Commit Graph

1422 Commits (f874188740a39ca5ba0ecd3bcd6c72aa1d50ac01)

Author SHA1 Message Date
J4vaovo 88e4a6e227
Update tomcat-default-login.yaml 2023-07-14 08:57:11 +08:00
E1A b5947d069f
CVE-2017-7925.yaml (#7687)
* CVE-2017-7925.yaml

Research done and updated template after issue: https://github.com/projectdiscovery/nuclei-templates/issues/5639

* Update CVE-2017-7925.yaml

* Update CVE-2017-7925.yaml

* improved matcher + metadata + extractor

* removing duplicate template

---------

Co-authored-by: sandeep <8293321+ehsandeep@users.noreply.github.com>
2023-07-14 03:26:00 +05:30
Ritik Chaddha 83af9b34d9
Update graylog-endpoints-exposure.yaml 2023-07-13 16:22:58 +05:30
Ritik Chaddha 33f675599e
Delete graylog-api-browser.yaml 2023-07-13 14:37:32 +05:30
Ritik Chaddha 20b2b337d0
Rename technologies/graylog/graylog-api-browser.yaml to http/technologies/graylog/graylog-api-browser.yaml 2023-07-13 14:06:39 +05:30
Ritik Chaddha 86392e1698
Rename technologies/graylog/graylog-endpoints-exposure.yaml to http/technologies/graylog/graylog-endpoints-exposure.yaml 2023-07-13 14:06:11 +05:30
Dhiyaneshwaran a082d33481
typo 2023-07-13 13:39:02 +05:30
Dhiyaneshwaran c77ec55fbb
added possible user enum endpoints 2023-07-13 13:37:51 +05:30
Ritik Chaddha e47db87042
Update CVE-2023-37270.yaml 2023-07-13 13:27:33 +05:30
Ritik Chaddha 92675d0756
Update CVE-2023-37270.yaml 2023-07-13 13:24:44 +05:30
pussycat0x b5789d2c1a
Merge pull request #7673 from projectdiscovery/CVE-2023-37270
Create CVE-2023-37270.yaml
2023-07-13 13:15:41 +05:30
pussycat0x 414b21ffb2
dsl matchers - update 2023-07-13 13:12:01 +05:30
pussycat0x 2b03e2782d
Update CVE-2023-37270.yaml 2023-07-13 13:01:44 +05:30
Ritik Chaddha b4b1c6ded0
Update CVE-2023-37270.yaml 2023-07-13 12:57:00 +05:30
pussycat0x 32ff78d0bc
minor -changes 2023-07-13 12:48:08 +05:30
GitHub Action c14d8deeab TemplateMan Update [Thu Jul 13 05:59:21 UTC 2023] 🤖 2023-07-13 05:59:21 +00:00
Dhiyaneshwaran c60aa8f6d8
Merge pull request #7648 from j4vaovo/patch-3
Update sitemap-sql-injection.yaml
2023-07-13 11:27:14 +05:30
J4vaovo 94f55f8141
Update sitemap-sql-injection.yaml 2023-07-13 13:53:05 +08:00
GitHub Action 09fef93f2c TemplateMan Update [Thu Jul 13 05:47:57 UTC 2023] 🤖 2023-07-13 05:47:57 +00:00
GitHub Action 6ee7c4dc2c Auto WordPress Plugins Update [Thu Jul 13 04:02:06 UTC 2023] 🤖 2023-07-13 04:02:06 +00:00
Sandeep Singh f6cd430e59
Added CVE-2023-29300 (Adobe ColdFusion - Pre-Auth Remote Code Execution) (#7682) 2023-07-13 03:59:28 +05:30
Prince Chaddha a20611fe5d
Create CVE-2023-29298.yaml (#7677)
* Create CVE-2023-29298.yaml

