Prince Chaddha
08dac56385
Update simple-employee-rce.yaml
2021-09-09 12:06:24 +05:30
sandeep
609705f676
removed extra headers not required for template
2021-09-08 17:47:19 +05:30
Prince Chaddha
9b75486616
Rename homeautomation-v3-openredirect.yaml to vulnerabilities/other/homeautomation-v3-openredirect.yaml
2021-09-07 18:07:48 +05:30
Sandeep Singh
e6a71e0e80
Merge pull request #2593 from projectdiscovery/openvpn-hhi
...
Added OpenVPN Host Header Injection
2021-09-06 18:56:27 +05:30
Sandeep Singh
e31a75af04
Merge pull request #2595 from projectdiscovery/host-header-injection
...
Create host-header-injection.yaml
2021-09-06 18:56:09 +05:30
Prince Chaddha
4075664390
Merge pull request #2580 from Akokonunes/patch-29
...
Create gSOAP-LFl.yaml
2021-09-06 17:36:18 +05:30
Prince Chaddha
e9d5665383
Update gsoap-lfi.yaml
2021-09-06 17:34:51 +05:30
Prince Chaddha
1942d13ed6
Update openvpn-hhi.yaml
2021-09-06 17:15:30 +05:30
Prince Chaddha
acd4624200
Create host-header-injection.yaml
2021-09-06 17:14:27 +05:30
Prince Chaddha
842f66380f
Revert "Create host-header-injection.yaml"
...
This reverts commit 6abfcd80e1
.
2021-09-06 17:13:48 +05:30
Prince Chaddha
6abfcd80e1
Create host-header-injection.yaml
2021-09-06 17:13:20 +05:30
sandeep
cec54e6d51
tags update
...
Co-Authored-By: me_dheeraj <9442273+Dheerajmadhukar@users.noreply.github.com>
2021-09-06 16:15:07 +05:30
sandeep
c105e41fa4
Added OpenVPN Host Header Injection
...
Co-Authored-By: me_dheeraj <9442273+Dheerajmadhukar@users.noreply.github.com>
2021-09-06 16:13:17 +05:30
Prince Chaddha
f6e52a6739
Merge pull request #2585 from sullo/master
...
Updates across many templates for clarity, spelling, and grammar.
2021-09-06 15:02:52 +05:30
Prince Chaddha
7579fe98c2
Update and rename minimouse-lfi.yaml to vulnerabilities/other/minimouse-lfi.yaml
2021-09-06 14:44:39 +05:30
sullo
ef1f7c5e92
Updates across many templates for clarity, spelling, and grammar.
2021-09-05 17:13:45 -04:00
Prince Chaddha
bf1d6374b2
Rename gSOAP-LFl.yaml to vulnerabilities/other/gsoap-lfi.yaml
2021-09-05 19:22:07 +05:30
sandeep
90f8caf302
Merge branch 'master' of https://github.com/projectdiscovery/nuclei-templates into pr/2481
2021-09-03 14:55:30 +05:30
sandeep
c266084621
Added stop-at-first-match in applicable templates
2021-09-02 17:29:10 +05:30
sandeep
faf111362c
Removing extra space
2021-09-01 12:37:02 +05:30
Prince Chaddha
5c5c6c3974
Update processmaker-lfi.yaml
2021-08-31 14:08:11 +05:30
Prince Chaddha
0b69ea80b2
Create processmaker-lfi.yaml
2021-08-31 14:03:47 +05:30
Noam Rathaus
86f3c08ba6
Vendor writes it as "NETGEAR"
2021-08-29 09:39:06 +03:00
Noam Rathaus
9f9970c8e9
Merge branch 'master' of https://github.com/projectdiscovery/nuclei-templates
2021-08-29 09:15:40 +03:00
forgedhallpass
419a957409
Fixing errors in templates
...
Related nuclei tickets:
* #259 - dynamic key-value field support for template information
* #940 - new infos in template
* #834
* RES-84
2021-08-27 10:43:24 +03:00
forgedhallpass
a4250b8f2f
Merge remote-tracking branch 'origin' into dynamic_attributes
2021-08-26 15:04:14 +03:00
Sandeep Singh
e66463d466
Merge pull request #2355 from G4L1T0/corsmisc
...
