Sandeep Singh
55e21f68f7
Merge pull request #3089 from Leovalcante/fix-cve-2018-2791
...
improve cve-2018-2791 vulnerability check
2021-11-06 13:43:34 +05:30
sandeep
c474434ab2
improved matchers
2021-11-06 13:17:42 +05:30
sandeep
2b38dce99c
updated with improved matchers
2021-11-06 12:51:30 +05:30
Valerio Preti
fe5385e932
create check for cve-2018-3238
2021-11-06 00:51:54 +01:00
Valerio Preti
69fc4c04c2
improve wcs cve-2018-2791 vulnerability check
2021-11-06 00:48:10 +01:00
Huy Nguyen
78189af295
Fix for potential false positives
...
See also following issue: https://github.com/projectdiscovery/nuclei-templates/issues/3065
2021-11-04 12:07:38 +01:00
GitHub Action
e70531ebca
Auto Generated CVE annotations [Wed Nov 3 06:21:45 UTC 2021] 🤖
2021-11-03 06:21:45 +00:00
Prince Chaddha
fd9e89e0db
Create CVE-2018-18570.yaml
2021-11-03 11:36:30 +05:30
forgedhallpass
5c3bbbb740
Update SSH user enum templates
...
SSH header structure:
SSH-protoversion-softwareversion[SPcomments]CRLF
see: https://datatracker.ietf.org/doc/html/rfc4253#section-4.2
2021-11-01 20:34:47 +02:00
sandeep
107679bd9a
matcher + added version extractors
2021-10-30 19:26:12 +05:30
sandeep
8c3f98c767
fixed invalid template syntax
2021-10-30 16:47:35 +05:30
Noam Rathaus
376c63189d
Add description
2021-10-27 14:07:22 +03:00
sandeep
33badb66d1
oob tags update
2021-10-19 02:10:26 +05:30
GitHub Action
d2d4d01846
Auto Generated CVE annotations [Mon Oct 18 15:19:41 UTC 2021] 🤖
2021-10-18 15:19:41 +00:00
Prince Chaddha
09d4e1ea28
Merge pull request #2912 from wisnupramoedya/patch-2
...
Create CVE-2018-10823.yaml
2021-10-18 20:48:20 +05:30
Prince Chaddha
1753507a39
Merge pull request #2911 from wisnupramoedya/patch-1
...
Create CVE-2018-10093.yaml
2021-10-18 20:47:51 +05:30
GitHub Action
0762d645fb
Auto Generated CVE annotations [Mon Oct 18 15:16:57 UTC 2021] 🤖
2021-10-18 15:16:57 +00:00
Prince Chaddha
868264f839
Update CVE-2018-10823.yaml
2021-10-18 20:46:01 +05:30
Prince Chaddha
9f30aa203b
Merge pull request #2913 from wisnupramoedya/patch-3
...
Create CVE-2018-13980.yaml
2021-10-18 20:45:06 +05:30
GitHub Action
79656346cd
Auto Generated CVE annotations [Mon Oct 18 15:14:58 UTC 2021] 🤖
2021-10-18 15:14:58 +00:00
Wisnu Pramoedya
cf1b818d5b
Create CVE-2018-12054.yaml
2021-10-18 20:04:38 +07:00
Wisnu Pramoedya
89f9d65d7d
Create CVE-2018-13980.yaml
2021-10-18 20:00:57 +07:00
Wisnu Pramoedya
7d007d29f0
Create CVE-2018-10823.yaml
2021-10-18 19:56:22 +07:00
Wisnu Pramoedya
98d8a15123
Create CVE-2018-10093.yaml
2021-10-18 19:44:09 +07:00
Noam Rathaus
452b4c10ea
Merge branch 'master' of https://github.com/projectdiscovery/nuclei-templates
2021-10-12 15:45:23 +03:00
GitHub Action
d7cd9a21de
Auto Generated CVE annotations [Mon Oct 11 11:27:30 UTC 2021] 🤖
2021-10-11 11:27:30 +00:00
Prince Chaddha
b9a2afe546
Update CVE-2018-9205.yaml
2021-10-11 16:53:15 +05:30
Muhammad Daffa
55caa61c96
Create CVE-2018-9205.yaml
2021-10-11 18:22:14 +07:00
Noam Rathaus
59a6cef7fb
Missing 'a'
2021-10-10 16:07:15 +03:00
sandeep
8f58d37f3a
Added missing condition
2021-10-05 23:42:16 +05:30
GitHub Action
fa947061ee
Auto Generated CVE annotations [Fri Oct 1 23:05:32 UTC 2021] 🤖
2021-10-01 23:05:32 +00:00
sandeep
2f99b4165a
misc update
2021-10-02 04:33:14 +05:30
Jackson Rolf
2b477061e8
Added CVE-2018-0127 template.
