** xray ** 🔧Tool update
Tools name:xray
Tools url:https://github.com/chaitin/xray/commit/a9ddda5e28119f72e391b8a0c8fb753d6c53c0d5
commitUpdate log:
Update jellyfin-cve-2021-29490.yml (#1632)
Tools name:xray
Tools url:https://github.com/chaitin/xray/commit/a9ddda5e28119f72e391b8a0c8fb753d6c53c0d5
commitUpdate log:
Update jellyfin-cve-2021-29490.yml (#1632)
GitHub
Update jellyfin-cve-2021-29490.yml (#1632) · chaitin/xray@a9ddda5
一款完善的安全评估工具,支持常见 web 安全问题扫描和自定义 poc | 使用之前务必先阅读文档. Contribute to chaitin/xray development by creating an account on GitHub.
👾CVE SERVICE 🏷#CVE
Mumber: CVE-2022-33980
Github: https://github.com/HKirito/CVE-2022-33980
Describe:
Apache Commons Configuration performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where "prefix" is used to locate an instance of org.apache.commons.configuration2.interpol.Lookup that performs the interpolation. Starting with version 2.4 and continuing through 2.7, the set of default Lookup instances included interpolators that could result in arbitrary code execution or contact with remote servers. These lookups are: - "script" - execute expressions using the JVM script execution engine (javax.script) - "dns" - resolve dns records - "url" - load values from urls, including from remote servers Applications using the interpolation defaults in the affected versions may be vulnerable to remote code execution or unintentional contact with remote servers if untrusted configuration values are used. Users are recommended to upgrade to Apache Commons Configuration 2.8.0, which disables the problematic interpolators by default.
Mumber: CVE-2022-33980
Github: https://github.com/HKirito/CVE-2022-33980
Describe:
Apache Commons Configuration performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where "prefix" is used to locate an instance of org.apache.commons.configuration2.interpol.Lookup that performs the interpolation. Starting with version 2.4 and continuing through 2.7, the set of default Lookup instances included interpolators that could result in arbitrary code execution or contact with remote servers. These lookups are: - "script" - execute expressions using the JVM script execution engine (javax.script) - "dns" - resolve dns records - "url" - load values from urls, including from remote servers Applications using the interpolation defaults in the affected versions may be vulnerable to remote code execution or unintentional contact with remote servers if untrusted configuration values are used. Users are recommended to upgrade to Apache Commons Configuration 2.8.0, which disables the problematic interpolators by default.
GitHub
GitHub - HKirito/CVE-2022-33980: CVE
CVE. Contribute to HKirito/CVE-2022-33980 development by creating an account on GitHub.
👾KEYWORD SERVICE 🏷#redteam
Name: Penetration-Testing-Tools
Github: https://github.com/mgeeky/Penetration-Testing-Tools
Name: Penetration-Testing-Tools
Github: https://github.com/mgeeky/Penetration-Testing-Tools
GitHub
GitHub - mgeeky/Penetration-Testing-Tools: A collection of more than 170+ tools, scripts, cheatsheets and other loots that I've…
A collection of more than 170+ tools, scripts, cheatsheets and other loots that I've developed over years for Red Teaming/Pentesting/IT Security audits purposes. - mgeeky/Penetration-Testing-Tools
👾KEYWORD SERVICE 🏷#sql_injection
Name: CUC-web-SQL-Injection
Github: https://github.com/zhang-de-xin/CUC-web-SQL-Injection
Name: CUC-web-SQL-Injection
Github: https://github.com/zhang-de-xin/CUC-web-SQL-Injection
GitHub
GitHub - zhang-de-xin/CUC-web-SQL-Injection
Contribute to zhang-de-xin/CUC-web-SQL-Injection development by creating an account on GitHub.
👾KEYWORD SERVICE 🏷#sql_injection
Name: Okta_DotNet_SQL_Injection
Github: https://github.com/aluminec/Okta_DotNet_SQL_Injection
Name: Okta_DotNet_SQL_Injection
Github: https://github.com/aluminec/Okta_DotNet_SQL_Injection
GitHub
GitHub - aluminec/Okta_DotNet_SQL_Injection
Contribute to aluminec/Okta_DotNet_SQL_Injection development by creating an account on GitHub.
👾KEYWORD SERVICE 🏷#exploit
Name: BitRat-Cracked-SRC-2022
Github: https://github.com/PowerIsCoding/BitRat-Cracked-SRC-2022
Name: BitRat-Cracked-SRC-2022
Github: https://github.com/PowerIsCoding/BitRat-Cracked-SRC-2022
GitHub
GitHub - PowerIsCoding/BitRat-Cracked-SRC-2022: Native client coded in C/C++. Fully Unicode compatible. Downloader - Generate a…
Native client coded in C/C++. Fully Unicode compatible. Downloader - Generate a downloader for any exe of your choice with options of execution from memory (RunPE) or disk. UAC Exploit for elevated...
