Commit Graph

352 Commits (a6989e198e0b34473df2471f86ce0636ee65530e)

Author SHA1 Message Date
Ritik Chaddha 6f9e1b30cb
Merge pull request #6962 from kazet/adding-descriptions
Adding descriptions to two exposures/ templates
2023-03-28 11:02:38 +05:30
MostInterestingBotInTheWorld 301fddaeb0
Dashboard Content Enhancements (#6965)
* Add description and enhance one where the UI failed to save properly.
dos2unix on a template

* Change cvedetails link to nvd

* make severities match

* Enhancement: cves/2015/CVE-2015-2863.yaml by md

* Enhancement: cves/2017/CVE-2017-14524.yaml by md

* Enhancement: cves/2017/CVE-2017-5638.yaml by md

* Enhancement: cves/2019/CVE-2019-16759.yaml by md

* Enhancement: cves/2021/CVE-2021-22986.yaml by md

* Enhancement: cves/2021/CVE-2021-24145.yaml by md

* Enhancement: cves/2021/CVE-2021-24145.yaml by md

* Enhancement: cves/2021/CVE-2021-24155.yaml by md

* Enhancement: cves/2021/CVE-2021-24145.yaml by md

* Enhancement: cves/2021/CVE-2021-24145.yaml by md

* Enhancement: cves/2021/CVE-2021-24347.yaml by md

* Enhancement: cves/2021/CVE-2021-25003.yaml by md

* Enhancement: cves/2021/CVE-2021-25296.yaml by md

* Enhancement: cves/2021/CVE-2021-25297.yaml by md

* Enhancement: cves/2021/CVE-2021-25296.yaml by md

* Enhancement: cves/2021/CVE-2021-25297.yaml by md

* Enhancement: cves/2021/CVE-2021-25298.yaml by md

* Enhancement: cves/2021/CVE-2021-25297.yaml by md

* Enhancement: cves/2021/CVE-2021-28151.yaml by md

* Enhancement: cves/2021/CVE-2021-30128.yaml by md

* Enhancement: cves/2022/CVE-2022-0824.yaml by md

* Enhancement: cves/2022/CVE-2022-0824.yaml by md

* Enhancement: cves/2022/CVE-2022-0885.yaml by md

* Enhancement: cves/2022/CVE-2022-21587.yaml by md

* Enhancement: cves/2022/CVE-2022-2314.yaml by md

* Enhancement: cves/2022/CVE-2022-24816.yaml by md

* Enhancement: cves/2022/CVE-2022-31499.yaml by md

* Enhancement: cves/2022/CVE-2022-21587.yaml by md

* Enhancement: cves/2021/CVE-2021-24155.yaml by md

* Enhancement: cves/2017/CVE-2017-5638.yaml by md

* Enhancement: cves/2015/CVE-2015-2863.yaml by md

* Enhancement: cves/2022/CVE-2022-33901.yaml by md

* Enhancement: cves/2022/CVE-2022-2314.yaml by md

* Enhancement: cves/2022/CVE-2022-33901.yaml by md

* Enhancement: cves/2022/CVE-2022-34753.yaml by md

* Enhancement: cves/2022/CVE-2022-39952.yaml by md

* Enhancement: cves/2022/CVE-2022-4060.yaml by md

* Enhancement: cves/2022/CVE-2022-44877.yaml by md

* Enhancement: cves/2023/CVE-2023-0669.yaml by md

* Enhancement: cves/2023/CVE-2023-26255.yaml by md

* Enhancement: cves/2023/CVE-2023-26256.yaml by md

* Enhancement: exposures/files/salesforce-credentials.yaml by md

* Enhancement: misconfiguration/hadoop-unauth-rce.yaml by md

* Enhancement: misconfiguration/installer/nopcommerce-installer.yaml by md

* Enhancement: network/backdoor/backdoored-zte.yaml by md

* Enhancement: network/detection/ibm-d2b-database-server.yaml by md

* Enhancement: network/detection/ibm-d2b-database-server.yaml by md

* Enhancement: technologies/oracle/oracle-atg-commerce.yaml by md

* Enhancement: token-spray/api-abuseipdb.yaml by md