add cors-misconfig.yaml
2021-08-26 04:26:37 +05:30
sandeep
1999a9b560
Enhanced CORS checks
2021-08-26 04:24:06 +05:30
sandeep
05305904ef
more strict matchers
2021-08-26 02:43:53 +05:30
socketz
ed76585ed6
Merge branch 'master' of https://github.com/projectdiscovery/nuclei-templates
2021-08-25 14:33:32 +02:00
socketz
c766a8454d
Fixed yaml linting errors
2021-08-25 14:09:42 +02:00
sandeep
8fb3c65965
template fix
2021-08-25 01:32:14 +05:30
forgedhallpass
110f9c9ddd
Merge remote-tracking branch 'origin' into dynamic_attributes
2021-08-24 20:38:11 +03:00
Sandeep Singh
ee37e34f54
Update wp-woocommerce-pdf-invoice-listing.yaml
2021-08-24 17:48:31 +05:30
Prince Chaddha
f66f36237b
Merge pull request #2455 from gy741/rule-add-v58
...
Create commax-biometric-access-control-system-auth-bypass.yaml
2021-08-24 17:44:13 +05:30
Prince Chaddha
554c4a505f
Update and rename commax-biometric-access-control-system-auth-bypass.yaml to commax-biometric-auth-bypass.yaml
2021-08-24 17:17:43 +05:30
Prince Chaddha
0a4cd456bf
Update commax-biometric-access-control-system-auth-bypass.yaml
2021-08-24 17:13:17 +05:30
Prince Chaddha
ba03c2b377
Update unauth-hoteldruid-panel.yaml
2021-08-24 16:46:24 +05:30
Prince Chaddha
d1065cd3fc
Create unauth-hoteldruid-panel.yaml
2021-08-24 16:42:11 +05:30
PikPikcU
ecd6547d05
Update thinkific-redirect.yaml
2021-08-24 14:56:21 +07:00
forgedhallpass
a124e393b4
Merge remote-tracking branch 'origin' into dynamic_attributes
2021-08-23 19:15:14 +03:00
Prince Chaddha
647d27925a
Merge pull request #2426 from projectdiscovery/generic
...
Templates by geeknik
2021-08-23 19:55:32 +05:30
forgedhallpass
296edfc37b
Merge remote-tracking branch 'origin' into dynamic_attributes
2021-08-23 14:40:33 +03:00
Sandeep Singh
04b401a8ef
Merge pull request #2456 from projectdiscovery/payloads-update
...
Payloads positional update to keep the request format uniform
2021-08-23 15:26:35 +05:30
sandeep
62530eafc2
Update wp-slideshow-xss.yaml
2021-08-23 15:15:26 +05:30
sandeep
2aa54304ee
Payloads positional update to keep the request format uniform
2021-08-22 23:39:33 +05:30
GwanYeong Kim
cad976abda
Create commax-biometric-access-control-system-auth-bypass.yaml
...
The application suffers from an authentication bypass vulnerability. An unauthenticated attacker through cookie poisoning can bypass authentication and disclose sensitive information and circumvent physical controls in smart homes and buildings.
Signed-off-by: GwanYeong Kim <gy741.kim@gmail.com>
2021-08-22 18:19:34 +09:00
sandeep
cbdef618f3
Update netgear-router-exposure.yaml
2021-08-21 00:38:54 +05:30
forgedhallpass
dc4cc62629
Merge remote-tracking branch 'origin/master' into dynamic_attributes
2021-08-20 15:35:17 +03:00
sandeep
e160acb481
misc updates
2021-08-20 16:37:22 +05:30
sandeep
0ef2106a6e
Improved template
2021-08-19 23:34:16 +05:30
Sandeep Singh
0bef05c541
Merge pull request #793 from pikpikcu/patch-40
...
resin information disclosure
2021-08-19 23:15:42 +05:30
Sandeep Singh
ab824564d3
minor updates
2021-08-19 23:11:29 +05:30
Sandeep Singh
1247fcd993
Update vulnerabilities/other/caucho-resin-info-disclosure.yaml
...
Co-authored-by: Toufik Airane <toufik.airane@appsectribe.com>
2021-08-19 23:09:26 +05:30
forgedhallpass
77103bc629
Satisfying the linter (all errors and warnings)
...
* whitespace modifications only
2021-08-19 17:44:46 +03:00
forgedhallpass
002e8db616
Moved the "vendor" custom attribute under reference
...
Related nuclei tickets:
* #259 - dynamic key-value field support for template information
* #940 - new infos in template
* #834
* RES-84
2021-08-19 17:00:46 +03:00
forgedhallpass
97d4f8705b
Fixed mistakes/typos
...
