Commit Graph

2745 Commits (d7534c8e71c62cfa4ee93d12608fc948c3219b83)

Author SHA1 Message Date
Dhiyaneshwaran 00acbe2bbb
Update cisco-vmanage-log4j.yaml 2022-10-20 02:30:56 +05:30
Prince Chaddha 2a411bef99
Merge pull request #5734 from projectdiscovery/fix-fp-rundeck-log4j
Update rundeck-log4j.yaml
2022-10-19 22:48:46 +05:30
Prince Chaddha 1e62e0720b
Merge pull request #5733 from projectdiscovery/fix-fp-metabase-log4j
Update metabase-log4j.yaml
2022-10-19 22:44:00 +05:30
Dhiyaneshwaran 499432b36a
Update rundeck-log4j.yaml 2022-10-19 17:43:25 +05:30
Dhiyaneshwaran 0b345ce6c7
Update metabase-log4j.yaml 2022-10-19 16:44:22 +05:30
Prince Chaddha 04846d28d2
Update vmware-nsx-log4j.yaml 2022-10-19 16:30:06 +05:30
Dhiyaneshwaran 6d591d01c4
Update vmware-nsx-log4j.yaml 2022-10-19 16:15:30 +05:30
Joshua Rogers 86bb38b96d
Fix typo in unaunthenticated-jenkin.yaml (#5724)
* Fix typo in unaunthenticated-jenkin.yaml

* Rename unaunthenticated-jenkin.yaml to unauthenticated-jenkins.yaml
2022-10-19 03:54:33 +05:30
Prince Chaddha c6cc78bcf1
Delete omnia-mpx-lfi.yaml 2022-10-17 13:03:17 +05:30
Prince Chaddha 75fdd023c5
Update flatpress-xss.yaml 2022-10-14 17:13:39 +05:30
Ritik Chaddha 2411426ed1
Update flatpress-xss.yaml 2022-10-14 11:41:59 +05:30
Ritik Chaddha 1878bae200
Update flatpress-xss.yaml 2022-10-13 16:26:36 +05:30
Arafat Ansari e4682184c2
Update flatpress-xss.yaml 2022-10-13 16:12:51 +05:30
Arafat Ansari ed83463ff3
Create flatpress-xss.yaml 2022-10-13 16:11:15 +05:30
GitHub Action 3fba7301e0 Auto Generated CVE annotations [Wed Oct 12 10:44:42 UTC 2022] 🤖 2022-10-12 10:44:42 +00:00
Prince Chaddha fa56e9eca9
Update vmware-operation-manager-log4j.yaml 2022-10-12 15:01:48 +05:30
Prince Chaddha 714813c445
Update vmware-hcx-log4j.yaml 2022-10-12 15:01:02 +05:30
Prince Chaddha 8be5694398
Update jamf-pro-log4j.yaml 2022-10-12 15:00:26 +05:30
Prince Chaddha fe3921231f
Update graylog-log4j.yaml 2022-10-12 14:59:44 +05:30
Prince Chaddha 9dccfb90ae
Update cisco-unified-communications-log4j.yaml 2022-10-12 14:59:13 +05:30
Prince Chaddha bf451ad15a
Update vmware-nsx-log4j.yaml 2022-10-12 14:58:33 +05:30
Prince Chaddha e0bf6d8e07
Update opennms-log4j-jndi-rce.yaml 2022-10-12 14:57:53 +05:30
Prince Chaddha a62dffe4bb
Update cisco-vmanage-log4j.yaml 2022-10-12 14:57:15 +05:30
Prince Chaddha 847d2b9631
Update rundeck-log4j.yaml 2022-10-12 14:56:48 +05:30
Prince Chaddha 386b4da10b
Update rundeck-log4j.yaml 2022-10-12 14:56:33 +05:30
Prince Chaddha cc897f6980
Update metabase-log4j.yaml 2022-10-12 14:55:31 +05:30
GitHub Action 6ab6aa6aa3 Auto Generated CVE annotations [Mon Oct 10 20:06:39 UTC 2022] 🤖 2022-10-10 20:06:39 +00:00
MostInterestingBotInTheWorld bcd4ae950d
Standardize Log4j Entries (#5634)
* Standardize Log4j name and classification fields

Co-authored-by: sullo <sullo@cirt.net>
2022-10-10 15:51:42 -04:00
GitHub Action a8c023abc4 Auto Generated CVE annotations [Mon Oct 10 19:40:25 UTC 2022] 🤖 2022-10-10 19:40:25 +00:00
MostInterestingBotInTheWorld 5892582899
Dashboard Content Enhancements (#5582)
Dashboard Content Enhancements
2022-10-10 15:22:59 -04:00
Sandeep Singh 712264db7e
Using "host-redirects" instead of "redirects" to avoid scanning 3rd party / out of scope hosts. (#5491) 2022-10-08 02:57:25 +05:30
Prince Chaddha 66059c01e2
Update unauthenticated-duplicator-disclosure.yaml 2022-10-01 20:59:50 +05:30
Ritik Chaddha 6f2f9abaa8
Update unauthenticated-duplicator-disclosure.yaml 2022-10-01 02:56:16 +05:30
Arman d19b29dc55
Create unauthenticated-duplicator-disclosure.yaml 2022-09-30 17:06:18 -04:00
GitHub Action cc11df1ede Auto Generated CVE annotations [Thu Sep 29 13:52:24 UTC 2022] 🤖 2022-09-29 13:52:24 +00:00
MostInterestingBotInTheWorld 1fa47500e4
Dashboard Content Enhancements (#5497)
Dashboard Content Enhancements
2022-09-29 09:38:41 -04:00
Dhiyaneshwaran fe3ba681b1
Create xenmobile-server-log4j.yaml 2022-09-29 12:14:52 +05:30
Sandeep Singh 34234c7a14
Added Web Page Test - Server Side Request Forgery (SSRF) (#5456) 2022-09-24 19:17:03 +05:30
GitHub Action 0851e093dc Auto Generated CVE annotations [Fri Sep 23 18:06:19 UTC 2022] 🤖 2022-09-23 18:06:19 +00:00
MostInterestingBotInTheWorld 529582c200
Dashboard Content Enhancements (#5455)
