
Proof-of-concept exploit for CVE-2022-26671, demonstrating hardcoded cleartext credential disclosure in an ASPX login page. Useful for vulnerability validation and security assessments.
If you got here, you know why this repo needed created.
CVE-2022-26671
GET /AT/ATDefault.aspx
Line's 430 contains the cleartext credential.
secom | supervisor
In regards to to responsible disclosure, not dislcosing a hardcoded cleartext HTTP body response is silly when its the login page./