Commit Graph

12258 Commits (bb8a7f72c2f7be188538241790fbf0a9a5e38fa8)

Author SHA1 Message Date
Smaran Chand 0babc27b75
Added elFinder filemanger exposed (#3602)
* Added elFinder filemanger exposed

* Template name / id update + more reference

* template name update

* matcher update

* Modified the matcher.

* minor updates

Co-authored-by: sandeep <sandeep@projectdiscovery.io>
2022-01-26 23:27:45 +05:30
pussycat0x e81fcabd25
Add files via upload 2022-01-26 22:31:33 +05:30
MostInterestingBotInTheWorld 7b0292bbfb Enhancement: cnvd/2019/CNVD-2019-01348.yaml by mp 2022-01-26 11:56:44 -05:00
sullo 9891b971cb
Merge pull request #3604 from MostInterestingBotInTheWorld/master
Enhancement: Replace nonstandard ascii chars with chars we like better
2022-01-26 10:38:24 -05:00
Sandeep Singh 21b7bd1547
Update CVE-2017-7391.yaml 2022-01-26 17:37:19 +05:30
Prince Chaddha a4d1bdca76
Merge pull request #3606 from dadevel/typo3-detect
Add typo3-detect
2022-01-26 17:21:13 +05:30
Prince Chaddha 73cd3367e3
Update typo3-detect.yaml 2022-01-26 17:12:53 +05:30
Prince Chaddha 65ad6705dd
Merge pull request #3607 from dadevel/typo3-login
Add typo3-login
2022-01-26 17:06:31 +05:30
Prince Chaddha 17349bf1d8
Update typo3-login.yaml 2022-01-26 17:03:49 +05:30
Dhiyaneshwaran 7bd14d5cbc
OpenBMCS Info Disclosure & SSRF Unauth (#3603)
* Create gophish-login.yaml

* Create gophish-workflow.yaml

* Update gophish-workflow.yaml

* Create openbmcs-secret-disclosure.yaml

* Create openbmcs-ssrf.yaml

* Added additional matcher

* Added missing header + matcher update

Co-authored-by: Sandeep Singh <sandeep@projectdiscovery.io>
Co-authored-by: root <root@3gzk.l.time4vps.cloud>
2022-01-26 16:56:40 +05:30
Sandeep Singh 74dc6a6293
Added missing header + matcher update 2022-01-26 16:54:41 +05:30
Sandeep Singh 254fa1959a
Added additional matcher 2022-01-26 16:52:12 +05:30
dadevel c77a7dc417
Add typo3-detect 2022-01-26 11:59:43 +01:00
dadevel 8a7baf1941
Add typo3-login 2022-01-26 11:56:04 +01:00
Sullo c99e6415fd Properly escape a ' 2022-01-25 14:53:41 -05:00
Sullo 9a8482172d Remove:
- various nonstandard ascii chars in favor of the standard ones (mostly quotes)
 - spaces after : in some files
2022-01-25 14:38:53 -05:00
Dhiyaneshwaran 33b0868740
Create openbmcs-ssrf.yaml 2022-01-25 23:18:50 +05:30
Dhiyaneshwaran 86a21a68bc
Create openbmcs-secret-disclosure.yaml 2022-01-25 23:03:15 +05:30
root e7d42abe0b Merge branch 'master' of https://github.com/projectdiscovery/nuclei-templates 2022-01-25 19:10:17 +02:00
GitHub Action 173f0ef2d3 Auto Generated CVE annotations [Tue Jan 25 16:51:00 UTC 2022] 🤖 2022-01-25 16:51:00 +00:00
Sandeep Singh 4401b9ebe9
Merge pull request #3599 from projectdiscovery/CVE-2021-24838
Added CVE-2021-24838
2022-01-25 22:19:30 +05:30
Sandeep Singh 494a80799c
Merge pull request #3600 from MostInterestingBotInTheWorld/dashboard
Enhancement: cves/2021/CVE-2021-29156.yaml by cs
2022-01-25 22:09:27 +05:30
sandeep 8c7ec49185 lint fix 2022-01-25 22:08:01 +05:30
Prince Chaddha 97b38b98b4
Update CVE-2022-21371.yaml 2022-01-25 21:06:14 +05:30
Prince Chaddha 91d9b71864
Merge pull request #3596 from gy741/rule-add-v93
Create CVE-2021-39350.yaml
2022-01-25 17:16:12 +05:30
sandeep 47e34dba46 Added CVE-2021-24838 2022-01-25 17:14:00 +05:30
Prince Chaddha 6a2ff6f09e
Update CVE-2021-39350.yaml 2022-01-25 17:08:01 +05:30
Prince Chaddha 338bb99ec7
Merge pull request #3594 from gy741/rule-add-v91
Create gnuboard-cms-detect.yaml
2022-01-25 16:41:58 +05:30
GitHub Action 48add9c36b Auto Generated CVE annotations [Tue Jan 25 11:06:39 UTC 2022] 🤖 2022-01-25 11:06:39 +00:00
Prince Chaddha 2460dceff3
Update CVE-2022-21371.yaml 2022-01-25 16:36:10 +05:30
Prince Chaddha 8654a4a3fa
Merge pull request #3590 from myztique/patch-1
Add BigBlueButton Login Panel
2022-01-25 16:35:03 +05:30
Prince Chaddha 1a0809deb1
Update bigbluebutton-login.yaml 2022-01-25 16:33:32 +05:30
GitHub Action 5f2efaf5df Auto Generated CVE annotations [Tue Jan 25 09:56:37 UTC 2022] 🤖 2022-01-25 09:56:37 +00:00
on abfbfe29ae CVE-2022-21371.yaml 2022-01-25 12:48:56 +03:00
GitHub Action e035a797c6 Auto Generated CVE annotations [Tue Jan 25 09:41:31 UTC 2022] 🤖 2022-01-25 09:41:31 +00:00
Onurhan Erdoğdu 68cc84e8c9
Merge branch 'projectdiscovery:master' into master 2022-01-25 12:39:31 +03:00
GwanYeong Kim 67b2955d98 Create CVE-2021-39350.yaml
The FV Flowplayer Video Player WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the player_id parameter found in the ~/view/stats.php file which allows attackers to inject arbitrary web scripts, in versions 7.5.0.727 - 7.5.2.727.