Dashboard Content Enhancements
2022-09-23 13:53:08 -04:00
GitHub Action daf007b79b Auto Generated CVE annotations [Fri Sep 23 11:36:52 UTC 2022] 🤖 2022-09-23 11:36:52 +00:00
Prince Chaddha 8ae53a1e66
Update age-gate-xss.yaml 2022-09-23 16:51:01 +05:30
Ritik Chaddha 0c79fc2594
Create age-gate-xss.yaml 2022-09-23 16:48:11 +05:30
st0fm 34a9d5d4ee
fix [WRN] [cors-misconfig] unresolved variables found: path (#5435)
* fix [WRN] [cors-misconfig] Could not make http request for..  unresolved variables found: path

* Additional path fix

Co-authored-by: sandeep <sandeep@projectdiscovery.io>
2022-09-22 11:40:37 +05:30
GitHub Action 0920762894 Auto Generated CVE annotations [Wed Sep 21 21:56:03 UTC 2022] 🤖 2022-09-21 21:56:03 +00:00
MostInterestingBotInTheWorld 1437dc1f59
Dashboard Content Enhancements (#5436)
Dashboard Content Enhancements
2022-09-21 17:42:27 -04:00
MostInterestingBotInTheWorld 3bc2e26e40
Dashboard Content Enhancements (#5372)
Dashboard Content Enhancements
2022-09-16 15:50:10 -04:00
Prince Chaddha 9addaee48f
Merge pull request #5365 from arafatansari/patch-89
Create hms-xss-2.yaml
2022-09-15 17:44:59 +05:30
Prince Chaddha d634588031
Merge pull request #5364 from arafatansari/patch-88
Create hms-xss.yaml
2022-09-15 17:43:14 +05:30
Prince Chaddha 28d456386c
Merge pull request #5352 from For3stCo1d/wapples-firewall-lfi
Create wapples-firewall-lfi.yaml
2022-09-15 17:28:44 +05:30
Prince Chaddha abe1487a4d
Update and rename 3DPrint-arbitrary-file-upload.yaml to 3dprint-arbitrary-file-upload.yaml 2022-09-15 15:51:34 +05:30
GitHub Action 84abeba9f8 Auto Generated CVE annotations [Thu Sep 15 09:30:23 UTC 2022] 🤖 2022-09-15 09:30:23 +00:00
Prince Chaddha aba55a3dd6
Merge pull request #5325 from projectdiscovery/3DPrint-arbitrary-file-upload
Create 3DPrint-arbitrary-file-upload.yaml
2022-09-15 14:51:59 +05:30
Prince Chaddha 6e98f462f7
Update 3DPrint-arbitrary-file-upload.yaml 2022-09-15 14:50:10 +05:30
Ritik Chaddha 8c672ef591
Update and rename hms-xss-2.yaml to hospital-management-xss2.yaml 2022-09-15 14:02:02 +05:30
Ritik Chaddha d7d164bd18
Update and rename hms-xss.yaml to hospital-management-xss.yaml 2022-09-15 13:57:26 +05:30
Arafat Ansari 99e5365479
Update hms-xss-2.yaml 2022-09-14 18:47:17 +05:30
Arafat Ansari b287e54f25
Update hms-xss.yaml 2022-09-14 18:38:44 +05:30
Arafat Ansari 9f3ed18b28
Create hms-xss-2.yaml 2022-09-14 18:37:11 +05:30
Arafat Ansari 1b9b7e3ac0
Create hms-xss.yaml 2022-09-14 18:31:55 +05:30
Ritik Chaddha 64fc8aaba0
Update wapples-firewall-lfi.yaml 2022-09-14 16:12:34 +05:30
林寒 b1eb1e3ef9
Create wapples-firewall-lfi.yaml 2022-09-14 12:13:52 +08:00
0x08 2c51f8ec00
Merge branch 'projectdiscovery:master' into patch-1 2022-09-12 15:22:21 +03:00
GitHub Action 724269bac5 Auto Generated CVE annotations [Mon Sep 12 11:34:28 UTC 2022] 🤖 2022-09-12 11:34:28 +00:00
Prince Chaddha 86d7f1b84a
Merge branch 'master' into patch-1 2022-09-12 16:56:13 +05:30
Prince Chaddha 9cad294004
Merge branch 'master' into patch-2 2022-09-12 16:41:45 +05:30
Prince Chaddha 56ec9d8200
Merge pull request #5339 from Akokonunes/patch-181
Create schneider-electric-pelco-videoxpert-core-admin-portal-lfi.yaml
2022-09-12 16:23:56 +05:30
Prince Chaddha 6b488e508b
Update videoxpert-lfi.yaml 2022-09-12 16:21:21 +05:30
Dhiyaneshwaran d04f55721c
Update videoxpert-lfi.yaml 2022-09-12 16:20:19 +05:30
Dhiyaneshwaran 0b062a58e8
Update videoxpert-lfi.yaml 2022-09-12 15:20:52 +05:30
Dhiyaneshwaran d1d0f8e65b
Update and rename schneider-electric-pelco-videoxpert-core-admin-portal-lfi.yaml to vulnerabilities/videoxpert-lfi.yaml 2022-09-12 14:03:36 +05:30
dave 2ad1894537 fix template description 2022-09-11 19:48:17 +02:00
GitHub Action a6dee5c3c4 Auto Generated CVE annotations [Sat Sep 10 02:12:57 UTC 2022] 🤖 2022-09-10 02:12:57 +00:00
MostInterestingBotInTheWorld 800648aa7e
Dashboard Merge Issues Resolution (#5337)
* Auto Generated CVE annotations [Wed Sep  7 15:59:37 UTC 2022] 🤖
* Fixed merge issues from previous PR
* moved vulnerabilities/wordpress/CVE-2019-10692.yaml to cves dir
* Fix CVSS information and other minor merge issues

Co-authored-by: Sullo <sullo@cirt.net>
2022-09-09 21:55:52 -04:00
sullo b65c24c45e
Normalization of Cross-Site Scripting names (#5329) 2022-09-09 23:04:37 +05:30
