Commit Graph

3093 Commits (48b1bdb9d133535378cd7da548e6dcd930243114)

Author SHA1 Message Date
sandeep 2d19236680 misc update 2021-10-27 18:21:06 +05:30
sandeep 6490a968b3 Added GitLab CE/EE Unauthenticated RCE using ExifTool (CVE-2021-22205) 2021-10-27 18:01:04 +05:30
GitHub Action 46321e321c Auto Generated CVE annotations [Wed Oct 27 12:05:42 UTC 2021] 🤖 2021-10-27 12:05:42 +00:00
meme-lord 70c90bba84 Added CVE-2017-0929 (DNN SSRF) 2021-10-27 13:03:45 +01:00
Noam Rathaus 376c63189d Add description 2021-10-27 14:07:22 +03:00
Chill3d e6d40037c5
Typo on rocketchat tag 2021-10-27 10:30:43 +02:00
GitHub Action 7ccaf4c07a Auto Generated CVE annotations [Tue Oct 26 18:33:18 UTC 2021] 🤖 2021-10-26 18:33:18 +00:00
Prince Chaddha c72328203a
Merge pull request #2994 from Akokonunes/patch-62
Create CVE-2015-5471.yaml
2021-10-27 00:01:40 +05:30
GitHub Action 2c6367720e Auto Generated CVE annotations [Tue Oct 26 18:30:55 UTC 2021] 🤖 2021-10-26 18:30:55 +00:00
Prince Chaddha 8178635b45
Update CVE-2015-5471.yaml 2021-10-26 23:58:12 +05:30
Prince Chaddha 4b3c46a773
Update CVE-2016-1000136.yaml 2021-10-26 23:51:04 +05:30
sandeep 1e9218db98 moving files around 2021-10-26 15:13:55 +05:30
sandeep 41e0b65e79 Merge branch 'master' of https://github.com/projectdiscovery/nuclei-templates into pr/2990 2021-10-26 15:03:54 +05:30
sandeep 2fa9791bdc misc update 2021-10-26 14:32:23 +05:30
sandeep 1986e1211d Adding condition between word matcher 2021-10-26 14:25:37 +05:30
Dwi Siswanto 9773130879 Remove blank lines 2021-10-26 15:31:41 +07:00
Dwi Siswanto bf7070dbc7 Add CVE-2021-42258 2021-10-26 15:26:22 +07:00
Muhammad Daffa f37ac4f60b
Create CVE-2016-1000136.yaml 2021-10-25 20:05:08 +07:00
Prince Chaddha 1db2405c25
Create CVE-2021-36749.yaml 2021-10-25 17:30:48 +05:30
GitHub Action ed4d1afd12 Auto Generated CVE annotations [Fri Oct 22 09:40:47 UTC 2021] 🤖 2021-10-22 09:40:47 +00:00
sandeep 41be58c633 misc update 2021-10-22 15:09:15 +05:30
Sandeep Singh b8aaf28eb6
Merge pull request #2901 from lethargynavigator/master
CVE-2020-24589 template
2021-10-21 22:27:25 +05:30
sandeep e7768bb348 misc update 2021-10-21 22:25:42 +05:30
lethargynavigator 15a8208fc6 full poc 2021-10-21 11:02:55 -04:00
GitHub Action 7cfaf6c7dd Auto Generated CVE annotations [Thu Oct 21 10:43:47 UTC 2021] 🤖 2021-10-21 10:43:47 +00:00
Prince Chaddha 9d80a9d0d9
Merge pull request #2929 from daffainfo/patch-239
Create CVE-2016-1000143.yaml
2021-10-21 16:12:25 +05:30
Prince Chaddha b39200b8e4
Update CVE-2021-33044.yaml 2021-10-21 15:47:46 +05:30
Philippe Delteil 56b0f60d5a
Update CVE-2021-41773.yaml
Fixes false positive due to IPS/ 

 'Request denied by WatchGuard Firewall.</p><p><b> Reason: </b> IPS detected for "WEB Apache HTTP Server Path traversal (CVE-2021-41773)"'