2021-10-01 15:30:31 -04:00
TheConciergeDev
6011701507
renamed file
...
the second dash was a unicode value -> "\u2013" instead
2021-09-29 11:18:09 +02:00
sandeep
cd37224212
Update CVE-2018–9845.yaml
2021-09-24 15:44:02 +05:30
Prince Chaddha
6cb56d3b77
Update CVE-2018–9845.yaml
2021-09-24 15:05:45 +05:30
Prince Chaddha
0614a6031c
Update CVE-2018–9845.yaml
2021-09-24 15:05:21 +05:30
Philippe Delteil
1f679d8b4e
Create CVE-2018–9845.yaml
2021-09-23 23:18:41 -03:00
GitHub Action
77215862c9
Auto Generated CVE annotations [Wed Sep 22 10:21:33 UTC 2021] 🤖
2021-09-22 10:21:33 +00:00
sandeep
a98e8defc2
misc update
2021-09-21 16:22:53 +05:30
sandeep
8fa18933e9
id update
2021-09-21 16:20:24 +05:30
sandeep
1c613882f8
Added missing cve tags
2021-09-21 16:17:16 +05:30
sandeep
7b23f4ebd4
outdated template cleanups
2021-09-21 14:34:20 +05:30
GitHub Action
fdc98d1405
Auto Generated CVE annotations [Thu Sep 16 17:39:06 UTC 2021] 🤖
2021-09-16 17:39:06 +00:00
Prince Chaddha
631005ebaa
Update CVE-2018-12998.yaml
2021-09-16 23:03:45 +05:30
PikPikcU
3a2eacf6b9
Update CVE-2018-12998.yaml
2021-09-15 11:31:34 +07:00
PikPikcU
85c32c4cd2
Create CVE-2018-12998.yaml
2021-09-15 11:00:16 +07:00
sandeep
e831dd4fe0
lint error fix
2021-09-12 20:45:49 +05:30
sandeep
35e8c3c1cf
Added complete poc
2021-09-12 19:50:30 +05:30
Ice3man543
e9f728c321
Added cve annotations + severity adjustments
2021-09-10 16:56:40 +05:30
Prince Chaddha
13ec24c2e3
Update CVE-2018-15535.yaml
2021-09-10 12:01:01 +05:30
Muhammad Daffa
02e6ccfd7e
Create CVE-2018-15535.yaml
2021-09-09 19:48:08 +07:00
sandeep
609705f676
removed extra headers not required for template
2021-09-08 17:47:19 +05:30
Sandeep Singh
0880b65284
Rename CVE-2018–14064.yaml to CVE-2018-14064.yaml
2021-09-08 13:11:41 +05:30
Prince Chaddha
ef6350bfcc
Update and rename CVE-2018–14064.yaml to cves/2018/CVE-2018–14064.yaml
2021-09-07 18:14:38 +05:30
Prince Chaddha
960a568ef8
Merge pull request #2500 from LogicalHunter/temp-4
...