Moayad Almalat 10febf172b
update wp-sym404.yaml
Changed High to high, :) i.e. lowercase
2022-09-09 10:21:36 +02:00
sullo 0126f9426e
Replace google-dork with google-query in all templates (#5328)
* dos2unix to standardize line endings

* Replace google-dork with google-query
2022-09-09 04:09:14 +05:30
MostInterestingBotInTheWorld 554c11c57b
Dashboard Content Enhancements (#5324)
Dashboard Content Enhancements
* dos2nix on several templates
* replacing some cvedetails links with NIST
2022-09-08 09:28:46 -04:00
Ritik Chaddha 3cedf0bd5f
Update 3DPrint-arbitrary-file-upload.yaml 2022-09-07 11:29:34 +05:30
Ritik Chaddha 963ae9342c
Create 3DPrint-arbitrary-file-upload.yaml 2022-09-07 11:26:34 +05:30
Prince Chaddha db22c1efa6
Update brightsign-dsdws-ssrf.yaml 2022-09-06 00:41:39 +05:30
Dhiyaneshwaran 3f930c57ac
Update brightsign-dsdws-ssrf.yaml 2022-09-02 11:30:44 +05:30
Dhiyaneshwaran 35d2ca68f9
Rename brightsign-dsdws-ssrf.yaml to vulnerabilities/other/brightsign-dsdws-ssrf.yaml 2022-09-02 11:28:57 +05:30
Prince Chaddha b0aaf21c36
Merge pull request #5266 from projectdiscovery/update-generic-linux-lfi
Update generic-linux-lfi.yaml
2022-09-02 10:22:44 +05:30
Prince Chaddha f0d0eff9ca
Update generic-linux-lfi.yaml 2022-09-02 01:48:37 +05:30
Dhiyaneshwaran 5e0f3a4229
Update generic-linux-lfi.yaml 2022-09-02 01:42:47 +05:30
Prince Chaddha 20a8a768d7
Update thinkcmf-arbitrary-code-execution.yaml 2022-09-02 01:38:27 +05:30
Prince Chaddha 931ca5c86f
Merge pull request #5268 from projectdiscovery/generic-windows-lfi
Update generic-windows-lfi.yaml
2022-09-02 01:19:13 +05:30
Prince Chaddha 9044284100
Merge branch 'master' into fileupload 2022-09-01 16:21:29 +05:30
Ritik Chaddha 471ae0fdce
Update generic-windows-lfi.yaml 2022-09-01 14:10:45 +05:30
Dhiyaneshwaran ea617f1ca3
Update dixell-xweb500-filewrite.yaml 2022-09-01 01:38:57 +05:30
Dhiyaneshwaran b839a4cb52
Update powercreator-cms-rce.yaml 2022-09-01 01:38:38 +05:30
Dhiyaneshwaran 028974759f
Update core-chuangtian-cloud-rce.yaml 2022-09-01 01:34:08 +05:30
Dhiyaneshwaran 81111ebb5e
Update wordpress-rce-simplefilelist.yaml 2022-09-01 01:32:51 +05:30
Dhiyaneshwaran fc7afa9f73
Update ait-csv-import-export-rce.yaml 2022-09-01 01:30:11 +05:30
Dhiyaneshwaran 23c86be97b
Update oa-v9-uploads-file.yaml 2022-09-01 01:29:39 +05:30
Dhiyaneshwaran ab10ad02cf
Update zhiyuan-file-upload.yaml 2022-09-01 01:28:54 +05:30
Dhiyaneshwaran 48ae8a32ff
Update cisco-rv-series-rce.yaml 2022-09-01 01:00:07 +05:30
Dhiyaneshwaran 25b136bf87
Update dixell-xweb500-filewrite.yaml 2022-09-01 00:57:38 +05:30
Dhiyaneshwaran d1186e3718
Update ait-csv-import-export-rce.yaml 2022-09-01 00:57:03 +05:30
Dhiyaneshwaran 82a860e347
Update core-chuangtian-cloud-rce.yaml 2022-09-01 00:56:04 +05:30
Dhiyaneshwaran 00b623d6a3
Update zhiyuan-file-upload.yaml 2022-09-01 00:45:27 +05:30
Dhiyaneshwaran 1ae6897871
Update oa-v9-uploads-file.yaml 2022-09-01 00:41:57 +05:30
Prince Chaddha 3f7a72b318
Update wordpress-accessible-wpconfig.yaml 2022-09-01 00:05:57 +05:30
Ritik Chaddha 3a939783b8
Update generic-windows-lfi.yaml 2022-08-31 23:12:58 +05:30
Ritik Chaddha b34b02ebd4 Revert "Update generic-windows-lfi.yaml"
This reverts commit a3076a43ac.
2022-08-31 23:11:07 +05:30
Ritik Chaddha 8c20c20328 Revert "Revert "Update generic-windows-lfi.yaml""
This reverts commit 2d626ef0fe.
2022-08-31 23:09:04 +05:30
Ritik Chaddha 2d626ef0fe Revert "Update generic-windows-lfi.yaml"
This reverts commit a3076a43ac.
2022-08-31 23:08:24 +05:30
Ritik Chaddha a3076a43ac
Update generic-windows-lfi.yaml 2022-08-31 23:05:41 +05:30
Dhiyaneshwaran 2dea6ed916
Update generic-linux-lfi.yaml 2022-08-31 22:03:32 +05:30
Dhiyaneshwaran 234b6a417a
Update generic-linux-lfi.yaml 2022-08-31 22:01:15 +05:30
its0x08 d634bb63d7 chore: Add reference to the template 2022-08-31 00:02:32 +02:00
0x08 0ea1df844a
fix: Update the template to avoid false positives
While testing I got a false positive. The `phpinfo();` was one `index.php` and any parameter appended did not affect the output. So I got a false positive because the template tests for `phpinfo();`. So I propose that the test string is updated to something random and if there is execution the string will show on the output.