👾KEYWORD SERVICE 🏷#exploit
Name: Rust_HTTP_Method_Enumerator
Github: https://github.com/Ayodub/Rust_HTTP_Method_Enumerator
Name: Rust_HTTP_Method_Enumerator
Github: https://github.com/Ayodub/Rust_HTTP_Method_Enumerator
GitHub
GitHub - Ayodub/Rust_HTTP_Method_Enumerator: Identify potentially exploitable HTTP methods using Rust
Identify potentially exploitable HTTP methods using Rust - GitHub - Ayodub/Rust_HTTP_Method_Enumerator: Identify potentially exploitable HTTP methods using Rust
👾KEYWORD SERVICE 🏷#exploit
Name: inverse-finance-exploit
Github: https://github.com/yuichiroaoki/inverse-finance-exploit
Name: inverse-finance-exploit
Github: https://github.com/yuichiroaoki/inverse-finance-exploit
GitHub
GitHub - yuichiroaoki/inverse-finance-exploit: Oracle Manipulation Attack on Inverse Finance
Oracle Manipulation Attack on Inverse Finance. Contribute to yuichiroaoki/inverse-finance-exploit development by creating an account on GitHub.
👾KEYWORD SERVICE 🏷#exploit
Name: SILENT-DOC-EXPLOIT-CLEAN-j
Github: https://github.com/codingcore2/SILENT-DOC-EXPLOIT-CLEAN-j
Name: SILENT-DOC-EXPLOIT-CLEAN-j
Github: https://github.com/codingcore2/SILENT-DOC-EXPLOIT-CLEAN-j
GitHub
GitHub - codingcore2/SILENT-DOC-EXPLOIT-CLEAN-j
Contribute to codingcore2/SILENT-DOC-EXPLOIT-CLEAN-j development by creating an account on GitHub.
👾KEYWORD SERVICE 🏷#exploit
Name: SILENT-PDF-EXPLOIT-CLEAN-j
Github: https://github.com/codingcore2/SILENT-PDF-EXPLOIT-CLEAN-j
Name: SILENT-PDF-EXPLOIT-CLEAN-j
Github: https://github.com/codingcore2/SILENT-PDF-EXPLOIT-CLEAN-j
GitHub
GitHub - codingcore2/SILENT-PDF-EXPLOIT-CLEAN-j
Contribute to codingcore2/SILENT-PDF-EXPLOIT-CLEAN-j development by creating an account on GitHub.
👾KEYWORD SERVICE 🏷#exploit
Name: SILENT-EXCEL-XLS-EXPLOIT-CLEAN-j
Github: https://github.com/codingcore2/SILENT-EXCEL-XLS-EXPLOIT-CLEAN-j
Name: SILENT-EXCEL-XLS-EXPLOIT-CLEAN-j
Github: https://github.com/codingcore2/SILENT-EXCEL-XLS-EXPLOIT-CLEAN-j
GitHub
GitHub - codingcore2/SILENT-EXCEL-XLS-EXPLOIT-CLEAN-j
Contribute to codingcore2/SILENT-EXCEL-XLS-EXPLOIT-CLEAN-j development by creating an account on GitHub.
👾CVE SERVICE 🏷#CVE
Mumber: CVE-2022-1421
Github: https://github.com/nb1b3k/CVE-2022-1421
Describe:
The Discy WordPress theme before 5.2 lacks CSRF checks in some AJAX actions, allowing an attacker to make a logged in admin change arbitrary 's settings including payment methods via a CSRF attack
Mumber: CVE-2022-1421
Github: https://github.com/nb1b3k/CVE-2022-1421
Describe:
The Discy WordPress theme before 5.2 lacks CSRF checks in some AJAX actions, allowing an attacker to make a logged in admin change arbitrary 's settings including payment methods via a CSRF attack
GitHub
GitHub - nb1b3k/CVE-2022-1421
Contribute to nb1b3k/CVE-2022-1421 development by creating an account on GitHub.
👾KEYWORD SERVICE 🏷#exploit
Name: test-application-default-discuss-exploit
Github: https://github.com/mmorhun-org/test-application-default-discuss-exploit
Name: test-application-default-discuss-exploit
Github: https://github.com/mmorhun-org/test-application-default-discuss-exploit
GitHub
GitHub - mmorhun-org/test-application-default-discuss-exploit: GitOps Repository
GitOps Repository. Contribute to mmorhun-org/test-application-default-discuss-exploit development by creating an account on GitHub.
👾KEYWORD SERVICE 🏷#exploit
Name: Private-Variable-Exploit-
Github: https://github.com/ishinu/Private-Variable-Exploit-
Name: Private-Variable-Exploit-
Github: https://github.com/ishinu/Private-Variable-Exploit-
GitHub
GitHub - ishinu/Private-Variable-Exploit-
Contribute to ishinu/Private-Variable-Exploit- development by creating an account on GitHub.