👾CVE SERVICE 🏷#CVE
Mumber: CVE-2022-21881
Github: https://github.com/theabysslabs/CVE-2022-21881
Describe:
Windows Kernel Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-21879.
Mumber: CVE-2022-21881
Github: https://github.com/theabysslabs/CVE-2022-21881
Describe:
Windows Kernel Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-21879.
GitHub
GitHub - theabysslabs/CVE-2022-21881: POC of CVE-2022-21881 exploited at TianfuCup 2021 to escape Chrome Sandbox
POC of CVE-2022-21881 exploited at TianfuCup 2021 to escape Chrome Sandbox - theabysslabs/CVE-2022-21881
👾KEYWORD SERVICE 🏷#sql_injection
Name: python-flask-sql-injection
Github: https://github.com/basiima/python-flask-sql-injection
Name: python-flask-sql-injection
Github: https://github.com/basiima/python-flask-sql-injection
GitHub
GitHub - basiima/python-flask-sql-injection
Contribute to basiima/python-flask-sql-injection development by creating an account on GitHub.
👾KEYWORD SERVICE 🏷#exploit
Name: ChatHistoryExploit
Github: https://github.com/sasoiYT/ChatHistoryExploit
Name: ChatHistoryExploit
Github: https://github.com/sasoiYT/ChatHistoryExploit
GitHub
sasoiYT/ChatHistoryExploit
Contribute to sasoiYT/ChatHistoryExploit development by creating an account on GitHub.
👾KEYWORD SERVICE 🏷#sql_injection
Name: sql-injection-assignment
Github: https://github.com/kleells/sql-injection-assignment
Name: sql-injection-assignment
Github: https://github.com/kleells/sql-injection-assignment
GitHub
GitHub - kleells/sql-injection-assignment
Contribute to kleells/sql-injection-assignment development by creating an account on GitHub.
👾CVE SERVICE 🏷#CVE
Mumber: CVE-2022-29968
Github: https://github.com/jprx/CVE-2022-29968
Describe:
An issue was discovered in the Linux kernel through 5.17.5. io_rw_init_file in fs/io_uring.c lacks initialization of kiocb->private.
Mumber: CVE-2022-29968
Github: https://github.com/jprx/CVE-2022-29968
Describe:
An issue was discovered in the Linux kernel through 5.17.5. io_rw_init_file in fs/io_uring.c lacks initialization of kiocb->private.
GitHub
GitHub - jprx/CVE-2022-29968: Exploit PoC for CVE-2022-29968 by Joseph Ravichandran and Michael Wang
Exploit PoC for CVE-2022-29968 by Joseph Ravichandran and Michael Wang - jprx/CVE-2022-29968
** xray ** 🔧Tool update
Tools name:xray
Tools url:https://github.com/chaitin/xray/commit/a9ddda5e28119f72e391b8a0c8fb753d6c53c0d5
commitUpdate log:
Update jellyfin-cve-2021-29490.yml (#1632)
Tools name:xray
Tools url:https://github.com/chaitin/xray/commit/a9ddda5e28119f72e391b8a0c8fb753d6c53c0d5
commitUpdate log:
Update jellyfin-cve-2021-29490.yml (#1632)
GitHub
Update jellyfin-cve-2021-29490.yml (#1632) · chaitin/xray@a9ddda5
一款完善的安全评估工具,支持常见 web 安全问题扫描和自定义 poc | 使用之前务必先阅读文档. Contribute to chaitin/xray development by creating an account on GitHub.
👾CVE SERVICE 🏷#CVE
Mumber: CVE-2022-33980
Github: https://github.com/HKirito/CVE-2022-33980
Describe:
Apache Commons Configuration performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where "prefix" is used to locate an instance of org.apache.commons.configuration2.interpol.Lookup that performs the interpolation. Starting with version 2.4 and continuing through 2.7, the set of default Lookup instances included interpolators that could result in arbitrary code execution or contact with remote servers. These lookups are: - "script" - execute expressions using the JVM script execution engine (javax.script) - "dns" - resolve dns records - "url" - load values from urls, including from remote servers Applications using the interpolation defaults in the affected versions may be vulnerable to remote code execution or unintentional contact with remote servers if untrusted configuration values are used. Users are recommended to upgrade to Apache Commons Configuration 2.8.0, which disables the problematic interpolators by default.
Mumber: CVE-2022-33980
Github: https://github.com/HKirito/CVE-2022-33980
Describe:
Apache Commons Configuration performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where "prefix" is used to locate an instance of org.apache.commons.configuration2.interpol.Lookup that performs the interpolation. Starting with version 2.4 and continuing through 2.7, the set of default Lookup instances included interpolators that could result in arbitrary code execution or contact with remote servers. These lookups are: - "script" - execute expressions using the JVM script execution engine (javax.script) - "dns" - resolve dns records - "url" - load values from urls, including from remote servers Applications using the interpolation defaults in the affected versions may be vulnerable to remote code execution or unintentional contact with remote servers if untrusted configuration values are used. Users are recommended to upgrade to Apache Commons Configuration 2.8.0, which disables the problematic interpolators by default.
GitHub
GitHub - HKirito/CVE-2022-33980: CVE
CVE. Contribute to HKirito/CVE-2022-33980 development by creating an account on GitHub.