2022-08-31 00:03:36 +03:00
MostInterestingBotInTheWorld 36cf9b2f61
Dashboard Enhancements + Severity Matching (#5245)
Dashboard Enhancements + Severity Matching
2022-08-29 16:21:30 -04:00
GitHub Action bc21497f99 Auto Generated CVE annotations [Sat Aug 27 04:41:18 UTC 2022] 🤖 2022-08-27 04:41:18 +00:00
Prince Chaddha 9838347cc3
Merge pull request #5027 from akincibor/wp-enhancement
Update Wordpress templates: typo, cve-id, ref & remove dupe
2022-08-25 14:12:13 +05:30
Prince Chaddha 15dbade56b
Merge pull request #5191 from arafatansari/patch-70
Create gnuboard5-rxss.yaml
2022-08-25 12:39:34 +05:30
Prince Chaddha ff82f4311d
Rename vulnerabilities/other/gnuboard5-rxss.yaml to vulnerabilities/gnuboard/gnuboard5-rxss.yaml 2022-08-25 12:27:51 +05:30
Prince Chaddha 409b655062
Rename vulnerabilities/other/gnuboard-sms-xss.yaml to vulnerabilities/gnuboard/gnuboard-sms-xss.yaml 2022-08-25 11:58:06 +05:30
Prince Chaddha 080906ab35
Update and rename vulnerabilities/other/gnuboard5-xss.yaml to vulnerabilities/gnuboard/gnuboard5-xss.yaml 2022-08-25 11:57:28 +05:30
Ritik Chaddha 3497197092
Update gnuboard5-rxss.yaml 2022-08-24 12:29:34 +05:30
Ritik Chaddha f7e6c4d03d
Update gnuboard5-xss.yaml 2022-08-24 12:23:48 +05:30
Arafat Ansari f5a80bcfe3
Create gnuboard5-rxss.yaml 2022-08-24 00:36:54 +05:30
Arafat Ansari 7dfd3a4edd
Create gnuboard5-xss.yaml 2022-08-24 00:21:46 +05:30
HJLee 660e8d3214 Modify spacing between id and info 2022-08-22 16:17:05 +09:00
Prince Chaddha 6bded3407c
Merge pull request #5117 from projectdiscovery/thruk-xss
Update thruk-xss.yaml
2022-08-16 18:03:41 -07:00
Prince Chaddha 486845f91f
Update thruk-xss.yaml 2022-08-17 05:00:25 +04:00
Prince Chaddha d90538043f
Merge pull request #5104 from djoevanka/patch-1
Added concrete-xss
2022-08-15 15:23:44 -07:00
Prince Chaddha 7269960168
Delete concrete-xss.yaml 2022-08-15 15:05:45 -07:00
Prince Chaddha 9f5ebd2182
Update concrete-xss.yaml 2022-08-15 14:55:19 -07:00
Ritik Chaddha 962bd2a744
Update thruk-xss.yaml 2022-08-15 14:27:04 +05:30
djojoe 5a3a34e4e2
Create concrete-xss.yaml 2022-08-14 20:18:48 +07:00
Prince Chaddha 0bdb85d570
Merge pull request #5091 from arafatansari/patch-52
Create dzzoffice-xss.yaml
2022-08-13 21:45:36 -07:00
Prince Chaddha 3b5c473606
Merge pull request #5081 from arafatansari/patch-51
Create kavita-lfi.yaml
2022-08-12 16:33:40 -07:00
Prince Chaddha 000c7c42d6
Update kavita-lfi.yaml 2022-08-12 16:23:16 -07:00
Prince Chaddha 338271dd97
Update and rename reddittoprss-xss.yaml to reddittop-rss-xss.yaml 2022-08-12 16:16:37 -07:00
Ritik Chaddha 12a76141a2
Update dzzoffice-xss.yaml 2022-08-13 00:37:24 +05:30
Arafat Ansari dc778f626a
Create dzzoffice-xss.yaml 2022-08-12 23:41:26 +05:30
Ritik Chaddha 5c867517d0
Update kavita-lfi.yaml 2022-08-12 16:14:39 +05:30
Ritik Chaddha aa8da9ab43
Update reddittoprss-xss.yaml 2022-08-12 15:55:22 +05:30
Arafat Ansari 6b6e82d232
Create kavita-lfi.yaml 2022-08-12 12:41:00 +05:30
Arafat Ansari 4b007e87d2
Create reddittoprss-xss.yaml 2022-08-12 12:39:23 +05:30
Prince Chaddha 9f4e720ba5
Merge pull request #4991 from projectdiscovery/log4j
Log4j
2022-08-10 09:56:15 -07:00
Prince Chaddha b67e15d02e
Update vmware-operation-manager-log4j.yaml 2022-08-10 09:41:22 -07:00
Prince Chaddha 1623e617b9
Update vmware-nsx-log4j.yaml 2022-08-10 09:41:02 -07:00
Prince Chaddha 39b7f16853
Update vmware-hcx-log4j.yaml 2022-08-10 09:40:49 -07:00
Prince Chaddha ea0315c4f2
Update rundeck-log4j.yaml 2022-08-10 09:40:35 -07:00
Prince Chaddha df1984890a
Update metabase-log4j.yaml 2022-08-10 09:40:16 -07:00
Prince Chaddha 2836673718
Update jamf-pro-log4j.yaml 2022-08-10 09:40:00 -07:00
Prince Chaddha 8a17b91ddd
Update graylog-log4j.yaml 2022-08-10 09:39:30 -07:00
Prince Chaddha 064b49d115
Update cisco-vmanage-log4j.yaml 2022-08-10 09:39:00 -07:00
Prince Chaddha 66c68c63a4
Update cisco-unified-communications-log4j.yaml 2022-08-10 09:38:46 -07:00
Prince Chaddha c7b77ae818
Update vmware-operation-manager-log4j.yaml 2022-08-10 09:37:38 -07:00
Prince Chaddha fadf1ba975
Merge pull request #5005 from projectdiscovery/wp-blogroll-fun-xss
Create wp-blogroll-fun-xss.yaml
2022-08-10 09:35:43 -07:00
Prince Chaddha 6899066085
Update wp-blogroll-fun-xss.yaml 2022-08-10 09:32:23 -07:00
Ritik Chaddha 98f75b6390
Update and rename vulnerabilities/wordpress/wp-church-admin-xss.yaml to cves/2015/CVE-2015-4127.yaml 2022-08-10 15:01:50 +05:30
Ritik Chaddha 0ba0e74aa1
Update wp-ambience-xss.yaml 2022-08-10 14:50:05 +05:30
Ritik Chaddha 0bbe2ff881
Update wordpress-zebra-form-xss.yaml 2022-08-10 14:48:17 +05:30
Ritik Chaddha 9f0b259e75
Update wordpress-social-metrics-tracker.yaml 2022-08-10 14:45:01 +05:30
Ritik Chaddha 37c98909c9
Update w3c-total-cache-ssrf.yaml 2022-08-10 14:43:01 +05:30
Ritik Chaddha 0ebe9f0b8f
Update sassy-social-share.yaml 2022-08-10 14:38:35 +05:30
Ritik Chaddha d817811a58
Update nativechurch-wp-theme-lfd.yaml 2022-08-10 14:36:49 +05:30
Ritik Chaddha 61f94b90d8
Update eatery-restaurant-open-redirect.yaml 2022-08-10 14:32:39 +05:30
Ritik Chaddha 62f10760af
Update brandfolder-open-redirect.yaml 2022-08-10 14:27:59 +05:30