* fixed lint error

* matcher + misc updates

* strict matcher

---------

Co-authored-by: sandeep <8293321+ehsandeep@users.noreply.github.com>
2023-07-13 03:38:33 +05:30
Sandeep Singh fd675eaba3
Merge branch 'main' into cve_enrichment 2023-07-12 21:27:27 +05:30
sandeep 98a618353e fixed typo 2023-07-12 19:20:08 +05:30
Ritik Chaddha 603b52e01b
Merge pull request #7656 from aringo-bf/main
Fixed 2021-40822
2023-07-12 17:33:34 +05:30
Ritik Chaddha ed22f507dd
Update CVE-2021-40822.yaml 2023-07-12 17:29:22 +05:30
sandeep b5a88ad386 tags update 2023-07-12 17:26:50 +05:30
Ritik Chaddha b594f453c7
Merge pull request #7666 from projectdiscovery/prometheus-promtail
Create prometheus-promtail.yaml
2023-07-12 17:22:00 +05:30
Ritik Chaddha 94b2c2688b
Update prometheus-promtail.yaml 2023-07-12 17:17:23 +05:30
Ritik Chaddha d0e462ca5f
Merge pull request #7678 from projectdiscovery/CVE-2023-29298
Create CVE-2022-4057.yaml
2023-07-12 17:17:11 +05:30
Ritik Chaddha 709fde5fd1
updated info 2023-07-12 17:12:54 +05:30
Ritik Chaddha cae1137e65
updated info 2023-07-12 17:09:01 +05:30
Dhiyaneshwaran 8339bcff3e
Update and rename CVE-2023-29298.yaml to CVE-2022-4057.yaml 2023-07-12 14:48:02 +05:30
Dhiyaneshwaran e00935e002
Create CVE-2019-17574.yaml 2023-07-12 14:43:01 +05:30
Dhiyaneshwaran 2247d3584c
Create CVE-2023-29298.yaml 2023-07-12 14:41:58 +05:30
pussycat0x d88787658b
Merge pull request #7671 from projectdiscovery/CVE-2022-45354
Create CVE-2022-45354.yaml
2023-07-12 11:56:27 +05:30
pussycat0x 7d70eaa50d
Update CVE-2022-45354.yaml 2023-07-12 11:47:34 +05:30
pussycat0x 1c1614b207
Merge pull request #7665 from projectdiscovery/CVE-2023-2796
Create CVE-2023-2796.yaml
2023-07-12 11:46:24 +05:30
GitHub Action e583a8e27b TemplateMan Update [Wed Jul 12 06:10:16 UTC 2023] 🤖 2023-07-12 06:10:17 +00:00
Dhiyaneshwaran 4d44db771e
Merge pull request #7657 from dongpohezui/exposed-kibana
Update exposed-kibana.yaml
2023-07-12 11:38:32 +05:30
Dhiyaneshwaran 26e8598cef
added metadata 2023-07-12 11:25:01 +05:30
pussycat0x c3fa5d32b6
baseurl - update 2023-07-12 11:18:40 +05:30
Ritik Chaddha b498c0160b
Create vercel-takeover.yaml 2023-07-12 11:17:00 +05:30
pussycat0x 5f2a5d45c0
Merge pull request #7668 from projectdiscovery/sharefile-panel
Create sharefile-panel.yaml
2023-07-12 11:00:53 +05:30
Dhiyaneshwaran 37139b6856
Merge pull request #7672 from dcruzec/main
sonarqube-default-credentials
2023-07-12 10:55:09 +05:30
Dhiyaneshwaran ae5c9fe556
Rename http/misconfiguration/sonarqube-default-credentials.yaml to http/default-logins/sonarqube/sonarqube-default-login.yaml 2023-07-12 10:35:52 +05:30
GitHub Action 52a60148f1 TemplateMan Update [Wed Jul 12 04:53:11 UTC 2023] 🤖 2023-07-12 04:53:12 +00:00
Ritik Chaddha 18279f40b1
tag updated 2023-07-12 10:22:14 +05:30
Ritik Chaddha 1856bf9a8e
Create CVE-2023-37270.yaml 2023-07-12 10:21:18 +05:30
pussycat0x 994d6dc3fe
Merge pull request #7661 from projectdiscovery/sharefile-storage-server
Create sharefile-storage-server.yaml
2023-07-12 10:21:14 +05:30
pussycat0x c14ffec32d
Update sharefile-storage-server.yaml 2023-07-12 10:14:40 +05:30
GitHub Action e974f32d28 Auto WordPress Plugins Update [Wed Jul 12 04:02:14 UTC 2023] 🤖 2023-07-12 04:02:14 +00:00
Ritik Chaddha 1c999a0b92
updated req,matcher,info 2023-07-12 09:27:52 +05:30
dcruzec 20803cbf4b
Update sonarqube-default-credentials.yaml 2023-07-11 17:39:23 -04:00
dcruzec a5e06fd380
Add files via upload
This template checks if Sonarqube assets take in default credentials
2023-07-11 17:34:55 -04:00
Dhiyaneshwaran 8f7c078997
CVE-2023-24489 🔥 Citrix ShareFile StorageZones Controller - RCE (#7664)
* Create CVE-2023-24489