2021-10-21 00:57:23 -03:00
Sandeep Singh a21cec6362
Merge pull request #2844 from projectdiscovery/more-fixes
Changes to adopt v2.5.3 engine
2021-10-21 07:21:20 +05:30
Sandeep Singh df54ed28f7
Merge pull request #2942 from projectdiscovery/CVE-2019-2729
Added CVE-2019-2729 (Oracle WebLogic  RCE)
2021-10-21 05:42:29 +05:30
sandeep 323da341b2 Added CVE-2019-2729 (Oracle WebLogic RCE) 2021-10-21 05:37:30 +05:30
GitHub Action f05e7364ca Auto Generated CVE annotations [Wed Oct 20 22:40:20 UTC 2021] 🤖 2021-10-20 22:40:20 +00:00
Muhammad Daffa 8ac553e844
Create CVE-2016-1000143.yaml 2021-10-19 22:21:58 +07:00
Prince Chaddha 10ebb22fb8
Merge pull request #2910 from gy741/rule-add-v65
Create CVE-2021-20031.yaml
2021-10-19 18:23:40 +05:30
Prince Chaddha 181dda73ec
Update CVE-2021-33044.yaml 2021-10-19 17:44:06 +05:30
GwanYeong Kim 02655a9f22 Create CVE-2021-33044.yaml
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.

Signed-off-by: GwanYeong Kim <gy741.kim@gmail.com>
2021-10-19 12:50:07 +09:00
sandeep 3175b12b22 Additional matcher 2021-10-19 03:19:32 +05:30
sandeep 33badb66d1 oob tags update 2021-10-19 02:10:26 +05:30
Prince Chaddha 2d83f055b4
Merge pull request #2908 from DhiyaneshGeek/master
CVE-2020-10770
2021-10-18 21:06:32 +05:30
Prince Chaddha fc81dd3b24
Update CVE-2020-10770.yaml 2021-10-18 21:03:29 +05:30
Prince Chaddha 9e37e202bd
Update CVE-2021-20031.yaml 2021-10-18 20:55:47 +05:30
Prince Chaddha 6346c6e93a
Update CVE-2021-20031.yaml 2021-10-18 20:52:36 +05:30
GitHub Action d2d4d01846 Auto Generated CVE annotations [Mon Oct 18 15:19:41 UTC 2021] 🤖 2021-10-18 15:19:41 +00:00
Prince Chaddha 09d4e1ea28
Merge pull request #2912 from wisnupramoedya/patch-2
Create CVE-2018-10823.yaml
2021-10-18 20:48:20 +05:30
Prince Chaddha 1753507a39
Merge pull request #2911 from wisnupramoedya/patch-1
Create CVE-2018-10093.yaml
2021-10-18 20:47:51 +05:30
GitHub Action 0762d645fb Auto Generated CVE annotations [Mon Oct 18 15:16:57 UTC 2021] 🤖 2021-10-18 15:16:57 +00:00
Prince Chaddha 868264f839
Update CVE-2018-10823.yaml 2021-10-18 20:46:01 +05:30
Prince Chaddha 9f30aa203b
Merge pull request #2913 from wisnupramoedya/patch-3
Create CVE-2018-13980.yaml
2021-10-18 20:45:06 +05:30
GitHub Action 79656346cd Auto Generated CVE annotations [Mon Oct 18 15:14:58 UTC 2021] 🤖 2021-10-18 15:14:58 +00:00
Wisnu Pramoedya cf1b818d5b
Create CVE-2018-12054.yaml 2021-10-18 20:04:38 +07:00
Wisnu Pramoedya 89f9d65d7d
Create CVE-2018-13980.yaml 2021-10-18 20:00:57 +07:00
Wisnu Pramoedya 7d007d29f0
Create CVE-2018-10823.yaml 2021-10-18 19:56:22 +07:00
Wisnu Pramoedya 98d8a15123
Create CVE-2018-10093.yaml 2021-10-18 19:44:09 +07:00