Ritik Chaddha 33d108ee76
Update advanced-access-manager-lfi.yaml 2022-08-10 14:19:57 +05:30
Ritik Chaddha 4c9182c73e
Update ad-widget-lfi.yaml 2022-08-10 14:18:06 +05:30
Ritik Chaddha 88f642a48a
Update wp-woocommerce-email-verification.yaml 2022-08-10 14:00:37 +05:30
Ritik Chaddha 8377f56550
Update wp-woocommerce-file-download.yaml 2022-08-10 13:58:11 +05:30
Prince Chaddha 518d92e567
Rename vulnerabilities/wordpress/wp-install.yaml to exposed-panels/wordpress/wp-install.yaml 2022-08-09 14:39:07 -07:00
Prince Chaddha 19b9eae7fe
Merge pull request #5018 from scent2d/CVE-2020-8772
Create CVE-2020-8772.yaml
2022-08-09 12:18:44 -07:00
Prince Chaddha 5dff73aec8
Merge pull request #5059 from pikpikcu/patch-335
Added webp server LFI
2022-08-09 12:02:17 -07:00
Prince Chaddha 60406e102f
Merge pull request #5055 from arafatansari/patch-48
Create yeswiki-sql.yaml
2022-08-09 11:47:41 -07:00
Prince Chaddha c69d94c158
Update yeswiki-sql.yaml 2022-08-09 11:43:33 -07:00
Prince Chaddha 473dbce6e6
Update yeswiki-sql.yaml 2022-08-09 11:41:09 -07:00
Prince Chaddha 6acbc4ed00
Merge pull request #5054 from arafatansari/patch-47
Create yeswiki-xss2.yaml
2022-08-09 11:38:41 -07:00
Prince Chaddha 8cf741bc67
Update yeswiki-stored-xss.yaml 2022-08-09 11:36:59 -07:00
Ritik Chaddha 9cde49ec96
Update webp-server-go-lfi.yaml 2022-08-09 16:25:59 +05:30
PikPikcU 9328ba3ee4
Create webp-server-go-lfi.yaml 2022-08-09 06:15:24 -04:00
Prince Chaddha b3e8664e2c
Merge pull request #5053 from arafatansari/patch-46
Create yeswiki-xss.yaml
2022-08-09 02:50:21 -07:00
Prince Chaddha 9ec1e497b3
Update yeswiki-xss.yaml 2022-08-09 02:47:08 -07:00
Prince Chaddha 7129ad3f4a
Update generic-j2ee-lfi.yaml 2022-08-09 02:36:13 -07:00
Prince Chaddha ef71f15309
Merge pull request #5050 from pussycat0x/master
CVE-2019-10692
2022-08-09 02:20:37 -07:00
Prince Chaddha c03b7f8448
Merge pull request #5038 from davidfegyver/j2ee-generic-lfi
Added generic J2EE LFI scan
2022-08-09 02:12:01 -07:00
Prince Chaddha 9dc980ad64
Update generic-j2ee-lfi.yaml 2022-08-09 02:09:46 -07:00
Ritik Chaddha 0590cc3c23
Update and rename yeswiki-xss2.yaml to yeswiki-stored-xss.yaml 2022-08-09 12:57:50 +05:30
Ritik Chaddha ca6611c9cf
Update yeswiki-sql.yaml 2022-08-09 12:02:17 +05:30
Dhiyaneshwaran 5c8f9cfdcf
Update yeswiki-xss.yaml 2022-08-09 07:40:54 +05:30
Arafat Ansari c0374e5993
Create yeswiki-sql.yaml 2022-08-09 02:41:34 +05:30
Arafat Ansari 8ec7755930
Create yeswiki-xss2.yaml 2022-08-09 02:40:20 +05:30
Arafat Ansari 0af2f4de1c
Create yeswiki-xss.yaml 2022-08-09 02:38:54 +05:30
Prince Chaddha 02e7097db5
Merge pull request #5041 from projectdiscovery/liferay-resource-leak
Create liferay-resource-leak.yaml
2022-08-08 13:08:22 -07:00
Prince Chaddha a7d1ffbefd
Update and rename misconfiguration/liferay-resource-leak.yaml to vulnerabilities/j2ee/liferay-resource-leak.yaml 2022-08-08 13:05:34 -07:00
Prince Chaddha bfaf4f5b6d Merge branch 'master' of https://github.com/projectdiscovery/nuclei-templates into pr/4738 2022-08-08 11:28:46 -07:00
Ritik Chaddha 3ca2ec0945
Update CVE-2019-10692.yaml 2022-08-08 19:11:01 +05:30
Ritik Chaddha 3964e22f69
Update CVE-2019-10692.yaml 2022-08-08 19:08:44 +05:30
pussycat0x 383ed21913
Add files via upload 2022-08-08 18:36:30 +05:30
Ritik Chaddha 6106342ddf
Update generic-j2ee-lfi.yaml 2022-08-08 12:05:51 +05:30
Dhiyaneshwaran 6d7316db73
Update generic-j2ee-lfi.yaml 2022-08-07 20:50:32 +05:30
Dhiyaneshwaran d02893bba3
Update generic-j2ee-lfi.yaml 2022-08-07 20:47:49 +05:30
David Fegyver 8590b47416
Added generic J2EE LFI scan 2022-08-07 15:31:31 +02:00
Prince Chaddha 3950e8304c
Update wp-blogroll-fun-xss.yaml 2022-08-06 10:36:51 -07:00
Akincibor db12feeead Update Wordpress templates: typo, cve-id, ref & remove dupe 2022-08-06 19:19:49 +02:00
Akincibor db692605d4 Update Wordpress templates: typo, cve-id, ref & remove dupe 2022-08-06 18:54:58 +02:00
Ritik Chaddha 001868f981
Update inspur-clusterengine-v4-sysshell-rce.yaml 2022-08-06 22:11:58 +05:30
Prince Chaddha 9e4645961c
Delete wordpress-infinitewp-auth-bypass.yaml 2022-08-06 00:09:02 -07:00
MostInterestingBotInTheWorld b2e886f09b
Dashboard Content Enhancements (#5009)
Dashboard Content Enhancements
2022-08-05 09:57:51 -04:00
pussycat0x e9974fe5ad
Delete wp-revslider-release-log-detect.yaml 2022-08-05 18:46:53 +05:30
Prince Chaddha 708649c943
Merge pull request #5008 from projectdiscovery/omnia-mpx-lfi
Update omnia-mpx-lfi.yaml
2022-08-05 07:58:42 +04:00
Prince Chaddha 3ef2eea48f
Merge pull request #5004 from projectdiscovery/wp-avchat-3-xss
Create wp-avchat-3-xss.yaml
2022-08-05 07:57:58 +04:00
Prince Chaddha ae02b5bb2b
Update omnia-mpx-lfi.yaml 2022-08-05 07:57:03 +04:00
Prince Chaddha e2d0cfed57
Update and rename wp-avchat-3-xss.yaml to avchat-video-chat-xss.yaml 2022-08-05 07:54:15 +04:00
Prince Chaddha 5538c251dd
Update and rename wp-athlon-manage-calameo-publications-xss.yaml to calameo-publications-xss.yaml 2022-08-05 07:48:41 +04:00
Ritik Chaddha a73b7924f0
Update omnia-mpx-lfi.yaml 2022-08-04 23:53:04 +05:30
Ritik Chaddha 5d7f87b2ab Revert "Update omnia-mpx-lfi.yaml"
This reverts commit 03ae109555.
