CVE HUB 👾
788 subscribers
19.3K links
Github Red team resource push
Github 红队资源推送
Cve/Rce/Exploit/Redteam/漏洞利用/红队

Channel push 24/7 (real time)
频道全天候推送(实时)
Download Telegram
👾KEYWORD SERVICE 🏷#redteam
Name: rockyou
Github: https://github.com/IrishMaestro/rockyou
👾CVE SERVICE 🏷#CVE
Mumber: CVE-2022-33174
Github: https://github.com/Henry4E36/CVE-2022-33174
Describe:
Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 allows remote authorization bypass in the web interface. To exploit the vulnerability, an attacker must send an HTTP packet to the data retrieval interface (/cgi/get_param.cgi) with the tmpToken cookie set to an empty string followed by a semicolon. This bypasses an active session authorization check. This can be then used to fetch the values of protected sys.passwd and sys.su.name fields that contain the username and password in cleartext.
👾CVE SERVICE 🏷#CVE
Mumber: CVE-2022-24780
Github: https://github.com/Acceis/exploit-CVE-2022-24780
Describe:
Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.6 and 3.0.0, users of the iTop user portal can send TWIG code to the server by forging specific http queries, and execute arbitrary code on the server using http server user privileges. This issue is fixed in versions 2.7.6 and 3.0.0. There are currently no known workarounds.