GwanYeong Kim c7fc202ef1 Create CVE-2021-20031.yaml
A Host Header Injection vulnerability may allow an attacker to spoof a particular Host header, allowing the attacker to render arbitrary links that point to a malicious website with poisoned Host header webpages. An issue was discovered in Sonicwall NAS, SonicWall Analyzer version 8.5.0 (may be affected on other versions too). The values of the 'Host' headers are implicitly set as trusted while this should be forbidden, leading to potential host header injection attack and also the affected hosts can be used for domain fronting. This means affected hosts can be used by attackers to hide behind during various other attack

Signed-off-by: GwanYeong Kim <gy741.kim@gmail.com>
2021-10-18 08:24:29 +09:00
sandeep a614391d3f Merge branch 'master' of https://github.com/projectdiscovery/nuclei-templates into more-fixes 2021-10-18 03:14:44 +05:30
GitHub Action e8218febf5 Auto Generated CVE annotations [Sun Oct 17 16:03:20 UTC 2021] 🤖 2021-10-17 16:03:20 +00:00
Dhiyaneshwaran a9eca98f7f
Update CVE-2020-10770.yaml 2021-10-17 21:31:55 +05:30
Dhiyaneshwaran 9c8d006dbe
Create CVE-2020-10770.yaml 2021-10-17 21:29:45 +05:30
GitHub Action dfc4a64fdc Auto Generated CVE annotations [Sun Oct 17 11:26:16 UTC 2021] 🤖 2021-10-17 11:26:16 +00:00
Prince Chaddha bd2e856174
Merge pull request #2902 from Akokonunes/patch-57
Create CVE-2015-4694.yaml
2021-10-17 16:55:03 +05:30
Prince Chaddha 39ab764bfa
Update CVE-2015-4694.yaml 2021-10-17 08:03:02 +05:30
Prince Chaddha d461c1f77c
Update and rename CVE-2015-4694.yaml to cves/2015/CVE-2015-4694.yaml 2021-10-17 08:01:28 +05:30
GitHub Action dc22f77a50 Auto Generated CVE annotations [Sun Oct 17 02:21:14 UTC 2021] 🤖 2021-10-17 02:21:14 +00:00
lethargynavigator 2871cc6b02 CVE-2020-24589 template 2021-10-15 20:37:03 -04:00
Philippe Delteil 794dfb0bbe
Update CVE-2019-6340.yaml
Solves cases when the source code contains only uid= and gid=  (e.g. https://account.mail.ru)

``nuclei -debug -t ~/nuclei-templates/cves/2019/CVE-2019-6340.yaml -u https://account.mail.ru``
2021-10-15 04:01:39 -03:00
GitHub Action 1833c3de19 Auto Generated CVE annotations [Thu Oct 14 20:34:25 UTC 2021] 🤖 2021-10-14 20:34:25 +00:00
sandeep 1ef07b6ad9 Added CVE-2021-40438 2021-10-15 01:29:52 +05:30
sandeep 42cc6d9507 Merge branch 'master' of https://github.com/projectdiscovery/nuclei-templates into more-fixes 2021-10-14 23:51:16 +05:30
sandeep 46fafc5a16 Merge branch 'master' of https://github.com/nrathaus/nuclei-templates into pr/2893 2021-10-14 20:11:47 +05:30
sandeep ac9cbb54b0 tags update 2021-10-14 20:10:59 +05:30
GitHub Action b025811dd2 Auto Generated CVE annotations [Thu Oct 14 14:40:51 UTC 2021] 🤖 2021-10-14 14:40:51 +00:00