* Add files via upload

* fuzz tag updation

* Rename CVE-2023-24489 to CVE-2023-24489.yaml

* Update http/cves/2023/CVE-2023-24489.yaml

Co-authored-by: Dwi Siswanto <me@dw1.io>

* changes as per review

* misc update

* variable update

* more strict matcher

---------

Co-authored-by: Sandeep Singh <sandeep@projectdiscovery.io>
Co-authored-by: Dwi Siswanto <me@dw1.io>
Co-authored-by: sandeep <8293321+ehsandeep@users.noreply.github.com>
2023-07-12 01:53:18 +05:30
Dhiyaneshwaran 836fb614d5
fix-template 2023-07-12 01:27:47 +05:30
Dhiyaneshwaran 5a2cd2b88a
Create CVE-2022-45354.yaml 2023-07-12 01:24:50 +05:30
sandeep dd83af0228 CVE Enrichment 🎉 2023-07-12 01:19:27 +05:30
Ritik Chaddha 2bc852f3d1
Update CVE-2023-2796.yaml 2023-07-11 23:32:39 +05:30
Dhiyaneshwaran 10572fdaf6
Create sharefile-panel.yaml 2023-07-11 18:31:16 +05:30
GitHub Action 55d7f7cb96 TemplateMan Update [Tue Jul 11 12:52:04 UTC 2023] 🤖 2023-07-11 12:52:04 +00:00
Dhiyaneshwaran 326f4666fc
Create prometheus-promtail.yaml 2023-07-11 18:10:42 +05:30
Dhiyaneshwaran 918e0b0891
Create CVE-2023-2796.yaml 2023-07-11 18:02:11 +05:30
Nybble04 b262a7d62a
Update payloads and attack type 2023-07-11 16:25:45 +04:00
pussycat0x 2ba11bbe29
Merge pull request #7655 from bhutch/leostream-default-login
Update leostream-default-login.yaml
2023-07-11 16:50:32 +05:30
GitHub Action 625347bb68 TemplateMan Update [Tue Jul 11 07:40:00 UTC 2023] 🤖 2023-07-11 07:40:01 +00:00
Dhiyaneshwaran 994cf3151a
Create sharefile-storage-server.yaml 2023-07-11 13:09:17 +05:30
Dhiyaneshwaran a7d4cff36b Revert "Create sharefile-storage-server.yaml"
This reverts commit 4e97d52063.
2023-07-11 13:08:20 +05:30
Dhiyaneshwaran 4e97d52063
Create sharefile-storage-server.yaml 2023-07-11 13:07:48 +05:30
Matt Miller 28b1b52f90
Create springboot-detect.yaml 2023-07-11 00:08:31 -07:00
Dhiyaneshwaran 87bc41c418
fix matcher 2023-07-11 12:14:55 +05:30
Dhiyaneshwaran 8be3eae424
remove duplicate URL 2023-07-11 11:58:31 +05:30
GitHub Action c01bb1f42c Auto WordPress Plugins Update [Tue Jul 11 04:02:09 UTC 2023] 🤖 2023-07-11 04:02:09 +00:00
dongpohezui 47059b1e31
Update exposed-kibana.yaml 2023-07-11 11:09:41 +08:00
sandeep 8dcd4dded7 moving files around 2023-07-11 02:24:59 +05:30
Aaron Ringo 058e02cd68
Update CVE-2021-40822.yaml 2023-07-10 13:05:51 -05:00
aringo 2cf1d043b7 Fixed CVE-2021-40822 2023-07-10 13:01:34 -05:00
