👾CVE SERVICE 🏷#CVE
Mumber: CVE-2022-24780
Github: https://github.com/Acceis/exploit-CVE-2022-24780
Describe:
Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.6 and 3.0.0, users of the iTop user portal can send TWIG code to the server by forging specific http queries, and execute arbitrary code on the server using http server user privileges. This issue is fixed in versions 2.7.6 and 3.0.0. There are currently no known workarounds.
Mumber: CVE-2022-24780
Github: https://github.com/Acceis/exploit-CVE-2022-24780
Describe:
Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.6 and 3.0.0, users of the iTop user portal can send TWIG code to the server by forging specific http queries, and execute arbitrary code on the server using http server user privileges. This issue is fixed in versions 2.7.6 and 3.0.0. There are currently no known workarounds.
GitHub
GitHub - Acceis/exploit-CVE-2022-24780: iTop < 2.7.6 - (Authenticated) Remote command execution
iTop < 2.7.6 - (Authenticated) Remote command execution - Acceis/exploit-CVE-2022-24780
👾KEYWORD SERVICE 🏷#exploit
Name: JWT-Attack-Exploits
Github: https://github.com/Linuxinet/JWT-Attack-Exploits
Name: JWT-Attack-Exploits
Github: https://github.com/Linuxinet/JWT-Attack-Exploits
GitHub
GitHub - Linuxinet/JWT-Attack-Exploits: Codes and blogs for JWT vulnerabilities
Codes and blogs for JWT vulnerabilities . Contribute to Linuxinet/JWT-Attack-Exploits development by creating an account on GitHub.
👾KEYWORD SERVICE 🏷#exploit
Name: e2e-dotnet-e2e-demo-sqqf-exploit-train
Github: https://github.com/redhat-appstudio-qe/e2e-dotnet-e2e-demo-sqqf-exploit-train
Name: e2e-dotnet-e2e-demo-sqqf-exploit-train
Github: https://github.com/redhat-appstudio-qe/e2e-dotnet-e2e-demo-sqqf-exploit-train
GitHub
GitHub - redhat-appstudio-qe/e2e-dotnet-e2e-demo-sqqf-exploit-train: GitOps Repository
GitOps Repository. Contribute to redhat-appstudio-qe/e2e-dotnet-e2e-demo-sqqf-exploit-train development by creating an account on GitHub.
👾CVE SERVICE 🏷#CVE
Mumber: CVE-2022-39196
Github: https://github.com/DayiliWaseem/CVE-2022-39196-
Describe:
**
Mumber: CVE-2022-39196
Github: https://github.com/DayiliWaseem/CVE-2022-39196-
Describe:
**
GitHub
GitHub - DayiliWaseem/CVE-2022-39196-: Black board CMS Escalation of Privileges
Black board CMS Escalation of Privileges. Contribute to DayiliWaseem/CVE-2022-39196- development by creating an account on GitHub.
👾KEYWORD SERVICE 🏷#exploit
Name: Web-Exploitation-Tools
Github: https://github.com/SolitudePy/Web-Exploitation-Tools
Name: Web-Exploitation-Tools
Github: https://github.com/SolitudePy/Web-Exploitation-Tools
GitHub
GitHub - SolitudePy/Web-Exploitation-Tools: A repository that contains some cool web exploitation automatic tools
A repository that contains some cool web exploitation automatic tools - GitHub - SolitudePy/Web-Exploitation-Tools: A repository that contains some cool web exploitation automatic tools
👾KEYWORD SERVICE 🏷#exploit
Name: Exploit-Development-Tools
Github: https://github.com/mgeeky/Exploit-Development-Tools
Name: Exploit-Development-Tools
Github: https://github.com/mgeeky/Exploit-Development-Tools
GitHub
GitHub - mgeeky/Exploit-Development-Tools: A bunch of my exploit development helper tools, collected in one place.
A bunch of my exploit development helper tools, collected in one place. - mgeeky/Exploit-Development-Tools
👾KEYWORD SERVICE 🏷#exploit
Name: build-suite-test-application-rdmb-build-e2e-usme-fulfil-exploit
Github: https://github.com/redhat-appstudio-qe/build-suite-test-application-rdmb-build-e2e-usme-fulfil-exploit
Name: build-suite-test-application-rdmb-build-e2e-usme-fulfil-exploit
Github: https://github.com/redhat-appstudio-qe/build-suite-test-application-rdmb-build-e2e-usme-fulfil-exploit
GitHub
GitHub - redhat-appstudio-qe/build-suite-test-application-rdmb-build-e2e-usme-fulfil-exploit: GitOps Repository
GitOps Repository. Contribute to redhat-appstudio-qe/build-suite-test-application-rdmb-build-e2e-usme-fulfil-exploit development by creating an account on GitHub.
👾CVE SERVICE 🏷#CVE
Mumber: CVE-2022-23131
Github: https://github.com/Vulnmachines/Zabbix-CVE-2022-23131
Describe:
In the case of instances where the SAML SSO authentication is enabled (non-default), session data can be modified by a malicious actor, because a user login stored in the session was not verified. Malicious unauthenticated actor may exploit this issue to escalate privileges and gain admin access to Zabbix Frontend. To perform the attack, SAML authentication is required to be enabled and the actor has to know the username of Zabbix user (or use the guest account, which is disabled by default).
Mumber: CVE-2022-23131
Github: https://github.com/Vulnmachines/Zabbix-CVE-2022-23131
Describe:
In the case of instances where the SAML SSO authentication is enabled (non-default), session data can be modified by a malicious actor, because a user login stored in the session was not verified. Malicious unauthenticated actor may exploit this issue to escalate privileges and gain admin access to Zabbix Frontend. To perform the attack, SAML authentication is required to be enabled and the actor has to know the username of Zabbix user (or use the guest account, which is disabled by default).
GitHub
GitHub - Vulnmachines/Zabbix-CVE-2022-23131: Zabbix-SAML-Bypass: CVE-2022-23131
Zabbix-SAML-Bypass: CVE-2022-23131. Contribute to Vulnmachines/Zabbix-CVE-2022-23131 development by creating an account on GitHub.