* Enhancement: token-spray/api-abuseipdb.yaml by md

* Enhancement: token-spray/api-dbt.yaml by md

* Enhancement: vulnerabilities/avaya/avaya-aura-rce.yaml by md

* Enhancement: vulnerabilities/avaya/avaya-aura-xss.yaml by md

* Enhancement: vulnerabilities/cisco/cisco-cloudcenter-suite-rce.yaml by md

* Enhancement: vulnerabilities/froxlor-xss.yaml by md

* Enhancement: vulnerabilities/jamf/jamf-log4j-jndi-rce.yaml by md

* Enhancement: vulnerabilities/mobileiron/mobileiron-log4j-jndi-rce.yaml by md

* Enhancement: vulnerabilities/jamf/jamf-log4j-jndi-rce.yaml by md

* Enhancement: vulnerabilities/opencpu/opencpu-rce.yaml by md

* Enhancement: vulnerabilities/other/academy-lms-xss.yaml by md

* Enhancement: vulnerabilities/other/caucho-resin-info-disclosure.yaml by md

* Enhancement: vulnerabilities/other/ckan-dom-based-xss.yaml by md

* Enhancement: vulnerabilities/other/couchdb-adminparty.yaml by md

* Enhancement: vulnerabilities/other/graylog-log4j.yaml by md

* Enhancement: vulnerabilities/mobileiron/mobileiron-log4j-jndi-rce.yaml by md

* Initial cleanups for syntax errors

* dashboard gremlins

* Add log4j back to name

* Enhancement: exposures/files/salesforce-credentials.yaml by cs

* Enhancement: misconfiguration/installer/nopcommerce-installer.yaml by cs

* Enhancement: network/backdoor/backdoored-zte.yaml by cs

* Enhancement: vulnerabilities/other/couchdb-adminparty.yaml by cs

* Sev and other info tweaks

* Merge conflict

---------

Co-authored-by: sullo <sullo@cirt.net>
2023-03-27 23:16:47 +05:30
Krzysztof Zając 7ef39abf43 Adding descriptions to exposures/files/django-secret-key.yaml and exposures/logs/php-debug-bar.yaml 2023-03-27 10:12:04 +02:00
Ritik Chaddha 0c605920b8
updated info,path 2023-03-22 01:55:37 +05:30
idealphase 92c587e672
Update gogs-install-exposure.yaml
Added metadata: shodan-query
2023-03-22 00:55:48 +07:00
MostInterestingBotInTheWorld 7677e07dec
Merge branch 'main' into dashboard 2023-03-17 11:24:28 -04:00
Dhiyaneshwaran c4ef1d5422
reactapp-env 2023-03-14 22:43:52 +05:30
MostInterestingBotInTheWorld 828d1b3ba6
Merge branch 'main' into dashboard 2023-03-10 15:03:33 -05:00
MostInterestingBotInTheWorld f3c130d6be Enhancement: exposures/files/sensitive-storage-exposure.yaml by md 2023-03-07 17:46:38 -05:00
MostInterestingBotInTheWorld 4d69c8f0c1 Enhancement: exposures/files/redmine-config.yaml by md 2023-03-07 17:28:14 -05:00
MostInterestingBotInTheWorld 2bfebe81b2 Enhancement: exposures/files/jetbrains-webservers.yaml by md 2023-03-07 17:22:50 -05:00
MostInterestingBotInTheWorld a77b75a1d5 Enhancement: exposures/files/dbeaver-database-connections.yaml by md 2023-03-07 17:18:10 -05:00
MostInterestingBotInTheWorld 97b53b1485 Enhancement: exposures/files/db-xml-file.yaml by md 2023-03-07 17:14:12 -05:00
Dhiyaneshwaran c69b67945b
reverted to GET 2023-03-06 13:14:46 +05:30
Dhiyaneshwaran 458e6443e2
Update svn-wc-db.yaml 2023-03-06 13:07:51 +05:30
QAQ 3dfd9e3915
Fix cve-2021-21311 (#6821)
* update zip-backup-files

* fix cve-2021-21311

* Update CVE-2021-21311.yaml

* Update php-backup-files

* add exposed-ds_store.yaml

* lint fixes

* added more matchers!