2022-08-04 23:52:03 +05:30
Ritik Chaddha 03ae109555
Update omnia-mpx-lfi.yaml 2022-08-04 23:47:18 +05:30
Dhiyaneshwaran 738df35bfc
Create wp-blogroll-fun-xss.yaml 2022-08-04 22:23:16 +05:30
Dhiyaneshwaran 9128955363
Delete wp-blogroll-fun-xss.yaml 2022-08-04 22:22:52 +05:30
Dhiyaneshwaran aa4bec9d62
Create wp-blogroll-fun-xss.yaml 2022-08-04 22:21:53 +05:30
Dhiyaneshwaran 404f1d56eb
Create wp-avchat-3-xss.yaml 2022-08-04 22:10:29 +05:30
Dhiyaneshwaran 94dcb8f006
Create wp-athlon-manage-calameo-publications-xss.yaml 2022-08-04 22:01:49 +05:30
Dhiyaneshwaran 4bc8d0fa91
Delete wp-athlon-manage-calameo-publications-xss.yaml 2022-08-04 22:01:14 +05:30
Dhiyaneshwaran a02733dcbc
Create wp-athlon-manage-calameo-publications-xss.yaml 2022-08-04 21:55:50 +05:30
Prince Chaddha 3c7f0847aa
Merge pull request #4913 from Akokonunes/patch-170
Create crystal-live-http-server-lfi.yaml
2022-08-04 20:27:25 +05:30
Prince Chaddha eee45f4897
Update and rename crystal-live-http-server-lfi.yaml to crystal-live-server-lfi.yaml 2022-08-04 18:55:57 +04:00
Prince Chaddha 64f3b3aac5
Merge pull request #4992 from projectdiscovery/microweber-stored-xss
Delete microweber-stored-xss.yaml
2022-08-04 19:52:29 +05:30
Prince Chaddha 53a2f6b0f9
Merge pull request #4979 from arafatansari/patch-37
Create mpx-lfi.yaml
2022-08-03 19:03:32 +05:30
Prince Chaddha fe631c7d8b
Merge pull request #4982 from projectdiscovery/solarview-compact-xss
Create solarview-compact-xss.yaml
2022-08-03 19:03:21 +05:30
Dhiyaneshwaran b548f03918
Create vmware-operation-manager-log4j.yaml 2022-08-03 18:47:13 +05:30
Dhiyaneshwaran 6d8a1762da
Create vmware-nsx-log4j.yaml 2022-08-03 18:46:40 +05:30
Dhiyaneshwaran b91aa0fb7c
Create vmware-hcx-log4j.yaml 2022-08-03 18:46:12 +05:30
Dhiyaneshwaran 2e17f180a9
Create rundeck-log4j.yaml 2022-08-03 18:45:34 +05:30
Dhiyaneshwaran 8c3f59485a
Create metabase-log4j.yaml 2022-08-03 18:44:49 +05:30
Dhiyaneshwaran cdde4d5053
Create jamf-pro-log4j.yaml 2022-08-03 18:44:10 +05:30
Dhiyaneshwaran 111e9319f1
Create graylog-log4j.yaml 2022-08-03 18:43:22 +05:30
Dhiyaneshwaran ad5c44ee6a
Create cisco-vmanage-log4j.yaml 2022-08-03 18:42:29 +05:30
Ritik Chaddha 82a0ff9b0b
Delete microweber-stored-xss.yaml 2022-08-03 18:42:24 +05:30
Dhiyaneshwaran 21340d3862
Create cisco-unified-communications-log4j.yaml 2022-08-03 18:40:21 +05:30
Prince Chaddha 78e60a784f
Rename vulnerabilities/other/royalevent/royalevent-stored-xss.yaml to vulnerabilities/royalevent/royalevent-stored-xss.yaml 2022-08-03 18:35:05 +05:30
Prince Chaddha cfeb72ac56
Rename vulnerabilities/other/royalevent/royalevent-management-xss.yaml to vulnerabilities/royalevent/royalevent-management-xss.yaml 2022-08-03 18:34:58 +05:30
Ritik Chaddha 2253fdcdab
Create solarview-compact-xss.yaml 2022-08-02 20:47:11 +05:30
Ritik Chaddha 3a75420965
Update and rename mpx-lfi.yaml to omnia-mpx-lfi.yaml 2022-08-02 18:31:57 +05:30
Arafat Ansari b74d093f74
Create mpx-lfi.yaml 2022-08-02 18:19:05 +05:30
Dhiyaneshwaran cacc097e08
Update crystal-live-http-server-lfi.yaml 2022-08-02 15:51:33 +05:30
Dhiyaneshwaran a7ffb8182b
Update crystal-live-http-server-lfi.yaml 2022-08-02 15:49:21 +05:30
Dhiyaneshwaran c729e73abe
Update and rename crystal-live-http-server-lfi.yaml to vulnerabilities/other/crystal-live-http-server-lfi.yaml 2022-08-02 15:40:20 +05:30
Dhiyaneshwaran b103fb9ef0
Update wp-revslider-release-log-detect.yaml 2022-08-02 15:00:54 +05:30
Dhiyaneshwaran 0963069a3c
Update and rename wp-revslider-release_log-detect.yaml to wp-revslider-release-log-detect.yaml 2022-08-02 14:47:17 +05:30
pussycat0x 76a55fc884
Add files via upload 2022-08-02 11:48:19 +05:30
Prince Chaddha 4a37bf0a2d
Merge pull request #4881 from arafatansari/patch-19
Create ems-sqli.yaml
2022-08-01 11:13:23 +05:30
Prince Chaddha 4c51fe5c08
Update carrental-xss.yaml 2022-08-01 10:51:34 +05:30
Dhiyaneshwaran 0f182e5102
Update carrental-xss.yaml 2022-08-01 05:40:27 +05:30
Arafat Ansari 4397a352f8
Create carrental-xss.yaml 2022-08-01 02:39:55 +05:30
Prince Chaddha f5b3587750
Merge pull request #4917 from amit-jd/amit-patch-7
Create stored-xss-mwb
2022-07-31 10:02:34 +05:30
Prince Chaddha 8d4a74484c
Rename stored-xss-mwb.yaml to microweber-stored-xss.yaml 2022-07-30 14:02:12 +05:30
Prince Chaddha 3916a596b5
Merge pull request #4890 from projectdiscovery/goanywhere-log4j-rce
Added goanywhere-log4j-rce
2022-07-30 13:58:47 +05:30
Ritik Chaddha b78a6b9a85
Update ems-sqli.yaml 2022-07-30 12:16:47 +05:30
Prince Chaddha 92e61df0e6
Update goanywhere-mft-log4j-rce.yaml 2022-07-30 11:05:23 +05:30
MostInterestingBotInTheWorld 8c3ab6c654
