👾CVE SERVICE 🏷#CVE
Mumber: CVE-2022-0543
Github: https://github.com/JacobEbben/CVE-2022-0543
Describe:
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution.
Mumber: CVE-2022-0543
Github: https://github.com/JacobEbben/CVE-2022-0543
Describe:
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution.
GitHub
GitHub - JacobEbben/CVE-2022-0543: Redis RCE through Lua Sandbox Escape vulnerability
Redis RCE through Lua Sandbox Escape vulnerability - JacobEbben/CVE-2022-0543
👾KEYWORD SERVICE 🏷#exploit
Name: post-exploitation-enum
Github: https://github.com/savenas/post-exploitation-enum
Name: post-exploitation-enum
Github: https://github.com/savenas/post-exploitation-enum
GitHub
GitHub - savenas/post-exploitation-enum: Post exploitation enumeration cheat sheet
Post exploitation enumeration cheat sheet. Contribute to savenas/post-exploitation-enum development by creating an account on GitHub.
👾KEYWORD SERVICE 🏷#exploit
Name: STM32UsbDeviceExploiter
Github: https://github.com/szymonh/STM32UsbDeviceExploiter
Name: STM32UsbDeviceExploiter
Github: https://github.com/szymonh/STM32UsbDeviceExploiter
GitHub
GitHub - szymonh/STM32UsbDeviceExploiter: Test USB device implementations based on STM32 middleware against buffer overflow issues…
Test USB device implementations based on STM32 middleware against buffer overflow issues resolved in version 2.8.0. - GitHub - szymonh/STM32UsbDeviceExploiter: Test USB device implementations based...
👾KEYWORD SERVICE 🏷#redteam
Name: GoPhish-Templates
Github: https://github.com/FreeZeroDays/GoPhish-Templates
Name: GoPhish-Templates
Github: https://github.com/FreeZeroDays/GoPhish-Templates
GitHub
GitHub - FreeZeroDays/GoPhish-Templates: GoPhish Templates that I have retired and/or templates I've recreated.
GoPhish Templates that I have retired and/or templates I've recreated. - FreeZeroDays/GoPhish-Templates
👾KEYWORD SERVICE 🏷#exploit
Name: tryhackme.com-room-exploitingavulnerabilityv2
Github: https://github.com/trcyprkr/tryhackme.com-room-exploitingavulnerabilityv2
Name: tryhackme.com-room-exploitingavulnerabilityv2
Github: https://github.com/trcyprkr/tryhackme.com-room-exploitingavulnerabilityv2
GitHub
GitHub - trcyprkr/tryhackme.com-room-exploitingavulnerabilityv2: Exploiting Vulnerabilities Task 5
Exploiting Vulnerabilities Task 5. Contribute to trcyprkr/tryhackme.com-room-exploitingavulnerabilityv2 development by creating an account on GitHub.
👾CVE SERVICE 🏷#CVE
Mumber: CVE-2022-25260
Github: https://github.com/yuriisanin/CVE-2022-25260
Describe:
JetBrains Hub before 2021.1.14276 was vulnerable to blind Server-Side Request Forgery (SSRF).
Mumber: CVE-2022-25260
Github: https://github.com/yuriisanin/CVE-2022-25260
Describe:
JetBrains Hub before 2021.1.14276 was vulnerable to blind Server-Side Request Forgery (SSRF).
GitHub
GitHub - yuriisanin/CVE-2022-25260: PoC for CVE-2022-25260: pre-auth semi-blind SSRF in JetBrains Hub
PoC for CVE-2022-25260: pre-auth semi-blind SSRF in JetBrains Hub - yuriisanin/CVE-2022-25260
** fscan ** 🔧Tool update
Tools name:fscan
Tools url:https://github.com/shadow1ng/fscan/commit/4908720acbbb4bdd369a8bfa92c7b73b0ca893cf
commitUpdate log:
socks代理时,自动-np
Tools name:fscan
Tools url:https://github.com/shadow1ng/fscan/commit/4908720acbbb4bdd369a8bfa92c7b73b0ca893cf
commitUpdate log:
socks代理时,自动-np
GitHub
socks代理时,自动-np · shadow1ng/fscan@4908720
一款内网综合扫描工具,方便一键自动化、全方位漏扫扫描。. Contribute to shadow1ng/fscan development by creating an account on GitHub.
👾CVE SERVICE 🏷#CVE
Mumber: CVE-2022-33174
Github: https://github.com/Henry4E36/CVE-2022-33174
Describe:
Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 allows remote authorization bypass in the web interface. To exploit the vulnerability, an attacker must send an HTTP packet to the data retrieval interface (/cgi/get_param.cgi) with the tmpToken cookie set to an empty string followed by a semicolon. This bypasses an active session authorization check. This can be then used to fetch the values of protected sys.passwd and sys.su.name fields that contain the username and password in cleartext.
Mumber: CVE-2022-33174
Github: https://github.com/Henry4E36/CVE-2022-33174
Describe:
Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 allows remote authorization bypass in the web interface. To exploit the vulnerability, an attacker must send an HTTP packet to the data retrieval interface (/cgi/get_param.cgi) with the tmpToken cookie set to an empty string followed by a semicolon. This bypasses an active session authorization check. This can be then used to fetch the values of protected sys.passwd and sys.su.name fields that contain the username and password in cleartext.
GitHub
GitHub - Henry4E36/CVE-2022-33174: Powertek PDU身份绕过
Powertek PDU身份绕过. Contribute to Henry4E36/CVE-2022-33174 development by creating an account on GitHub.
👾KEYWORD SERVICE 🏷#exploit
Name: SILENT-PDF-EXPLOIT-CLEAN-gt
Github: https://github.com/codingcore2/SILENT-PDF-EXPLOIT-CLEAN-gt
Name: SILENT-PDF-EXPLOIT-CLEAN-gt
Github: https://github.com/codingcore2/SILENT-PDF-EXPLOIT-CLEAN-gt
GitHub
GitHub - codingcore2/SILENT-PDF-EXPLOIT-CLEAN-gt
Contribute to codingcore2/SILENT-PDF-EXPLOIT-CLEAN-gt development by creating an account on GitHub.
👾KEYWORD SERVICE 🏷#exploit
Name: SILENT-EXCEL-XLS-EXPLOIT-CLEAN-gt
Github: https://github.com/codingcore2/SILENT-EXCEL-XLS-EXPLOIT-CLEAN-gt
Name: SILENT-EXCEL-XLS-EXPLOIT-CLEAN-gt
Github: https://github.com/codingcore2/SILENT-EXCEL-XLS-EXPLOIT-CLEAN-gt
GitHub
GitHub - codingcore2/SILENT-EXCEL-XLS-EXPLOIT-CLEAN-gt
Contribute to codingcore2/SILENT-EXCEL-XLS-EXPLOIT-CLEAN-gt development by creating an account on GitHub.