sandeep 58ebf6b043 Merge branch 'master' of https://github.com/nrathaus/nuclei-templates into pr/2893 2021-10-14 20:09:00 +05:30
sandeep aad97c084c misc update 2021-10-14 20:08:44 +05:30
GitHub Action e8a32dbbf7 Auto Generated CVE annotations [Thu Oct 14 14:37:07 UTC 2021] 🤖 2021-10-14 14:37:07 +00:00
sandeep f9f4e3327e moving files around 2021-10-14 20:05:25 +05:30
Prince Chaddha 83dd71fe27
Merge pull request #2890 from pdelteil/patch-71
Update CVE-2021-41773.yaml
2021-10-14 16:25:15 +05:30
GitHub Action e1adf856e4 Auto Generated CVE annotations [Thu Oct 14 10:52:45 UTC 2021] 🤖 2021-10-14 10:52:45 +00:00
Philippe Delteil 742677870a
Update CVE-2021-41773.yaml
shodan query added
2021-10-14 03:52:10 -03:00
Prince Chaddha 1e4fae76a3
Update CVE-2021-40978.yaml 2021-10-14 09:23:48 +05:30
PikPikcU b22eb1ba01
Create CVE-2021-40978.yaml 2021-10-14 08:37:46 +07:00
GitHub Action 708adea285 Auto Generated CVE annotations [Wed Oct 13 08:57:56 UTC 2021] 🤖 2021-10-13 08:57:56 +00:00
Sandeep Singh 9273a765c0
Merge branch 'master' into more-fixes 2021-10-13 13:48:52 +05:30
Noam Rathaus 452b4c10ea Merge branch 'master' of https://github.com/projectdiscovery/nuclei-templates 2021-10-12 15:45:23 +03:00
Prince Chaddha 58e277f87d
Update CVE-2017-12544.yaml 2021-10-12 10:30:56 +05:30
Divya 2a6acf66e7
Add CVE-2017-12544.yaml
Template for HPE System Management XSS (CVE-2017-12544)
2021-10-12 00:08:39 -04:00
Prince Chaddha ca5c28faa2
Merge pull request #2874 from daffainfo/patch-237
Create CVE-2015-2067.yaml
2021-10-11 18:27:34 +05:30
Prince Chaddha 2d3c3a1382
Update CVE-2015-2068.yaml 2021-10-11 17:35:38 +05:30
Prince Chaddha c8d7f08e3c
Update CVE-2015-2068.yaml 2021-10-11 17:33:46 +05:30
Prince Chaddha dace44b3af
Update CVE-2015-2068.yaml 2021-10-11 17:32:29 +05:30
Muhammad Daffa 13fe132913
Create CVE-2015-2068.yaml 2021-10-11 18:28:08 +07:00
GitHub Action d7cd9a21de Auto Generated CVE annotations [Mon Oct 11 11:27:30 UTC 2021] 🤖 2021-10-11 11:27:30 +00:00
Muhammad Daffa 7cd433faf9
Create CVE-2015-2067.yaml 2021-10-11 18:24:36 +07:00
Prince Chaddha b9a2afe546
Update CVE-2018-9205.yaml 2021-10-11 16:53:15 +05:30
Muhammad Daffa 55caa61c96
Create CVE-2018-9205.yaml 2021-10-11 18:22:14 +07:00
GitHub Action 5cf090ddec Auto Generated CVE annotations [Sun Oct 10 22:40:30 UTC 2021] 🤖 2021-10-10 22:40:30 +00:00
Sandeep Singh 966e3d0947
Merge pull request #2866 from Akokonunes/patch-53
Create lotus-core-cms-lfi.yaml
2021-10-11 04:09:11 +05:30
sandeep d76884c109 moving files around 2021-10-11 04:07:10 +05:30
Noam Rathaus 59a6cef7fb Missing 'a' 2021-10-10 16:07:15 +03:00
sandeep 665e3f15e5 dynamic match 2021-10-10 18:27:15 +05:30
sandeep 5072932509 more updates 2021-10-10 06:43:30 +05:30