbsp;</td><td>&nbsp;</td><td>http://exploitsdownload.com/search/cotonti</td></tr>
<tr><td>Daisy</td><td>/login</td><td>admin</td><td>admin</td><td>&nbsp;</td><td>&nbsp;</td><td>&nbsp;</td></tr>
<tr><td>Dell SonicWall Analyzer</td><td>/sgms/login</td><td>admin</td><td>password</td><td>&nbsp;</td><td>https://support.software.dell.com/download/downloads?id=5477891&ei=fhQTVZHWMZO1sQTxo4KAAw&usg=AFQjCNG2yGbefRqEta9Nhq73or00BYFY4Q&bvm=bv.89217033,d.eXY&cad=rja</td></tr>
<tr><td>Django-cms</td><td>/admin</td><td>admin</td><td>&nbsp;</td><td>&nbsp;</td><td>&nbsp;</td><td>http://exploitsdownload.com/search/django</td></tr>
<tr><td>Dokuwiki</td><td>/dokuwiki?do=login</td><td>&nbsp;</td><td>&nbsp;</td><td>&nbsp;</td><td>&nbsp;</td><td>http://exploitsdownload.com/search/dokuwiki</td></tr>
<tr><td>Dotclear</td><td>/dotclear/admin/</td><td>&nbsp;</td><td>&nbsp;</td><td>&nbsp;</td><td>&nbsp;</td><td>http://exploitsdownload.com/search/dotclear</td></tr>
Expand All @@ -79,7 +223,10 @@ API Documentation: [https://apigee.com/console](https://apigee.com/console)
<tr><td>DSpace</td><td>(dspace?).site.com/admin </td><td>&nbsp;</td><td>&nbsp;</td><td>&nbsp;</td><td>&nbsp;</td><td>&nbsp;</td></tr>
<tr><td>DynPG</td><td>/cms or /dynpg</td><td>&nbsp;</td><td>&nbsp;</td><td>&nbsp;</td><td>&nbsp;</td><td>http://exploitsdownload.com/search/dynpg</td></tr>
<tr><td>e107</td><td><siteURL>/<Basedir>/e107_admin/admin.php?view.all</td><td>&nbsp;</td><td>&nbsp;</td><td>&nbsp;</td><td>&nbsp;</td><td>http://exploitsdownload.com/search/e107</td></tr>
<tr><td>Ektron CMS400.Net</td><td>/workarea/login.aspx</td><td>admin</td><td>admin</td><td>documentation.ektron.com/CMS400/v70/adminmanual.pdf</td><td>&nbsp;</td><td>&nbsp;</td></tr>
<tr><td>Ektron CMS400.Net</td><td>/workarea/login.aspx</td><td>admin</td><td>admin</td><td>All permissions</td><td>documentation.ektron.com/CMS400/v70/adminmanual.pdf</td></tr>
<tr><td>Ektron CMS400.Net</td><td>/workarea/login.aspx</td><td>builtin</td><td>builtin</td><td>All permissions</td><td>documentation.ektron.com/CMS400/v70/adminmanual.pdf</td></tr>
<tr><td>Ektron CMS400.Net</td><td>/workarea/login.aspx</td><td>jedit</td><td>jedit</td><td>Basic permissions</td><td>http://documentation.ektron.com/cms400/v802/mobile_help/Advanced/Content/Getting%20Started/Logging%20In%20and%20Out/loginandout_login.htm</td></tr>
<tr><td>Ektron CMS400.Net</td><td>/workarea/login.aspx</td><td>jmember</td><td>jmember</td><td>Read-Only permissions</td><td>http://documentation.ektron.com/cms400/v802/mobile_help/Advanced/Content/Getting%20Started/Logging%20In%20and%20Out/loginandout_login.htm</td></tr>
<tr><td>Elcom CMS</td><td>&nbsp;</td><td>&nbsp;</td><td>&nbsp;</td><td>&nbsp;</td><td>&nbsp;</td><td>http://exploitsdownload.com/search/elcom</td></tr>
<tr><td>EMC Documentum ECM</td><td>&nbsp;</td><td>&nbsp;</td><td>&nbsp;</td><td>&nbsp;</td><td>&nbsp;</td><td>&nbsp;</td></tr>
<tr><td>EPrints</td><td>/perl/users/home</td><td>admin</td><td>admin</td><td>&nbsp;</td><td>&nbsp;</td><td>&nbsp;</td></tr>
Expand All @@ -100,9 +247,8 @@ API Documentation: [https://apigee.com/console](https://apigee.com/console)
<tr><td>IBM Lotus Web Content Management</td><td>&nbsp;</td><td>&nbsp;</td><td>&nbsp;</td><td>&nbsp;</td><td>&nbsp;</td><td>&nbsp;</td></tr>