Dashboard Content Enhancements (#4943)
Dashboard Content Enhancements
2022-07-29 10:04:23 -04:00
Ritik Chaddha 06adbe6447 Update springboot-actuators-jolokia-xxe.yaml 2022-07-28 14:05:26 +05:30
MostInterestingBotInTheWorld 690da7dd94
Dashboard Content Enhancements (#4927)
Dashboard Content Enhancements
2022-07-27 16:17:31 -04:00
Ritik Chaddha efcd51e82c
Create analytify-plugin-xss.yaml 2022-07-27 16:46:12 +05:30
Ritik Chaddha c28e6fa3ea
Update and rename goanywhere-log4j-rce.yaml to goanywhere-mft-log4j-rce.yaml 2022-07-27 14:21:59 +05:30
Ritik Chaddha a9afe92229
Update stored-xss-mwb.yaml 2022-07-27 13:18:58 +05:30
Ritik Chaddha 4fc4fa5050
Update stored-xss-mwb.yaml 2022-07-27 13:16:49 +05:30
amit-jd 66ad97de7c
Update stored-xss-mwb.yaml 2022-07-27 13:01:23 +05:30
amit-jd 38278e0211
Update stored-xss-mwb.yaml 2022-07-27 12:59:11 +05:30
amit-jd 38eba0637e
Update stored-xss-mwb.yaml 2022-07-27 12:09:06 +05:30
amit-jd 711bad8a91
Update stored-xss-mwb.yaml 2022-07-27 11:50:07 +05:30
MostInterestingBotInTheWorld c5a7d79f5a
Dashboard Content Enhancements (#4819)
Dashboard Content Enhancements
2022-07-26 09:45:11 -04:00
amit-jd 4968037238
Create stored-xss-mwb 2022-07-26 19:00:38 +05:30
PikPikcU 731c02429a
Create weiphp-sql-injection (#941)
* Create weiphp-sql-injection.yaml

* Update weiphp-sql-injection.yaml

* Update weiphp-sql-injection.yaml

Co-authored-by: Ritik Chaddha <44563978+ritikchaddha@users.noreply.github.com>
2022-07-26 17:28:08 +05:30
Prince Chaddha f94c44a51a
Merge pull request #3263 from projectdiscovery/jexboss-backdoor
Added Jexboss Backdoor Webshell
2022-07-26 12:46:15 +05:30
Prince Chaddha 6a24e37b31
Update jexboss-backdoor.yaml 2022-07-26 12:29:48 +05:30
Prince Chaddha d07b944d90
Merge pull request #4882 from arafatansari/patch-20
Create cvms-sqli.yaml
2022-07-26 10:43:07 +05:30
Prince Chaddha 6c8e1772fa
Update cvms-sqli.yaml 2022-07-26 10:19:24 +05:30
Prince Chaddha 3ef173ca7f
Update zms-sqli.yaml 2022-07-26 10:16:30 +05:30
Ritik Chaddha d73f42e715
Update zms-sqli.yaml 2022-07-26 10:05:07 +05:30
Ritik Chaddha e4e2f4cf00
Update zms-sqli.yaml 2022-07-25 23:55:18 +05:30
Arafat Ansari f5295fa474
Update zms-sqli.yaml 2022-07-25 23:50:46 +05:30
Arafat Ansari 2e6ea14451
Create zms-sqli.yaml 2022-07-25 23:47:14 +05:30
Ritik Chaddha 0831a9d488
Update cvms-sqli.yaml 2022-07-25 23:41:06 +05:30
Ritik Chaddha 43c389c42a
Update cvms-sqli.yaml 2022-07-25 23:39:57 +05:30
Prince Chaddha f0b5e19833
Merge pull request #4163 from ritikchaddha/patch-34
Create zzcms-xss.yaml
2022-07-24 21:26:23 +05:30
Prince Chaddha ac96218aae
Update zzcms-xss.yaml 2022-07-24 21:16:05 +05:30
Ritik Chaddha 8c6cc9b9eb
Update zzcms-xss.yaml 2022-07-24 19:13:49 +05:30
sandeep 7379d35162 addition signup path + template fix 2022-07-23 18:37:43 +05:30
Ritik Chaddha 9d8af2ac47
Update goanywhere-log4j-rce.yaml 2022-07-22 23:41:57 +05:30
Prince Chaddha 53ca3cf256
Merge pull request #4870 from arafatansari/patch-16
Create loancms-sqli.yaml
2022-07-22 12:40:16 +05:30
Ritik Chaddha e79fa7e245
Update loancms-sqli.yaml 2022-07-22 12:15:21 +05:30
sandeep 1ea058b576 added goanywhere-log4j-rce 2022-07-22 07:12:43 +05:30
Ritik Chaddha 42470ac90c
Update loancms-sqli.yaml 2022-07-21 16:36:05 +05:30
Prince Chaddha de5b654312
Merge pull request #4883 from arafatansari/patch-21
Create alumni-sqli.yaml
2022-07-21 16:29:38 +05:30
Prince Chaddha daf917a751
Update alumni-management-sqli.yaml 2022-07-21 16:20:17 +05:30
Ritik Chaddha 268a9f0a39
Update and rename alumni-sqli.yaml to alumni-management-sqli.yaml 2022-07-21 16:17:53 +05:30
Prince Chaddha 3035ea903c
Merge pull request #4868 from arafatansari/patch-15
Create devalcms-xss.yaml
2022-07-21 15:20:18 +05:30
Prince Chaddha 47c8fdd8fc
Update loancms-sqli.yaml 2022-07-21 15:17:40 +05:30
Prince Chaddha b4be125f85
Merge pull request #4872 from arafatansari/patch-17
Create onlinecms-xss.yaml
2022-07-21 15:10:36 +05:30
Prince Chaddha 04a0949573
Update and rename onlinecms-xss.yaml to onlinefarm-management-xss.yaml 2022-07-21 15:06:42 +05:30
Prince Chaddha 66786b8aaa
Merge pull request #4874 from arafatansari/patch-18
Create surrealtodo-lfi.yaml
2022-07-21 14:17:03 +05:30
Ritik Chaddha 77ab5e2cbd
Update dedecms-rce.yaml 2022-07-21 14:02:18 +05:30
Ritik Chaddha 8823370bdf
Create dedecms-rce.yaml 2022-07-21 13:52:11 +05:30
Prince Chaddha 5baf2a4bf2
Update and rename opencti-lfi.yaml to vulnerabilities/other/opencti-lfi.yaml 2022-07-21 13:18:27 +05:30
Arafat Ansari 467d8ecc6a
Create alumni-sqli.yaml 2022-07-21 13:16:42 +05:30
Arafat Ansari 91f907e3b1
Create cvms-sqli.yaml 2022-07-21 12:57:46 +05:30