Brandon Hutchinson 3ff56ffef3 Update leostream-default-login.yaml 2023-07-10 17:27:32 +00:00
E1A 93bf747773
Update CVE-2023-27524.yaml 2023-07-10 17:21:35 +02:00
Dhiyaneshwaran c8626872ee
fix-lines 2023-07-10 20:51:19 +05:30
Ritik Chaddha 167d0e267d
Merge pull request #7649 from edoardottt/main
Add CVE-2023-3479
2023-07-10 20:44:47 +05:30
Ritik Chaddha f942b15400
updated matcher 2023-07-10 20:41:27 +05:30
Dhiyaneshwaran 685850abae
fix-matcher 2023-07-10 20:34:42 +05:30
Ritik Chaddha 295a6f6ecf
Merge branch 'main' into rule-add-v141 2023-07-10 18:19:56 +05:30
Ritik Chaddha c6b036ffb9
updated name,info,matcher 2023-07-10 18:17:56 +05:30
GitHub Action 04800ddd75 TemplateMan Update [Mon Jul 10 12:43:00 UTC 2023] 🤖 2023-07-10 12:43:01 +00:00
Dhiyaneshwaran b15ab9f3ae
Merge pull request #7539 from harsh2403/patch-7
Create CVE-2023-33440.yaml
2023-07-10 18:11:05 +05:30
Dhiyaneshwaran 942bb169ca
fix 2023-07-10 18:07:31 +05:30
GitHub Action 674cbf611f TemplateMan Update [Mon Jul 10 12:35:12 UTC 2023] 🤖 2023-07-10 12:35:13 +00:00
GitHub Action 02599a324a TemplateMan Update [Mon Jul 10 12:34:24 UTC 2023] 🤖 2023-07-10 12:34:24 +00:00
Dhiyaneshwaran da29099005
Merge pull request #7570 from harsh2403/patch-12
Create CVE-2023-33338.yaml
2023-07-10 18:03:25 +05:30
Dhiyaneshwaran 091fb42570
Merge pull request #7579 from harsh2403/patch-14
Create CVE-2022-46071.yaml
2023-07-10 18:02:31 +05:30
Ritik Chaddha dd6be10dc8
updated info 2023-07-10 17:59:22 +05:30
Ritik Chaddha 7a21bb6f23
matcher and req updated 2023-07-10 17:55:32 +05:30
Ritik Chaddha 33fdee9c77
matchers and req update 2023-07-10 17:40:18 +05:30
Dhiyaneshwaran f371951eca
Merge branch 'main' into patch-36 2023-07-10 16:24:00 +05:30
Dhiyaneshwaran 4ca99ac8f0
Merge pull request #7576 from projectdiscovery/CVE-2023-2982
Create CVE-2023-2982.yaml
2023-07-10 13:38:57 +05:30
GitHub Action 7219ee5e96 TemplateMan Update [Mon Jul 10 07:01:53 UTC 2023] 🤖 2023-07-10 07:01:53 +00:00
Dhiyaneshwaran a8732b298c
Merge pull request #7647 from projectdiscovery/rhadamanthys-stealer-panel
Create rhadamanthys-stealer-panel.yaml
2023-07-10 12:29:54 +05:30
Dhiyaneshwaran 1f3a891f5c
Merge pull request #7537 from harsh2403/patch-6
Create CVE-2016-10973.yaml
2023-07-10 12:29:19 +05:30
GitHub Action 74eec1301c TemplateMan Update [Mon Jul 10 05:27:05 UTC 2023] 🤖 2023-07-10 05:27:05 +00:00
Ritik Chaddha a11f62317d