Related nuclei tickets:
* #259 - dynamic key-value field support for template information
* #940 - new infos in template
* #834
* RES-84
2021-08-19 16:59:55 +03:00
forgedhallpass
f55d6b75e1
Removed pipe (|) character from references, because the structure requires it to be a string slice, not a string
...
Related nuclei tickets:
* #259 - dynamic key-value field support for template information
* #940 - new infos in template
* #834
* RES-84
2021-08-19 16:59:12 +03:00
forgedhallpass
7b29be739e
Merge branch 'master' into dynamic_attributes
2021-08-19 16:23:26 +03:00
forgedhallpass
ffaff64565
Changes fixes/around dynamic attributes ("additional-fields")
...
Related nuclei tickets:
* #259 - dynamic key-value field support for template information
* #940 - new infos in template
* #834
* RES-84
2021-08-19 16:17:27 +03:00
forgedhallpass
0b432b341b
Added comments with URLs under the "references" field
...
Related nuclei tickets:
* #259 - dynamic key-value field support for template information
* #940 - new infos in template
* #834
* RES-84
2021-08-19 16:15:35 +03:00
forgedhallpass
e68d15ab63
Fixed mistakes/typos in the templates.
...
Related nuclei tickets:
* #259 - dynamic key-value field support for template information
* #940 - new infos in template
* #834
* RES-84
2021-08-19 15:30:14 +03:00
Prince Chaddha
bc1bf5d919
Create comtrend-ct5367-disclosure.yaml
2021-08-19 14:47:44 +05:30
Prince Chaddha
f8a8968408
Revert "Create comtrend-ct5367-disclosure.yaml"
...
This reverts commit 33ea2d360c
.
2021-08-19 14:46:35 +05:30
Prince Chaddha
33ea2d360c
Create comtrend-ct5367-disclosure.yaml
2021-08-19 14:45:37 +05:30
Sandeep Singh
ab0750b570
minor update
2021-08-19 00:43:44 +05:30
forgedhallpass
cdf9451158
Removed pipe (|) character from references, because the structure requires it to be a string slice, not a string
...
Related nuclei tickets:
* #259 - dynamic key-value field support for template information
* #940 - new infos in template
* #834
* RES-84
2021-08-18 14:44:27 +03:00
Prince Chaddha
dd1bbe6093
Revert "Delete netgear-router-disclosure.yaml"
...
This reverts commit 3b969e7e0d
.
2021-08-18 17:02:08 +05:30
Prince Chaddha
3b969e7e0d
Delete netgear-router-disclosure.yaml
2021-08-18 16:59:49 +05:30
forgedhallpass
4c920b2552
Rename "references" to "reference" to match the expected template info structure
...
Related nuclei tickets:
* #259 - dynamic key-value field support for template information
* #940 - new infos in template
* #834
* RES-84
2021-08-18 14:29:20 +03:00
Prince Chaddha
0a0b5c7f74
Update netgear-router-disclosure.yaml
2021-08-18 16:56:56 +05:30
Prince Chaddha
d07323e0be
Create netgear-router-disclosure.yaml
2021-08-18 16:44:28 +05:30
Prince Chaddha
af15e4817f
Update netgear-router-auth-bypass.yaml
2021-08-18 16:42:34 +05:30
Prince Chaddha
067c9a8755
Create xmlrpc-pingback-ssrf.yaml
2021-08-18 16:39:22 +05:30
Prince Chaddha
fe1e7d36fb
Merge pull request #2429 from Mad-robot/patch-3
...
Create geovision-geowebserver-lfi.yaml
2021-08-18 16:19:49 +05:30
Prince Chaddha
0731a772d4
Update geovision-geowebserver-lfi.yaml
2021-08-18 16:18:12 +05:30
Prince Chaddha
1db2715a06
Update geovision-geowebserver-xss.yaml
2021-08-18 14:51:23 +05:30
Prince Chaddha
eeb284a7ec
Update geovision-geowebserver-xss.yaml
2021-08-18 14:48:34 +05:30
SaN ThosH
db4073d2b5
Update geovision-geowebserver-lfi.yaml
2021-08-18 03:54:30 +05:30
SaN ThosH
d5748c95fc
Create geovision-geowebserver-lfi.yaml
2021-08-18 03:50:45 +05:30
SaN ThosH
0c24cc2f74
Create geovision-geowebserver-xss.yaml
2021-08-18 03:50:39 +05:30
Prince Chaddha
f60cef447b
Update generic-blind-xxe.yaml
2021-08-17 22:57:34 +05:30
Prince Chaddha
727e73c5c3
Create solar-log-authbypass.yaml
2021-08-17 18:02:41 +05:30
Prince Chaddha
c39f0e2077
Create generic-blind-xxe.yaml
2021-08-17 17:18:52 +05:30
Sandeep Singh
59b2aeda40
Merge pull request #2420 from geeknik/patch-18
...