Added CVE-2018-8719.yaml Template
2021-08-31 16:30:09 +05:30
Prince Chaddha
64b25c359b
Update CVE-2018-8719.yaml
2021-08-31 12:07:28 +05:30
Noam Rathaus
5b344c944c
Updated
2021-08-30 12:50:56 +03:00
Prince Chaddha
02b429fe89
Update CVE-2018-8719.yaml
2021-08-29 17:56:50 +05:30
sandeep
ac68ef0e9a
misc updates
2021-08-29 14:44:12 +05:30
Noam Rathaus
5e27e5d528
Add description
2021-08-29 09:42:18 +03:00
Noam Rathaus
3a1f7e0910
Remove |
2021-08-29 09:36:50 +03:00
Noam Rathaus
5b0a50d514
Add description and references
2021-08-29 09:24:41 +03:00
Noam Rathaus
9f9970c8e9
Merge branch 'master' of https://github.com/projectdiscovery/nuclei-templates
2021-08-29 09:15:40 +03:00
LogicalHunter
40371e83cc
Added CVE-2018-8719.yaml Template
2021-08-27 11:40:18 -07:00
forgedhallpass
419a957409
Fixing errors in templates
...
Related nuclei tickets:
* #259 - dynamic key-value field support for template information
* #940 - new infos in template
* #834
* RES-84
2021-08-27 10:43:24 +03:00
forgedhallpass
a4250b8f2f
Merge remote-tracking branch 'origin' into dynamic_attributes
2021-08-26 15:04:14 +03:00
Prince Chaddha
972ba7f4c2
Update CVE-2018-12095.yaml
2021-08-25 16:55:53 +05:30
Borna Nematzadeh
2a3b20de2c
Update CVE-2018-12095.yaml
2021-08-24 12:27:07 -07:00
LogicalHunter
60e2816815
Added CVE-2018-12095.yaml Template
2021-08-24 10:29:51 -07:00
forgedhallpass
296edfc37b
Merge remote-tracking branch 'origin' into dynamic_attributes
2021-08-23 14:40:33 +03:00
Sandeep Singh
04b401a8ef
Merge pull request #2456 from projectdiscovery/payloads-update
...
Payloads positional update to keep the request format uniform
2021-08-23 15:26:35 +05:30
sandeep
1a34341c1e
Update CVE-2018-6008.yaml
2021-08-23 15:20:53 +05:30
Muhammad Daffa
906d9fd5af
Create CVE-2018-6008.yaml
2021-08-23 07:03:54 +07:00
sandeep
2aa54304ee
Payloads positional update to keep the request format uniform
2021-08-22 23:39:33 +05:30
Prince Chaddha
9cc8cd3353
Update CVE-2018-15473.yaml
2021-08-21 18:52:00 +05:30
Muhammad Daffa
1447a6d3d4
Update and rename network/openssh-username-enumeration.yaml to cves/2018/CVE-2018-15473.yaml
2021-08-21 18:55:11 +07:00
forgedhallpass
77103bc629
Satisfying the linter (all errors and warnings)
...
* whitespace modifications only
2021-08-19 17:44:46 +03:00
forgedhallpass
f55d6b75e1
Removed pipe (|) character from references, because the structure requires it to be a string slice, not a string
...
Related nuclei tickets:
* #259 - dynamic key-value field support for template information
* #940 - new infos in template
* #834
* RES-84
2021-08-19 16:59:12 +03:00
forgedhallpass
7b29be739e
Merge branch 'master' into dynamic_attributes
2021-08-19 16:23:26 +03:00
forgedhallpass
ffaff64565
Changes fixes/around dynamic attributes ("additional-fields")
...
Related nuclei tickets:
* #259 - dynamic key-value field support for template information
* #940 - new infos in template
* #834
* RES-84
2021-08-19 16:17:27 +03:00
forgedhallpass
0b432b341b
Added comments with URLs under the "references" field
...
