Sandeep Singh
8ec1767561
Rename hp-printer-unanuthorized-access.yaml to unauthorized-hp-printer.yaml
2021-07-13 01:45:40 +05:30
sandeep
567096e97f
matcher update
2021-07-13 01:42:15 +05:30
sandeep
3b13abc7f2
matcher update
2021-07-13 01:30:58 +05:30
pussycat0x
647677f0ab
Update hp-printer-unanuthorized-access.yaml
2021-07-11 23:49:17 +05:30
pussycat0x
09b002134d
Add files via upload
2021-07-11 23:44:34 +05:30
Prince Chaddha
89b4fdf8ed
Merge pull request #1757 from pussycat0x/master
...
New template added
2021-06-24 02:02:42 +05:30
Prince Chaddha
5fa51dd043
Update phpmyadmin-sql.php-server.yaml
2021-06-24 01:26:51 +05:30
sandeep
134a23aeab
Some fixes (WIP)
...
- Added missing matcher condition
- Updated severity to lowercase, as it's case sensitive
2021-06-24 01:03:41 +05:30
pussycat0x
2dd0ce2664
Update phpmyadmin-sql.php-server.yaml
2021-06-23 21:37:14 +05:30
pussycat0x
5ae899a66f
Update phpmyadmin-sql.php-server.yaml
2021-06-23 21:34:13 +05:30
pussycat0x
bb251938c8
Add files via upload
2021-06-22 20:40:53 +05:30
sandeep
49f9b67827
Added reference
2021-06-20 16:39:47 +05:30
Prince Chaddha
bd4b43bbce
Merge pull request #995 from pikpikcu/patch-101
...
Create zhiyuan-oa-unauthorized
2021-06-19 12:53:24 +05:30
Prince Chaddha
5463655627
Update zhiyuan-oa-unauthorized.yaml
2021-06-19 12:52:35 +05:30
sandeep
f0b67ef56b
Few template updates
2021-06-18 15:53:49 +05:30
sandeep
6081edd83f
Added reference
2021-06-18 12:16:27 +05:30
sandeep
f9d068a105
Added ssrf-via-oauth-misconfig
2021-06-18 12:15:13 +05:30
sandeep
b1e401ff9c
Delete adobe-connect-xss.yaml
2021-06-15 15:54:19 +05:30
sandeep
891e8374b1
misc changes
2021-06-14 20:32:21 +05:30
Dhiyaneshwaran
629b655ef1
Create adobe-connect-xss.yaml
2021-06-13 23:54:48 +05:30
Dhiyaneshwaran
afec528d82
Create adobe-connect-version.yaml
2021-06-13 23:40:58 +05:30
Dhiyaneshwaran
6e727805c1
Create adobe-connect-username-exposure.yaml
2021-06-13 23:25:39 +05:30
sandeep
8d35960831
Strict matchers
2021-06-10 21:18:38 +05:30
Sandeep Singh
13090ace75
Merge pull request #1659 from WillD96/IIS-Internal-IP-Disclosure
...
Created IIS Internal IP Disclosure Template
2021-06-10 00:02:02 +05:30
r3naissance
aa9e899dd2
Added conditional word in body
...
I found this be a valid finding /actuator/env on a production host but was missing additional words to check which was causing a false negative. 'activeProfiles' allows this test to pass on the instance that I came across.
2021-06-09 11:36:54 -06:00
sandeep
3c6aa9da0c
misc updates
2021-06-09 22:15:55 +05:30
Will Davison
cd06c6137f
Fixed trailing spaces
2021-06-09 16:04:53 +01:00
Will Davison
ad8d064bf9
Fixed linting error.
2021-06-09 15:40:06 +01:00
Will Davison
6279e1fb70
Added template for IIS Internal IP Disclosure
...
By sending a HTTP 1.0 request to the root of the webserver, sometimes an internal IP address is disclosed in the Location header of the 302 response.
2021-06-09 15:30:59 +01:00
Prince Chaddha
83ce809e8d
Updated author names
2021-06-09 17:50:56 +05:30
Prince Chaddha
0013f94807
Merge pull request #1631 from projectdiscovery/sap_update
...
SAP NetWeaver update
2021-06-09 14:17:51 +05:30
sandeep
1851068721
Updated matcher
2021-06-08 00:33:06 +05:30
sandeep
0fe0d327b0
moving files around
2021-06-07 19:57:59 +05:30
Dhiyaneshwaran
52adac2e12
Create firebase-urls.yaml
2021-06-06 19:38:51 +05:30
Dhiyaneshwaran
158914d4db
Create artifactory-anonymous-deploy.yaml
2021-06-06 19:37:32 +05:30
Prince Chaddha
1d07ace8a5
Merge pull request #1634 from DhiyaneshGeek/master
...
Exposed jQuery File Upload
2021-06-06 17:58:25 +05:30
Prince Chaddha
6649abf131
Update exposed-jquery-file-upload.yaml
2021-06-06 17:55:05 +05:30
Sandeep Singh
fae9755374
Merge pull request #1639 from pdelteil/patch-9
...
Update shell-history.yaml
2021-06-06 13:40:47 +05:30
sandeep
0cf8ffdc57
misc changes
2021-06-06 13:39:16 +05:30
sandeep
e2eaedc6a1
misc updates
2021-06-06 13:19:01 +05:30
Philippe Delteil
652da29f9a
Update shell-history.yaml
...
There are two problems with this template, it only checks for chmod commands but most importantly doesn't check for html tags. A real history file the response doesn't include html tags at all.
So, I'm adding two rules: Check for another possible commands (from real example) and adding a negative rule to discard false positives like this one:
nuclei -debug -t /home/kali/nuclei-templates/misconfiguration/shell-history.yaml -u http://777.urbanup.com
2021-06-05 22:06:30 -04:00
Philippe Delteil
9014a4b0a2
Update aws-object-listing.yaml
...
Added extractor that retrieves the name of the s3 bucket.
Test
nuclei -t nuclei-templates/misconfiguration/aws-object-listing.yaml -u http://img.secnews.gr
[2021-06-06 01:19:10] [aws-object-listing] [http] [low] http://imgcdn.secnews.gr [img.secnews.gr]
2021-06-05 21:27:44 -04:00
Dhiyaneshwaran
0d82660f90
Create exposed-jquery-file-upload.yaml
2021-06-05 22:04:09 +05:30
sandeep
a85c1dd35a
Moving files around + duplicate remove
2021-06-05 15:57:13 +05:30
sandeep
ae8c130668
Moving files around
2021-06-05 15:55:01 +05:30
sandeep
edcc35d604
Added Private key exposure via helper detector
2021-06-04 20:46:19 +05:30
sandeep
0c436e35aa
Added airflow-debug
2021-06-03 19:39:51 +05:30
sandeep
0c4f75d3ad
Duplicate template
2021-06-03 18:44:50 +05:30
sandeep
bdc803fd4b
Added CVE-2020-13927
2021-06-03 14:23:34 +05:30
Prince Chaddha
f63cd48c79
Update alibaba-mongoshake-unauth.yaml
2021-06-02 01:16:41 +05:30