Update twig-php-ssti.yaml
2021-08-17 17:12:00 +05:30
sandeep
c2f87671fb
strict matcher
2021-08-17 15:52:22 +05:30
sandeep
03cd55a33f
severity update based on poc
...
We will update this again as per assigned CVE which is not available right now?
2021-08-17 15:02:47 +05:30
sandeep
4a5137b742
more tags
2021-08-17 15:00:30 +05:30
sandeep
e8c3a1f9c7
Additional matchers update
2021-08-17 15:00:05 +05:30
Sanyam Chawla
5072dbbcbb
Create ms-exchange-server-reflected-xss.yaml
2021-08-17 13:55:38 +05:30
Geeknik Labs
3b9fb75fcb
Update twig-php-ssti.yaml
...
Another FP fix
2021-08-16 15:30:23 -05:00
Geeknik Labs
d52c97c569
Update twig-php-ssti.yaml
...
False positive fix
2021-08-16 15:28:13 -05:00
Prince Chaddha
970bdb3ac7
Update pmb-directory-traversal.yaml
2021-08-16 16:43:47 +05:30
Prince Chaddha
d45887f9f9
Delete node-nunjucks-ssti.yaml
2021-08-16 16:41:58 +05:30
Prince Chaddha
d3a379e112
Update eyelock-nano-lfd.yaml
2021-08-16 16:40:42 +05:30
Prince Chaddha
af4f29ab03
Update beward-ipcamera-disclosure.yaml
2021-08-16 16:37:34 +05:30
Prince Chaddha
4e498a6478
Create pmb-directory-traversal.yaml
2021-08-16 16:14:02 +05:30
Prince Chaddha
451823f887
Create node-nunjucks-ssti.yaml
2021-08-16 16:13:27 +05:30
Prince Chaddha
c6927262eb
Create eyelock-nano-lfd.yaml
2021-08-16 16:12:45 +05:30
Prince Chaddha
232b187a40
Create beward-ipcamera-disclosure.yaml
2021-08-16 16:11:44 +05:30
sandeep
3ac7a756fc
Added woocommerce-pdf-invoice-listing
2021-08-16 15:37:07 +05:30
Prince Chaddha
b3d27f3d0c
Merge pull request #2407 from DhiyaneshGeek/master
...
Oracle XSS
2021-08-16 14:14:20 +05:30
Prince Chaddha
610924d55b
Update oracle-siebel-xss.yaml
2021-08-16 14:12:49 +05:30
Prince Chaddha
2875be2d82
Update simple-crm-sql-injection.yaml
2021-08-16 14:06:18 +05:30
Prince Chaddha
bd865a0615
Update simple-crm-sql-injection.yaml
2021-08-16 14:03:41 +05:30
Prince Chaddha
2a448b52db
Update simple-crm-sql-injection.yaml
2021-08-16 14:03:09 +05:30
Geeknik Labs
cacb2ff684
Update simple-crm-sql-injection.yaml
2021-08-15 15:28:00 -05:00
Geeknik Labs
9fb1b464b4
Create simple-crm-sql-injection.yaml
2021-08-15 15:23:38 -05:00
Dhiyaneshwaran
cceb32a88b
Create oracle-siebel-xss.yaml
2021-08-15 23:18:13 +05:30
Prince Chaddha
7bce4fbb26
Update netis-info-leak.yaml
2021-08-14 16:00:00 +05:30
Prince Chaddha
edffa49ca4
Update netis-info-leak.yaml
2021-08-14 15:53:30 +05:30
GwanYeong Kim
5b81af7ab4
Create netis-info-leak.yaml
...
Signed-off-by: GwanYeong Kim <gy741.kim@gmail.com>
2021-08-13 13:34:28 +09:00
sandeep
df65ba694b
Update ewebs-arbitrary-file-reading.yaml
2021-08-12 18:19:22 +05:30
PikPikcU
65ed503022
Create ewebs-arbitrary-file-reading.yaml
2021-08-12 18:41:02 +07:00
Sandeep Singh
5ca0a70f3e
Merge pull request #2372 from projectdiscovery/buffalo
...