Arafat Ansari 2fd7baf1bf
Create ems-sqli.yaml 2022-07-21 12:39:06 +05:30
Ritik Chaddha 9e829668a4
Update onlinecms-xss.yaml 2022-07-20 23:52:19 +05:30
Arafat Ansari acc357f591
Update onlinecms-xss.yaml 2022-07-20 23:43:48 +05:30
Ritik Chaddha d88160b8d5
Update surrealtodo-lfi.yaml 2022-07-20 23:21:03 +05:30
Ritik Chaddha 14e430b3df
Update surrealtodo-lfi.yaml 2022-07-20 23:20:37 +05:30
Arafat Ansari 9f28a9c8e3
Create surrealtodo-lfi.yaml 2022-07-20 23:14:17 +05:30
Arafat Ansari ef1a1f0f44
Create onlinecms-xss.yaml 2022-07-20 22:14:07 +05:30
Ritik Chaddha bd0c9a9163
Update loancms-sqli.yaml 2022-07-20 18:11:03 +05:30
Ritik Chaddha 8bca76cf6d
Update loancms-sqli.yaml 2022-07-20 18:08:25 +05:30
Arafat Ansari 2d71d7a288
Create loancms-sqli.yaml 2022-07-20 16:37:42 +05:30
Ritik Chaddha 4b6aa7df81
Update devalcms-xss.yaml 2022-07-20 14:42:25 +05:30
Arafat Ansari 289f1731bb
Update devalcms-xss.yaml 2022-07-20 14:37:43 +05:30
Arafat Ansari 0f209ca08c
Update devalcms-xss.yaml 2022-07-20 14:31:44 +05:30
Arafat Ansari 9304c58b2c
Create devalcms-xss.yaml 2022-07-20 14:26:54 +05:30
Prince Chaddha 8279d7b4e7
Merge pull request #4854 from arafatansari/patch-14
Create eris-xss.yaml
2022-07-19 14:58:37 +05:30
Ritik Chaddha cba12fe78d
Update eris-xss.yaml 2022-07-19 14:25:14 +05:30
Arafat Ansari 920ee7ea97
Update eris-xss.yaml 2022-07-18 21:59:07 +05:30
Prince Chaddha b7b317dc02
Merge pull request #4461 from gy741/rule-add-v113
Create cisco-rv-series-rce.yaml
2022-07-18 20:52:16 +05:30
Prince Chaddha 099e9ede6e
Update cisco-rv-series-rce.yaml 2022-07-18 20:49:58 +05:30
Arafat Ansari d004cb9b65
Create eris-xss.yaml 2022-07-18 18:14:09 +05:30
Prince Chaddha 38b1247fcf
Update cisco-rv-series-rce.yaml 2022-07-18 15:22:26 +05:30
Prince Chaddha 279a418e17
Merge pull request #4836 from gy741/v119
Create carel-bacnet-gateway-directory-traversal.yaml
2022-07-18 14:15:54 +05:30
Prince Chaddha 1318dbbae8
Update and rename carel-bacnet-gateway-directory-traversal.yaml to carel-bacnet-gateway-traversal.yaml 2022-07-18 13:47:02 +05:30
Prince Chaddha 22e47c889b
Merge pull request #4847 from ritikchaddha/Update-metadata-query
Log4j templates enhancement
2022-07-18 12:15:49 +05:30
Ritik Chaddha 08bf44add6 Update apache-ofbiz-log4j-rce.yaml 2022-07-18 12:04:47 +05:30
Ritik Chaddha 4a6ef1b3b0 Update apache-solr-log4j-rce.yaml 2022-07-18 12:04:43 +05:30
Ritik Chaddha 73c9a981ac Update jamf-log4j-jndi-rce.yaml 2022-07-18 12:04:40 +05:30
Ritik Chaddha 6f6eb47953 Update mobileiron-log4j-jndi-rce.yaml 2022-07-18 12:04:37 +05:30
Ritik Chaddha a1409f1f2a Update unifi-network-log4j-rce.yaml 2022-07-18 12:04:32 +05:30
Ritik Chaddha 3b2e9d617b Update vmware-horizon-log4j-jndi-rce.yaml 2022-07-18 12:04:27 +05:30
Ritik Chaddha d516bf58d9 Update vmware-vcenter-log4j-jndi-rce.yaml 2022-07-18 12:04:24 +05:30
Ritik Chaddha 5f24480409 Update vrealize-operations-log4j-rce.yaml 2022-07-18 12:04:22 +05:30
Prince Chaddha 851c7ef71d
Update mobileiron-log4j-jndi-rce.yaml 2022-07-17 09:23:02 +05:30
Ritik Chaddha 633c7ccbee Update apache-ofbiz-log4j-rce.yaml 2022-07-16 22:38:08 +05:30
Ritik Chaddha a312af919a Update apache-solr-log4j-rce.yaml 2022-07-16 22:38:06 +05:30
Ritik Chaddha e065e78756 Update code42-log4j-rce.yaml 2022-07-16 22:38:04 +05:30
Ritik Chaddha f0ef7c981b Update jamf-log4j-jndi-rce.yaml 2022-07-16 22:38:02 +05:30
Ritik Chaddha aa631b6a04 Update mobileiron-log4j-jndi-rce.yaml 2022-07-16 22:37:18 +05:30
Ritik Chaddha 928abe95cc Update unifi-network-log4j-rce.yaml 2022-07-16 22:37:16 +05:30
Ritik Chaddha ab67da1487 Update springboot-log4j-rce.yaml 2022-07-16 22:37:13 +05:30
Ritik Chaddha b5818db94c Update vmware-horizon-log4j-jndi-rce.yaml 2022-07-16 22:35:40 +05:30
Ritik Chaddha 4add304837 Update vmware-vcenter-log4j-jndi-rce.yaml 2022-07-16 22:35:37 +05:30
Ritik Chaddha 10ad3459b6 Update vrealize-operations-log4j-rce.yaml 2022-07-16 22:35:27 +05:30
Prince Chaddha c7b482532d
Update elasticsearch5-log4j-rce.yaml 2022-07-16 18:04:04 +05:30
Ritik Chaddha 236912a8fa
Create elasticsearch5-log4j-rce.yaml 2022-07-16 12:21:07 +05:30
GwanYeong Kim 549c969d5f Create carel-bacnet-gateway-directory-traversal.yaml
The device suffers from an unauthenticated arbitrary file disclosure vulnerability. Input passed through the 'file' GET parameter through the 'logdownload.cgi' Bash script is not properly verified before being used to download log files. This can be exploited to disclose the contents of arbitrary and sensitive files via directory traversal attacks.

Signed-off-by: GwanYeong Kim <gy741.kim@gmail.com>
2022-07-16 10:59:44 +09:00