Related nuclei tickets:
* #259 - dynamic key-value field support for template information
* #940 - new infos in template
* #834
* RES-84
2021-08-19 16:15:35 +03:00
forgedhallpass
e68d15ab63
Fixed mistakes/typos in the templates.
...
Related nuclei tickets:
* #259 - dynamic key-value field support for template information
* #940 - new infos in template
* #834
* RES-84
2021-08-19 15:30:14 +03:00
forgedhallpass
cdf9451158
Removed pipe (|) character from references, because the structure requires it to be a string slice, not a string
...
Related nuclei tickets:
* #259 - dynamic key-value field support for template information
* #940 - new infos in template
* #834
* RES-84
2021-08-18 14:44:27 +03:00
Muhammad Daffa
76e6fbcf8e
Create CVE-2018-16288.yaml
2021-08-12 09:41:00 +07:00
GwanYeong Kim
19517e8855
Create CVE-2018-16167.yaml
...
LogonTracer 1.2.0 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.
Signed-off-by: GwanYeong Kim <gy741.kim@gmail.com>
2021-08-10 14:30:22 +09:00
Noam Rathaus
14d2dcd26b
reference
2021-08-09 16:35:43 +03:00
Prince Chaddha
0b3a307294
Update CVE-2018-15517.yaml
2021-08-04 13:44:42 +05:30
Prince Chaddha
8cc213cec1
Update CVE-2018-15745.yaml
2021-08-04 13:42:14 +05:30
GwanYeong Kim
812d4faca2
Create CVE-2018-15517.yaml
...
Using a web browser or script SSRF can be initiated against internal/external systems to conduct port scans by leveraging D LINKs MailConnect component. The MailConnect feature on D-Link Central WiFiManager CWM-100 1.03 r0098 devices is intended to check a connection to an SMTP server but actually allows outbound TCP to any port on any IP address, leading to SSRF, as demonstrated by an index.php/System/MailConnect/host/127.0.0.1/port/22/secure/ URI. This can undermine accountability of where scan or connections actually came from and or bypass the FW etc. This can be automated via script or using Web Browser.
Signed-off-by: GwanYeong Kim <gy741.kim@gmail.com>
2021-08-04 14:25:54 +09:00
GwanYeong Kim
adce7d2c39
Create CVE-2018-15745.yaml
...
Argus Surveillance DVR 4.0.0.0 devices allow Unauthenticated Directory Traversal, leading to File Disclosure via a ..%2F in the WEBACCOUNT.CGI RESULTPAGE parameter.
Signed-off-by: GwanYeong Kim <gy741.kim@gmail.com>
2021-08-04 14:16:24 +09:00
Prince Chaddha
41b06a2ed7
Merge pull request #2216 from pikpikcu/patch-223
...
Add Zimbra XSS
2021-08-03 13:22:42 +05:30
Prince Chaddha
c4acd62307
Update CVE-2018-14013.yaml
2021-08-03 13:13:57 +05:30
Prince Chaddha
1c83792023
Merge pull request #2314 from daffainfo/patch-126
...
Create CVE-2018-20470.yaml
2021-08-03 13:08:36 +05:30
Muhammad Daffa
6e13d833ef
Create CVE-2018-19458.yaml
2021-08-03 06:20:58 +07:00
Muhammad Daffa
02d3258f2a
Create CVE-2018-20470.yaml
2021-08-03 06:19:42 +07:00
Prince Chaddha
1939842ab6
Merge pull request #2219 from pikpikcu/patch-225
...
Add Dolibarr xss
2021-08-02 22:32:24 +05:30
Prince Chaddha
f924e58b8e
Update CVE-2018-10095.yaml
2021-08-02 22:31:01 +05:30
Prince Chaddha
dca1dd56b1
Merge pull request #2220 from pikpikcu/patch-226
...
Add Grav CMS XSS
2021-08-02 22:26:37 +05:30
Prince Chaddha
e359b030f2
Update CVE-2018-5233.yaml
2021-08-02 22:25:21 +05:30