👾CVE SERVICE 🏷#CVE
Mumber: CVE-2022-33174
Github: https://github.com/Henry4E36/CVE-2022-33174
Describe:
Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 allows remote authorization bypass in the web interface. To exploit the vulnerability, an attacker must send an HTTP packet to the data retrieval interface (/cgi/get_param.cgi) with the tmpToken cookie set to an empty string followed by a semicolon. This bypasses an active session authorization check. This can be then used to fetch the values of protected sys.passwd and sys.su.name fields that contain the username and password in cleartext.
Mumber: CVE-2022-33174
Github: https://github.com/Henry4E36/CVE-2022-33174
Describe:
Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 allows remote authorization bypass in the web interface. To exploit the vulnerability, an attacker must send an HTTP packet to the data retrieval interface (/cgi/get_param.cgi) with the tmpToken cookie set to an empty string followed by a semicolon. This bypasses an active session authorization check. This can be then used to fetch the values of protected sys.passwd and sys.su.name fields that contain the username and password in cleartext.
GitHub
GitHub - Henry4E36/CVE-2022-33174: Powertek PDU身份绕过
Powertek PDU身份绕过. Contribute to Henry4E36/CVE-2022-33174 development by creating an account on GitHub.
👾KEYWORD SERVICE 🏷#exploit
Name: SILENT-PDF-EXPLOIT-CLEAN-gt
Github: https://github.com/codingcore2/SILENT-PDF-EXPLOIT-CLEAN-gt
Name: SILENT-PDF-EXPLOIT-CLEAN-gt
Github: https://github.com/codingcore2/SILENT-PDF-EXPLOIT-CLEAN-gt
GitHub
GitHub - codingcore2/SILENT-PDF-EXPLOIT-CLEAN-gt
Contribute to codingcore2/SILENT-PDF-EXPLOIT-CLEAN-gt development by creating an account on GitHub.
👾KEYWORD SERVICE 🏷#exploit
Name: SILENT-EXCEL-XLS-EXPLOIT-CLEAN-gt
Github: https://github.com/codingcore2/SILENT-EXCEL-XLS-EXPLOIT-CLEAN-gt
Name: SILENT-EXCEL-XLS-EXPLOIT-CLEAN-gt
Github: https://github.com/codingcore2/SILENT-EXCEL-XLS-EXPLOIT-CLEAN-gt
GitHub
GitHub - codingcore2/SILENT-EXCEL-XLS-EXPLOIT-CLEAN-gt
Contribute to codingcore2/SILENT-EXCEL-XLS-EXPLOIT-CLEAN-gt development by creating an account on GitHub.
👾KEYWORD SERVICE 🏷#exploit
Name: SILENT-DOC-EXPLOIT-CLEAN-gt
Github: https://github.com/codingcore2/SILENT-DOC-EXPLOIT-CLEAN-gt
Name: SILENT-DOC-EXPLOIT-CLEAN-gt
Github: https://github.com/codingcore2/SILENT-DOC-EXPLOIT-CLEAN-gt
GitHub
GitHub - codingcore2/SILENT-DOC-EXPLOIT-CLEAN-gt
Contribute to codingcore2/SILENT-DOC-EXPLOIT-CLEAN-gt development by creating an account on GitHub.
👾KEYWORD SERVICE 🏷#exploit
Name: Vbulletin-Custmerid-Checker-0day-exploit
Github: https://github.com/s4udiT3rr0rist/Vbulletin-Custmerid-Checker-0day-exploit
Name: Vbulletin-Custmerid-Checker-0day-exploit
Github: https://github.com/s4udiT3rr0rist/Vbulletin-Custmerid-Checker-0day-exploit
GitHub
s4udiT3rr0rist/Vbulletin-Custmerid-Checker-0day-exploit
Vbulletin Custmerid Checker 0day exploit. Contribute to s4udiT3rr0rist/Vbulletin-Custmerid-Checker-0day-exploit development by creating an account on GitHub.
👾KEYWORD SERVICE 🏷#内存马
Name: java-memshell-scanner
Github: https://github.com/c0ny1/java-memshell-scanner
Name: java-memshell-scanner
Github: https://github.com/c0ny1/java-memshell-scanner
GitHub
GitHub - c0ny1/java-memshell-scanner: 通过jsp脚本扫描java web Filter/Servlet型内存马
通过jsp脚本扫描java web Filter/Servlet型内存马. Contribute to c0ny1/java-memshell-scanner development by creating an account on GitHub.
👾CVE SERVICE 🏷#CVE
Mumber: CVE-2022-24780
Github: https://github.com/Acceis/exploit-CVE-2022-24780
Describe:
Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.6 and 3.0.0, users of the iTop user portal can send TWIG code to the server by forging specific http queries, and execute arbitrary code on the server using http server user privileges. This issue is fixed in versions 2.7.6 and 3.0.0. There are currently no known workarounds.
Mumber: CVE-2022-24780
Github: https://github.com/Acceis/exploit-CVE-2022-24780
Describe:
Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.6 and 3.0.0, users of the iTop user portal can send TWIG code to the server by forging specific http queries, and execute arbitrary code on the server using http server user privileges. This issue is fixed in versions 2.7.6 and 3.0.0. There are currently no known workarounds.
GitHub
GitHub - Acceis/exploit-CVE-2022-24780: iTop < 2.7.6 - (Authenticated) Remote command execution
iTop < 2.7.6 - (Authenticated) Remote command execution - Acceis/exploit-CVE-2022-24780
👾KEYWORD SERVICE 🏷#exploit
Name: JWT-Attack-Exploits
Github: https://github.com/Linuxinet/JWT-Attack-Exploits
Name: JWT-Attack-Exploits
Github: https://github.com/Linuxinet/JWT-Attack-Exploits
GitHub
GitHub - Linuxinet/JWT-Attack-Exploits: Codes and blogs for JWT vulnerabilities
Codes and blogs for JWT vulnerabilities . Contribute to Linuxinet/JWT-Attack-Exploits development by creating an account on GitHub.
👾KEYWORD SERVICE 🏷#exploit
Name: e2e-dotnet-e2e-demo-sqqf-exploit-train
Github: https://github.com/redhat-appstudio-qe/e2e-dotnet-e2e-demo-sqqf-exploit-train
Name: e2e-dotnet-e2e-demo-sqqf-exploit-train
Github: https://github.com/redhat-appstudio-qe/e2e-dotnet-e2e-demo-sqqf-exploit-train
GitHub
GitHub - redhat-appstudio-qe/e2e-dotnet-e2e-demo-sqqf-exploit-train: GitOps Repository
GitOps Repository. Contribute to redhat-appstudio-qe/e2e-dotnet-e2e-demo-sqqf-exploit-train development by creating an account on GitHub.
👾CVE SERVICE 🏷#CVE
Mumber: CVE-2022-39196
Github: https://github.com/DayiliWaseem/CVE-2022-39196-
Describe:
**
Mumber: CVE-2022-39196
Github: https://github.com/DayiliWaseem/CVE-2022-39196-
Describe:
**
GitHub
GitHub - DayiliWaseem/CVE-2022-39196-: Black board CMS Escalation of Privileges
Black board CMS Escalation of Privileges. Contribute to DayiliWaseem/CVE-2022-39196- development by creating an account on GitHub.