Ethical Hacking Automation

Automate Recon and scanning process with Vidoc. All security teams in one place

Sitefinity Login

By kannthu

Informative
Vidoc logoVidoc Module
#sitefinity#edb#panel
Description

What is the "Sitefinity Login?"

The "Sitefinity Login" module is designed to identify the Sitefinity login page. Sitefinity is a web content management system used for building and managing websites. This module focuses on the /Sitefinity/Authenticate/SWT GET request and checks for the presence of the Telerik.Sitefinity.Web.UI.UserPreferences word in the response. The module is created by an unknown author.

Impact

This module is classified as informative, meaning it provides information about the presence of the Sitefinity login page but does not indicate any specific misconfiguration, vulnerability, or software fingerprint.

How the module works?

The module sends a GET request to the /Sitefinity/Authenticate/SWT endpoint. It then checks the response for the presence of the word Telerik.Sitefinity.Web.UI.UserPreferences and verifies that the response status is 200. If both conditions are met, the module considers the Sitefinity login page to be present.

While this module does not provide any specific vulnerability or misconfiguration details, it can be used as a starting point for further investigation into the Sitefinity login functionality.

Module preview

Concurrent Requests (1)
1. HTTP Request template
GET/Sitefinity/Authenti...
Matching conditions
word: Telerik.Sitefinity.Web.UI.UserPreference...and
status: 200
Passive global matcher
No matching conditions.
On match action
Report vulnerability