XXL-JOB 任务调度中心 后台默认弱口令.md
1.14 KB / 2021-07-04 06:01:08
# XXL-JOB 任务调度中心 后台默认弱口令
## 漏洞描述
XXL-JOB 任务调度中心 后台存在默认弱口令,攻击者可以在后台进一步攻击
## 漏洞影响
> [!NOTE]
>
> XXL-JOB
## FOFA
> [!NOTE]
>
> app="XXL-JOB" || title="任务调度中心"
## 漏洞复现
使用默认口令登录 admin 123456
![](http://wikioss.peiqi.tech/vuln/xxl-1.png?x-oss-process=image/auto-orient,1/quality,q_90/watermark,image_c2h1aXlpbi9zdWkucG5nP3gtb3NzLXByb2Nlc3M9aW1hZ2UvcmVzaXplLFBfMTQvYnJpZ2h0LC0zOS9jb250cmFzdCwtNjQ,g_se,t_17,x_1,y_10)
![](http://wikioss.peiqi.tech/vuln/xxl-2.png?x-oss-process=image/auto-orient,1/quality,q_90/watermark,image_c2h1aXlpbi9zdWkucG5nP3gtb3NzLXByb2Nlc3M9aW1hZ2UvcmVzaXplLFBfMTQvYnJpZ2h0LC0zOS9jb250cmFzdCwtNjQ,g_se,t_17,x_1,y_10)
## Goby & POC
> [!NOTE]
>
> 已上传 https://github.com/PeiQi0/PeiQi-WIKI-POC Goby & POC 目录中
>
> XXL_JOB_Default_password
![](http://wikioss.peiqi.tech/vuln/xxl-3.png?x-oss-process=image/auto-orient,1/quality,q_90/watermark,image_c2h1aXlpbi9zdWkucG5nP3gtb3NzLXByb2Nlc3M9aW1hZ2UvcmVzaXplLFBfMTQvYnJpZ2h0LC0zOS9jb250cmFzdCwtNjQ,g_se,t_17,x_1,y_10)