* removed duplicate template

* misc formatting update

* added fuzz tags

---------

Co-authored-by: sandeep <8293321+ehsandeep@users.noreply.github.com>
2023-03-04 13:35:35 +05:30
Dhiyaneshwaran 098e50da12
fixed-template 2023-03-02 15:35:55 +05:30
Rizwan Syed 4926c2951a
Update svn-wc-db.yaml 2023-02-13 16:23:06 +05:30
Rizwan Syed 239f8d6b6d
Update svn-wc-db.yaml
Most of the time wc.db file is big in size, response from the web server may take time, could lead to content deadline exceeded error, even if the wc.db file exist.
So I change the HTTP Method to HEAD
Also, I change the rating to High because it could lead to source code disclosure.
I cross verified with one of my target, current template does not work, so here is the revised one.
Reference: https://infosecwriteups.com/indias-aadhar-card-source-code-disclosure-via-exposed-svn-wc-db-c05519ea7761
2023-02-13 16:17:37 +05:30
Ritik Chaddha a3c60792cf
updated name 2023-02-11 10:30:13 +05:30
Thibault Soubiran 8d26b3fea5 Improve Keycloak templates 2023-02-10 22:01:43 +01:00
Marcial Paul Gargoles b7da019f86
Update secret-token-rb.yaml 2023-02-06 21:27:28 +08:00
MostInterestingBotInTheWorld 0d6fbd237f
Dashboard Content Enhancements (#6598)
Dashboard Content Enhancements
2023-01-23 14:14:23 -08:00
Dhiyaneshwaran dd1c5d227d
stop-at-first-match 2023-01-05 21:53:37 +05:30
Arman feaa5b948f
Update appsettings-file-disclosure.yaml 2023-01-05 11:22:07 -05:00
GitHub Action 997d941552 Auto Generated CVE annotations [Thu Jan 5 11:21:19 UTC 2023] 🤖 2023-01-05 11:21:19 +00:00
Dhiyaneshwaran 39c05ff472
Merge pull request #6392 from HardikSolanki96/cloud-config
Create cloud-config.yml
2022-12-20 10:45:12 +05:30
Ritik Chaddha 4d6f479d3b
Update cloud-config.yaml 2022-12-20 09:56:55 +05:30
Ritik Chaddha 917b712f98
Update salesforce-credentials.yaml 2022-12-16 08:09:24 +05:30
Dhiyaneshwaran f48dd3523e
Create salesforce-credentials.yaml 2022-12-15 01:13:29 +05:30
Dhiyaneshwaran c483d07e55
Merge pull request #6317 from HardikSolanki96/svn-wc-db
Svn wc db
2022-12-12 23:52:35 +05:30
Ritik Chaddha d0a5b15c38
Update svn-wc-db.yaml 2022-12-12 23:49:02 +05:30
Ritik Chaddha 658c1fa002
Merge pull request #6315 from HardikSolanki96/kube-apiserver-keys
Kube apiserver keys.yaml
2022-12-12 23:23:48 +05:30
Ritik Chaddha 84ad5b64c3
Update kubernetes-etcd-keys.yaml 2022-12-12 23:21:38 +05:30
Ritik Chaddha 90e4eae23b
Merge pull request #6313 from HardikSolanki96/database-credentials
Database credentials.yaml
2022-12-12 23:19:45 +05:30
Ritik Chaddha ebe422ca3a
Update database-credentials.yaml 2022-12-12 23:17:18 +05:30
Dhiyaneshwaran e2006ae636
Update and rename exposures/configs/database-credentials.yaml to exposures/files/database-credentials.yaml 2022-12-10 23:39:38 +05:30
Dhiyaneshwaran 510797b4f6
Update and rename kube-apiserver-keys.yaml to kubernetes-etcd-keys.yaml 2022-12-10 23:12:57 +05:30
Dhiyaneshwaran 112fcc2541
Rename exposures/configs/svn-wc-db.yaml to exposures/files/svn-wc-db.yaml 2022-12-10 23:03:15 +05:30
Dhiyaneshwaran dbcd248973
Rename exposures/kube-apiserver-keys.yaml to exposures/files/kube-apiserver-keys.yaml 2022-12-10 22:06:07 +05:30
Ritik Chaddha cbb12e690b
Merge pull request #6226 from projectdiscovery/gradle-libs
Create gradle-libs.yaml
2022-12-09 00:31:57 +05:30
Dhiyaneshwaran 88fd34ff71
Update npmrc-authtoken.yaml 2022-12-08 23:21:33 +05:30
Ritik Chaddha 1ffdff5b2d
Update gradle-libs.yaml 2022-12-08 16:56:04 +05:30
Ritik Chaddha b13ddeb3d9
Merge pull request #6206 from projectdiscovery/putty-private-key
Update putty-private-key-disclosure.yaml
2022-12-08 15:02:48 +05:30
Ritik Chaddha 7182ecb48d
Update putty-private-key-disclosure.yaml 2022-12-08 14:58:06 +05:30
Ritik Chaddha cbdb30567d
Merge pull request #6203 from projectdiscovery/routes-ini
Create routes-ini.yaml
2022-12-08 14:53:49 +05:30
Dhiyaneshwaran 8f4fbea711
Create gradle-libs.yaml 2022-12-05 00:24:30 +05:30
Prince Chaddha 4c46f809a3
Update jetbrains-webservers.yaml 2022-12-04 11:22:03 +05:30
Prince Chaddha 321bacceab
Update openstack-user-secrets.yaml 2022-12-04 11:13:39 +05:30
Prince Chaddha 1144c2190b
Update npmrc-authtoken.yaml 2022-12-04 11:12:40 +05:30