Added CVE-2021-20090 / CVE-2021-20091 / CVE-2021-20092
2021-08-12 16:07:45 +05:30
Prince Chaddha
0875847c7d
Merge pull request #2374 from gy741/rule-add-v54
...
Create sar2html-rce.yaml
2021-08-12 15:06:13 +05:30
Prince Chaddha
cfc534af89
Update sar2html-rce.yaml
2021-08-12 15:03:49 +05:30
sandeep
98a07bd594
Added unauth config injection
2021-08-12 14:12:20 +05:30
Prince Chaddha
6ac4da7993
Merge branch 'master' into corsmisc
2021-08-11 13:17:10 +05:30
Prince Chaddha
b466fce758
Update basic-cors.yaml
2021-08-11 13:15:04 +05:30
Prince Chaddha
5ac272597b
Delete cors-misconfig.yaml
2021-08-11 13:14:04 +05:30
Prince Chaddha
cb94b58009
Update basic-cors.yaml
2021-08-11 13:13:45 +05:30
Prince Chaddha
d49dc5f9d4
Update top-xss-params.yaml
2021-08-11 13:08:49 +05:30
Prince Chaddha
c576f4317b
Update open-redirect.yaml
2021-08-11 13:08:24 +05:30
Prince Chaddha
efa7319d40
Update generic-windows-lfi.yaml
2021-08-11 13:08:11 +05:30
Prince Chaddha
57b8d89815
Update generic-linux-lfi.yaml
2021-08-11 13:08:00 +05:30
Prince Chaddha
cbfe76f33f
Update error-based-sql-injection.yaml
2021-08-11 13:07:46 +05:30
Prince Chaddha
aa0b195c99
Update crlf-injection.yaml
2021-08-11 13:07:36 +05:30
Prince Chaddha
2165418c59
Update cache-poisoning.yaml
2021-08-11 13:07:27 +05:30
Prince Chaddha
4d4ae2edd2
Update basic-xss-prober.yaml
2021-08-11 13:07:17 +05:30
Prince Chaddha
791472aa2b
Update basic-cors.yaml
2021-08-11 13:07:05 +05:30
GwanYeong Kim
0d2b53e71d
Create sar2html-rce.yaml
...
SAR2HTML could allow a remote attacker to execute arbitrary commands on the system, caused by a commend injection flaw in the index.php script. By sending specially-crafted commands, an attacker could exploit this vulnerability to execute arbitrary commands on the system.
Signed-off-by: GwanYeong Kim <gy741.kim@gmail.com>
2021-08-11 14:11:25 +09:00
sandeep
8c48ca97d2
matcher + payload + regex updates
2021-08-09 21:58:28 +05:30
G4L1T0
a44324ec2f
updatev2 cors-misconfig.yaml
2021-08-09 11:57:37 -03:00
G4L1T0
e98fb7179e
update cors-misconfig.yaml
2021-08-09 11:56:37 -03:00
Noam Rathaus
a806149864
Spelling
2021-08-09 16:31:00 +03:00
Noam Rathaus
864b209cc1
Add reference
2021-08-09 16:10:10 +03:00
Noam Rathaus
3651410d37
Provide description
2021-08-09 16:08:19 +03:00
Sandeep Singh
210c57768d
Merge pull request #2193 from gy741/rule-add-v42
...
Create kevinlab-hems-backdoor.yaml
2021-08-08 13:56:56 +05:30
Sandeep Singh
3918071875
Merge pull request #2348 from Akokonunes/patch-25
...
Create grimag-open-redirect.yaml
2021-08-08 12:38:24 +05:30
sandeep
d7b8760231
minor update
2021-08-08 12:29:11 +05:30
sandeep
4c057dcb1e
minor update
2021-08-08 12:26:34 +05:30
sandeep
a7dcd3f317
added more tags
2021-08-08 00:27:18 +05:30
sandeep
3b6d6322ea
Additional matcher
2021-08-08 00:22:55 +05:30
sandeep
e690901c86
minor update
2021-08-08 00:20:56 +05:30
Sandeep Singh
0ee60c4a3e
Merge pull request #2197 from mesaglio/master
...
Detect azure directory traversal hosts file
2021-08-07 23:15:29 +05:30
sandeep
318aa4736e
misc update
2021-08-07 23:04:27 +05:30
sandeep
2233ebf3f1
moving files around
2021-08-07 23:02:17 +05:30
sandeep
ca9efec5c0
tag update
2021-08-07 15:00:29 +05:30
Dhiyaneshwaran
afcbd374a9
Create sap-redirect.yaml
2021-08-07 11:31:58 +05:30