Signed-off-by: GwanYeong Kim <gy741.kim@gmail.com>
2022-01-25 17:31:13 +09:00
GitHub Action a96f336f15 Auto Generated CVE annotations [Tue Jan 25 08:23:33 UTC 2022] 🤖 2022-01-25 08:23:33 +00:00
Prince Chaddha a8b57df334
Update bigbluebutton-login.yaml 2022-01-25 13:38:15 +05:30
Prince Chaddha bc382a72b2
Merge pull request #3592 from projectdiscovery/lexmark-detect
Create lexmark-detect.yaml
2022-01-25 13:04:41 +05:30
Prince Chaddha b006e12019
Update lexmark-detect.yaml 2022-01-25 13:01:40 +05:30
Prince Chaddha 6e5afae8ce
Merge pull request #3593 from niranc/alfresco
Added Alfresco CMS version detection
2022-01-25 13:00:53 +05:30
Prince Chaddha 1717ea8d3e
Merge pull request #3591 from projectdiscovery/airtame-device-detect
Create airtame-device-detect.yaml
2022-01-25 13:00:28 +05:30
Prince Chaddha d5c11d01e4
Update alfresco-detect.yaml 2022-01-25 12:59:19 +05:30
Prince Chaddha 071b29af85
Update and rename technologies/alfresco-detect.yaml to exposed-panels/alfresco-detect.yaml 2022-01-25 12:57:56 +05:30
Prince Chaddha 810330917a
Update and rename gnuboard-cms-detect.yaml to gnuboard-detect.yaml 2022-01-25 12:44:35 +05:30
Prince Chaddha 9fa09a0d4a
Merge pull request #3595 from gy741/rule-add-v92
Create CVE-2021-43810.yaml
2022-01-25 12:40:26 +05:30
Prince Chaddha 25e3537212
Update CVE-2021-43810.yaml 2022-01-25 12:34:20 +05:30
GwanYeong Kim c368e33117 Create CVE-2021-43810.yaml
Admidio is a free open source user management system for websites of organizations and groups. A cross-site scripting vulnerability is present in Admidio prior to version 4.0.12. The Reflected XSS vulnerability occurs because redirect.php does not properly validate the value of the url parameter. Through this vulnerability, an attacker is capable to execute malicious scripts. This issue is patched in version 4.0.12.

Signed-off-by: GwanYeong Kim <gy741.kim@gmail.com>
2022-01-25 13:55:34 +09:00
GwanYeong Kim 5fc755c561 Create gnuboard-cms-detect.yaml
Signed-off-by: GwanYeong Kim <gy741.kim@gmail.com>
2022-01-25 11:31:56 +09:00