updated req,matchers 2023-07-10 10:38:33 +05:30
GitHub Action d14caf6372 Auto WordPress Plugins Update [Mon Jul 10 04:02:25 UTC 2023] 🤖 2023-07-10 04:02:25 +00:00
GitHub Action 0dd1d1c36e TemplateMan Update [Sun Jul 9 09:50:07 UTC 2023] 🤖 2023-07-09 09:50:08 +00:00
Sandeep Singh 616e1ec5b0
Added CVE-2023-36934 (MOVEit Transfer - SQL Injection) (#7650) 2023-07-09 15:17:35 +05:30
edoardottt 6dc7cbafe6 add CVE-2023-3479 2023-07-09 11:02:02 +02:00
J4vaovo a068bf6283
Update sitemap-sql-injection.yaml 2023-07-09 16:17:26 +08:00
Ritik Chaddha f990c0a1e7
Create rhadamanthys-stealer-panel.yaml 2023-07-09 13:29:55 +05:30
GitHub Action a676ce2234 Auto WordPress Plugins Update [Sun Jul 9 04:02:05 UTC 2023] 🤖 2023-07-09 04:02:05 +00:00
GitHub Action fdb634b5ae TemplateMan Update [Sat Jul 8 19:17:12 UTC 2023] 🤖 2023-07-08 19:17:13 +00:00
pussycat0x 9bb0d73588
Merge pull request #7580 from harsh2403/patch-15
Create CVE-2022-46073.yaml
2023-07-09 00:44:46 +05:30
GitHub Action 5a1a729d19 TemplateMan Update [Sat Jul 8 17:35:10 UTC 2023] 🤖 2023-07-08 17:35:10 +00:00
pussycat0x 2979f24797
Merge pull request #7643 from bhutch/sunbird-dcim-panel
Create sunbird-dcim-panel.yaml
2023-07-08 23:02:37 +05:30
Dhiyaneshwaran e2248067c8
change to favicon 2023-07-08 12:26:41 +05:30
Dhiyaneshwaran 6f0e0b1b92
fix reference 2023-07-08 12:22:18 +05:30
GitHub Action 4da7d10231 TemplateMan Update [Sat Jul 8 06:51:37 UTC 2023] 🤖 2023-07-08 06:51:37 +00:00
Prince Chaddha 4c2b9ab57c
Update dell-idrac.yaml 2023-07-08 12:16:40 +05:30
Prince Chaddha 79203dca0e
Update CVE-2023-36346.yaml 2023-07-08 12:13:35 +05:30
Prince Chaddha 50b0c162fe
Update open-proxy-external.yaml 2023-07-08 12:01:58 +05:30
Prince Chaddha 18f1702db0
Rename sitemap-sql-injection.yaml to sitemap-sql-injection.yaml 2023-07-08 11:55:13 +05:30
Prince Chaddha cd1b7781db
Update CVE-2023-36346.yaml 2023-07-08 11:53:21 +05:30
Prince Chaddha c8d7286f77
Updated protocol syntax 2023-07-08 11:52:35 +05:30
GitHub Action 3e1cac710f Auto WordPress Plugins Update [Sat Jul 8 04:01:58 UTC 2023] 🤖 2023-07-08 04:01:58 +00:00
GwanYeong Kim a7e213703b Create d-link-auth-bypass.yaml
Security vulnerability known as Unauthenticated access to settings or Unauthenticated configuration download. This vulnerability occurs when a device, such as a repeater, allows the download of user settings without requiring proper authentication.

