👾KEYWORD SERVICE 🏷#exploit
Name: tryhackme.com-room-exploitingavulnerabilityv2
Github: https://github.com/trcyprkr/tryhackme.com-room-exploitingavulnerabilityv2
Name: tryhackme.com-room-exploitingavulnerabilityv2
Github: https://github.com/trcyprkr/tryhackme.com-room-exploitingavulnerabilityv2
GitHub
GitHub - trcyprkr/tryhackme.com-room-exploitingavulnerabilityv2: Exploiting Vulnerabilities Task 5
Exploiting Vulnerabilities Task 5. Contribute to trcyprkr/tryhackme.com-room-exploitingavulnerabilityv2 development by creating an account on GitHub.
👾CVE SERVICE 🏷#CVE
Mumber: CVE-2022-25260
Github: https://github.com/yuriisanin/CVE-2022-25260
Describe:
JetBrains Hub before 2021.1.14276 was vulnerable to blind Server-Side Request Forgery (SSRF).
Mumber: CVE-2022-25260
Github: https://github.com/yuriisanin/CVE-2022-25260
Describe:
JetBrains Hub before 2021.1.14276 was vulnerable to blind Server-Side Request Forgery (SSRF).
GitHub
GitHub - yuriisanin/CVE-2022-25260: PoC for CVE-2022-25260: pre-auth semi-blind SSRF in JetBrains Hub
PoC for CVE-2022-25260: pre-auth semi-blind SSRF in JetBrains Hub - yuriisanin/CVE-2022-25260
** fscan ** 🔧Tool update
Tools name:fscan
Tools url:https://github.com/shadow1ng/fscan/commit/4908720acbbb4bdd369a8bfa92c7b73b0ca893cf
commitUpdate log:
socks代理时,自动-np
Tools name:fscan
Tools url:https://github.com/shadow1ng/fscan/commit/4908720acbbb4bdd369a8bfa92c7b73b0ca893cf
commitUpdate log:
socks代理时,自动-np
GitHub
socks代理时,自动-np · shadow1ng/fscan@4908720
一款内网综合扫描工具,方便一键自动化、全方位漏扫扫描。. Contribute to shadow1ng/fscan development by creating an account on GitHub.
👾CVE SERVICE 🏷#CVE
Mumber: CVE-2022-33174
Github: https://github.com/Henry4E36/CVE-2022-33174
Describe:
Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 allows remote authorization bypass in the web interface. To exploit the vulnerability, an attacker must send an HTTP packet to the data retrieval interface (/cgi/get_param.cgi) with the tmpToken cookie set to an empty string followed by a semicolon. This bypasses an active session authorization check. This can be then used to fetch the values of protected sys.passwd and sys.su.name fields that contain the username and password in cleartext.
Mumber: CVE-2022-33174
Github: https://github.com/Henry4E36/CVE-2022-33174
Describe:
Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 allows remote authorization bypass in the web interface. To exploit the vulnerability, an attacker must send an HTTP packet to the data retrieval interface (/cgi/get_param.cgi) with the tmpToken cookie set to an empty string followed by a semicolon. This bypasses an active session authorization check. This can be then used to fetch the values of protected sys.passwd and sys.su.name fields that contain the username and password in cleartext.
GitHub
GitHub - Henry4E36/CVE-2022-33174: Powertek PDU身份绕过
Powertek PDU身份绕过. Contribute to Henry4E36/CVE-2022-33174 development by creating an account on GitHub.
👾KEYWORD SERVICE 🏷#exploit
Name: SILENT-PDF-EXPLOIT-CLEAN-gt
Github: https://github.com/codingcore2/SILENT-PDF-EXPLOIT-CLEAN-gt
Name: SILENT-PDF-EXPLOIT-CLEAN-gt
Github: https://github.com/codingcore2/SILENT-PDF-EXPLOIT-CLEAN-gt
GitHub
GitHub - codingcore2/SILENT-PDF-EXPLOIT-CLEAN-gt
Contribute to codingcore2/SILENT-PDF-EXPLOIT-CLEAN-gt development by creating an account on GitHub.
👾KEYWORD SERVICE 🏷#exploit
Name: SILENT-EXCEL-XLS-EXPLOIT-CLEAN-gt
Github: https://github.com/codingcore2/SILENT-EXCEL-XLS-EXPLOIT-CLEAN-gt
Name: SILENT-EXCEL-XLS-EXPLOIT-CLEAN-gt
Github: https://github.com/codingcore2/SILENT-EXCEL-XLS-EXPLOIT-CLEAN-gt
GitHub
GitHub - codingcore2/SILENT-EXCEL-XLS-EXPLOIT-CLEAN-gt
Contribute to codingcore2/SILENT-EXCEL-XLS-EXPLOIT-CLEAN-gt development by creating an account on GitHub.
👾KEYWORD SERVICE 🏷#exploit
Name: SILENT-DOC-EXPLOIT-CLEAN-gt
Github: https://github.com/codingcore2/SILENT-DOC-EXPLOIT-CLEAN-gt
Name: SILENT-DOC-EXPLOIT-CLEAN-gt
Github: https://github.com/codingcore2/SILENT-DOC-EXPLOIT-CLEAN-gt
GitHub
GitHub - codingcore2/SILENT-DOC-EXPLOIT-CLEAN-gt
Contribute to codingcore2/SILENT-DOC-EXPLOIT-CLEAN-gt development by creating an account on GitHub.
👾KEYWORD SERVICE 🏷#exploit
Name: Vbulletin-Custmerid-Checker-0day-exploit
Github: https://github.com/s4udiT3rr0rist/Vbulletin-Custmerid-Checker-0day-exploit
Name: Vbulletin-Custmerid-Checker-0day-exploit
Github: https://github.com/s4udiT3rr0rist/Vbulletin-Custmerid-Checker-0day-exploit
GitHub
s4udiT3rr0rist/Vbulletin-Custmerid-Checker-0day-exploit
Vbulletin Custmerid Checker 0day exploit. Contribute to s4udiT3rr0rist/Vbulletin-Custmerid-Checker-0day-exploit development by creating an account on GitHub.
👾KEYWORD SERVICE 🏷#内存马
Name: java-memshell-scanner
Github: https://github.com/c0ny1/java-memshell-scanner
Name: java-memshell-scanner
Github: https://github.com/c0ny1/java-memshell-scanner
GitHub
GitHub - c0ny1/java-memshell-scanner: 通过jsp脚本扫描java web Filter/Servlet型内存马
通过jsp脚本扫描java web Filter/Servlet型内存马. Contribute to c0ny1/java-memshell-scanner development by creating an account on GitHub.
👾CVE SERVICE 🏷#CVE
Mumber: CVE-2022-24780
Github: https://github.com/Acceis/exploit-CVE-2022-24780
Describe:
Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.6 and 3.0.0, users of the iTop user portal can send TWIG code to the server by forging specific http queries, and execute arbitrary code on the server using http server user privileges. This issue is fixed in versions 2.7.6 and 3.0.0. There are currently no known workarounds.
Mumber: CVE-2022-24780
Github: https://github.com/Acceis/exploit-CVE-2022-24780
Describe:
Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.6 and 3.0.0, users of the iTop user portal can send TWIG code to the server by forging specific http queries, and execute arbitrary code on the server using http server user privileges. This issue is fixed in versions 2.7.6 and 3.0.0. There are currently no known workarounds.
GitHub
GitHub - Acceis/exploit-CVE-2022-24780: iTop < 2.7.6 - (Authenticated) Remote command execution
iTop < 2.7.6 - (Authenticated) Remote command execution - Acceis/exploit-CVE-2022-24780