<tr><td>Ikiwiki</td><td>&nbsp;</td><td>&nbsp;</td><td>&nbsp;</td><td>&nbsp;</td><td>&nbsp;</td><td>&nbsp;</td></tr>
<tr><td>ImpressCMS</td><td>/admin.php</td><td>&nbsp;</td><td>&nbsp;</td><td>&nbsp;</td><td>&nbsp;</td><td>&nbsp;</td></tr>
<tr><td>Quest Software inSync</td><td>/GoAdmin</td><td>admin</td><td>admin</td><td>&nbsp;</td><td>http://support-public.cfm.software.dell.com/ddbeaa24-9332-4506-bda8-aceeef47af34:602964.pdf</td></tr>
<tr><td>Jadu</td><td>"/mymicrosite/jadu/</td></tr>
<tr><td> </td></tr>
<tr><td>"</td><td>&nbsp;</td><td>&nbsp;</td><td>&nbsp;</td><td>&nbsp;</td><td>&nbsp;</td></tr>
<tr><td>JCore</td><td>/admin/</td><td>admin</td><td>&nbsp;</td><td>&nbsp;</td><td>&nbsp;</td><td>&nbsp;</td></tr>
<tr><td>Joomla!</td><td>/administrator or /joomla/administrator</td><td>admin</td><td>&nbsp;</td><td>&nbsp;</td><td>&nbsp;</td><td>&nbsp;</td></tr>
<tr><td>Jumbo</td><td>jumbo/loginpage.php</td><td>admin</td><td>password</td><td>&nbsp;</td><td>&nbsp;</td><td>&nbsp;</td></tr>
Expand Down Expand Up @@ -168,9 +314,11 @@ API Documentation: [https://apigee.com/console](https://apigee.com/console)
<tr><td>Sitefinity CMS</td><td>/Sitefinity/LoginPages/LoginForm</td><td>admin</td><td>Password</td><td>http://www.sitefinity.com/devnet/kb.aspx</td><td>If you see telerik.rad it's sitefinity</td><td>http://exploitsdownload.com/search/sitefinity</td></tr>
<tr><td>Sitekit CMS</td><td>/admin</td><td>&nbsp;</td><td>&nbsp;</td><td>http://www.sitekit.net</td><td>&nbsp;</td><td>&nbsp;</td></tr>
<tr><td>SMW+</td><td>&nbsp;</td><td>root</td><td>m8nix</td><td>http://www.smwplus.com/index.php/Help:SMW%2B</td><td>&nbsp;</td><td>http://exploitsdownload.com/search/smwplus</td></tr>
<tr><td>SolarWinds Web Helpdesk</td><td>https://ip_address:5480/</td><td>admin</td><td>admin</td><td>&nbsp;</td><td>http://www.solarwinds.com/documentation/WebHelpDesk/docs/WHDAdminGuide12-2-0.pdf</td></tr>
<tr><td>SPIP</td><td>&nbsp;</td><td>&nbsp;</td><td>&nbsp;</td><td>&nbsp;</td><td>&nbsp;</td><td>&nbsp;</td></tr>
<tr><td>Squiz CMS</td><td>/_edit</td><td>admin/editor/approver</td><td>password</td><td>http://cms.squizsuite.net/quick-start-guide/</td><td>admin password should be changed</td><td>http://exploitsdownload.com/search?q=squiz</td></tr>
<tr><td>Squiz Matrix</td><td>/_admin</td><td>root</td><td>root</td><td>http://matrix.squizsuite.net/quick-start-guide/</td><td>&nbsp;</td><td>http://exploitsdownload.com/search?q=squiz</td></tr>
<tr><td>SuperMicro IPMI BMC</td><td>/</td><td>ADMIN</td><td>ADMIN</td><td></td><td>http://supermicro.com/manuals/other/SMT_IPMI_Manual.pdf</td></tr>http://supermicro.com/manuals/other/SMT_IPMI_Manual.pdf
<tr><td>TangoCMS</td><td>index.php?url=session or /session</td><td>&nbsp;</td><td>&nbsp;</td><td>http://tangocms.org/announcements?page=2</td><td>&nbsp;</td><td>&nbsp;</td></tr>
<tr><td>Telligent Community</td><td>/telligent_evolution</td><td>admin</td><td>pa$$word</td><td>&nbsp;</td><td>check for /solr/admin</td><td>&nbsp;</td></tr>
<tr><td>Textpattern</td><td>/textpattern/index.php or /textpattern/</td><td>&nbsp;</td><td>&nbsp;</td><td>&nbsp;</td><td>&nbsp;</td><td>http://exploitsdownload.com/search?q=textpattern</td></tr>
Expand Down
Loading