Signed-off-by: GwanYeong Kim <gy741.kim@gmail.com>
2023-07-08 11:31:57 +09:00
Brandon Hutchinson 82986ad64f Create sunbird-dcim-panel.yaml 2023-07-07 20:27:59 +00:00
Dhiyaneshwaran 4bc6ae766b
base url update and reference 2023-07-07 18:24:25 +05:30
sandeep 3a2e8b144f Merge branch 'main' of https://github.com/projectdiscovery/nuclei-templates 2023-07-07 17:22:14 +05:30
sandeep de6d6e5b56 moving file around 2023-07-07 17:21:56 +05:30
Dhiyaneshwaran e993676827
Merge pull request #7634 from bhutch/leostream-default-login
Create leostream-default-login.yaml
2023-07-07 17:21:16 +05:30
Dhiyaneshwaran 57def2c27c
fix matcher 2023-07-07 17:18:15 +05:30
GitHub Action 646ffaf0b8 TemplateMan Update [Fri Jul 7 11:37:24 UTC 2023] 🤖 2023-07-07 11:37:25 +00:00
GitHub Action ac29ee7958 TemplateMan Update [Fri Jul 7 11:35:10 UTC 2023] 🤖 2023-07-07 11:35:11 +00:00
Prince Chaddha f00f0b0488
Merge pull request #7552 from harsh2403/patch-10
Create CVE-2023-33439.yaml
2023-07-07 17:05:10 +05:30
Dhiyaneshwaran d90e8cb0d6
Merge pull request #7640 from projectdiscovery/pussycat0x-patch-6
Mystic Stealer Panel
2023-07-07 17:03:17 +05:30
Prince Chaddha b316cc936f
Merge pull request #7618 from projectdiscovery/remove-comments
removed enhanced by comments
2023-07-07 17:00:46 +05:30
Prince Chaddha 0a681ec0bb removed empty lines 2023-07-07 16:56:27 +05:30
pussycat0x 5b6c47b74e
Mystic Stealer Panel 2023-07-07 16:54:31 +05:30
GitHub Action cb26083079 TemplateMan Update [Fri Jul 7 11:17:58 UTC 2023] 🤖 2023-07-07 11:17:59 +00:00
pussycat0x cb6eaf95a2
Merge pull request #7637 from projectdiscovery/cve-templates4
CVEs added
2023-07-07 16:46:09 +05:30
GitHub Action 74440d2fbe TemplateMan Update [Fri Jul 7 11:14:01 UTC 2023] 🤖 2023-07-07 11:14:02 +00:00
Dhiyaneshwaran 4f7174686a
Merge pull request #7639 from projectdiscovery/path-updated
Rename universal-media-xss.yaml to universal-media-xss.yaml
2023-07-07 16:42:56 +05:30
Ritik Chaddha 9ef2c9acd7
Merge pull request #7372 from aravindb26/aravind
sitemap-sql
2023-07-07 16:42:18 +05:30
Ritik Chaddha 1565dc6517
Rename universal-media-xss.yaml to universal-media-xss.yaml 2023-07-07 16:40:25 +05:30
Ritik Chaddha 88bb3eb0d1
Rename http/misconfiguration/sitemap-sql-injection.yaml to http/vulnerabilities /other/sitemap-sql-injection.yaml 2023-07-07 16:39:23 +05:30
pussycat0x 0ccffd229a
Merge branch 'main' into remove-comments 2023-07-07 16:38:46 +05:30
GitHub Action f7204ac643 TemplateMan Update [Fri Jul 7 11:07:24 UTC 2023] 🤖 2023-07-07 11:07:25 +00:00
GitHub Action 331e96afba TemplateMan Update [Fri Jul 7 11:07:15 UTC 2023] 🤖 2023-07-07 11:07:16 +00:00
Ritik Chaddha b3a8e0d1b5
Merge pull request #7632 from projectdiscovery/pussycat0x-patch-6
Esafenet CDG - Default Login
2023-07-07 16:35:12 +05:30
Ritik Chaddha f2305ec321
Merge pull request #7633 from projectdiscovery/pussycat0x-patch-14
Hookbot Rat Panel
2023-07-07 16:35:03 +05:30