👾CVE SERVICE 🏷#CVE
Mumber: CVE-2022-31692
Github: https://github.com/SpindleSec/CVE-2022-31692
Describe:
Spring Security, versions 5.7 prior to 5.7.5 and 5.6 prior to 5.6.9 could be susceptible to authorization rules bypass via forward or include dispatcher types. Specifically, an application is vulnerable when all of the following are true: The application expects that Spring Security applies security to forward and include dispatcher types. The application uses the AuthorizationFilter either manually or via the authorizeHttpRequests() method. The application configures the FilterChainProxy to apply to forward and/or include requests (e.g. spring.security.filter.dispatcher-types = request, error, async, forward, include). The application may forward or include the request to a higher privilege-secured endpoint.The application configures Spring Security to apply to every dispatcher type via authorizeHttpRequests().shouldFilterAllDispatcherTypes(true)
Mumber: CVE-2022-31692
Github: https://github.com/SpindleSec/CVE-2022-31692
Describe:
Spring Security, versions 5.7 prior to 5.7.5 and 5.6 prior to 5.6.9 could be susceptible to authorization rules bypass via forward or include dispatcher types. Specifically, an application is vulnerable when all of the following are true: The application expects that Spring Security applies security to forward and include dispatcher types. The application uses the AuthorizationFilter either manually or via the authorizeHttpRequests() method. The application configures the FilterChainProxy to apply to forward and/or include requests (e.g. spring.security.filter.dispatcher-types = request, error, async, forward, include). The application may forward or include the request to a higher privilege-secured endpoint.The application configures Spring Security to apply to every dispatcher type via authorizeHttpRequests().shouldFilterAllDispatcherTypes(true)
GitHub
GitHub - blipzip/cve-2022-31692: A project demonstrating an app that is vulnerable to Spring Security authorization bypass CVE…
A project demonstrating an app that is vulnerable to Spring Security authorization bypass CVE-2022-31692 - blipzip/cve-2022-31692
👾CVE SERVICE 🏷#CVE
Mumber: CVE-2022-0185
Github: https://github.com/featherL/CVE-2022-0185-exploit
Describe:
A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel verified the supplied parameters length. An unprivileged (in case of unprivileged user namespaces enabled, otherwise needs namespaced CAP_SYS_ADMIN privilege) local user able to open a filesystem that does not support the Filesystem Context API (and thus fallbacks to legacy handling) could use this flaw to escalate their privileges on the system.
Mumber: CVE-2022-0185
Github: https://github.com/featherL/CVE-2022-0185-exploit
Describe:
A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel verified the supplied parameters length. An unprivileged (in case of unprivileged user namespaces enabled, otherwise needs namespaced CAP_SYS_ADMIN privilege) local user able to open a filesystem that does not support the Filesystem Context API (and thus fallbacks to legacy handling) could use this flaw to escalate their privileges on the system.
GitHub
GitHub - featherL/CVE-2022-0185-exploit: CVE-2022-0185 exploit
CVE-2022-0185 exploit. Contribute to featherL/CVE-2022-0185-exploit development by creating an account on GitHub.
👾KEYWORD SERVICE 🏷#exploit
Name: Lightning-Network
Github: https://github.com/davidshares/Lightning-Network
Name: Lightning-Network
Github: https://github.com/davidshares/Lightning-Network
GitHub
GitHub - davidshares/Lightning-Network: List of Lightning Network technical issues, bugs, flaws, and exploits.
List of Lightning Network technical issues, bugs, flaws, and exploits. - davidshares/Lightning-Network
👾KEYWORD SERVICE 🏷#sql_injection
Name: COMP421A_IC_Assignment1
Github: https://github.com/maq796113/COMP421A_IC_Assignment1
Name: COMP421A_IC_Assignment1
Github: https://github.com/maq796113/COMP421A_IC_Assignment1
GitHub
maq796113/COMP421A_IC_Assignment1
SQL Injection. Contribute to maq796113/COMP421A_IC_Assignment1 development by creating an account on GitHub.
👾KEYWORD SERVICE 🏷#sql_injection
Name: ADO_SQL_Injection_Prevention
Github: https://github.com/ameybawane/ADO_SQL_Injection_Prevention
Name: ADO_SQL_Injection_Prevention
Github: https://github.com/ameybawane/ADO_SQL_Injection_Prevention
GitHub
GitHub - ameybawane/ADO_SQL_Injection_Prevention
Contribute to ameybawane/ADO_SQL_Injection_Prevention development by creating an account on GitHub.
👾KEYWORD SERVICE 🏷#exploit
Name: Silent-Doc-Exploit-Python
Github: https://github.com/RobertDEVx/Silent-Doc-Exploit-Python
Name: Silent-Doc-Exploit-Python
Github: https://github.com/RobertDEVx/Silent-Doc-Exploit-Python
GitHub
GitHub - RobertDEVx/Silent-Doc-Exploit-Python: Silent doc exploit
Silent doc exploit. Contribute to RobertDEVx/Silent-Doc-Exploit-Python development by creating an account on GitHub.
👾KEYWORD SERVICE 🏷#exploit
Name: Sentinel-Remake-krnl-api-
Github: https://github.com/EatingCowsIsHaram/Sentinel-Remake-krnl-api-
Name: Sentinel-Remake-krnl-api-
Github: https://github.com/EatingCowsIsHaram/Sentinel-Remake-krnl-api-
GitHub
EatingCowsIsHaram/Sentinel-Remake-krnl-api-
I did not create or own the UI itself, All I did was fix a decompiled source and added krnl api to get it to work again. I'll be the source code of a older version or I'll make the ...
👾KEYWORD SERVICE 🏷#exploit
Name: Sentinel-Remake
Github: https://github.com/EatingCowsIsHaram/Sentinel-Remake
Name: Sentinel-Remake
Github: https://github.com/EatingCowsIsHaram/Sentinel-Remake
GitHub
GitHub - EatingCowsIsHaram/Sentinel-Remake: I did not create or own the UI itself, All I did was fix a decompiled source and added…
I did not create or own the UI itself, All I did was fix a decompiled source and added krnl api to get it to work again. I'll be the source code of a older version or I'll make the ...
👾CVE SERVICE 🏷#CVE
Mumber: CVE-2022-33079
Github: https://github.com/Bdenneu/CVE-2022-33079
Describe:
**
Mumber: CVE-2022-33079
Github: https://github.com/Bdenneu/CVE-2022-33079
Describe:
**
GitHub
GitHub - Bdenneu/CVE-2022-33679: One day based on https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html
One day based on https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html - GitHub - Bdenneu/CVE-2022-33679: One day based on https://googleprojectzero.blogspot.com/2022/...
👾KEYWORD SERVICE 🏷#exploit
Name: -uXBk7-resolve-exploit
Github: https://github.com/redhat-appstudio-appdata/-uXBk7-resolve-exploit
Name: -uXBk7-resolve-exploit
Github: https://github.com/redhat-appstudio-appdata/-uXBk7-resolve-exploit
GitHub
redhat-appstudio-appdata/-uXBk7-resolve-exploit
GitOps Repository. Contribute to redhat-appstudio-appdata/-uXBk7-resolve-exploit development by creating an account on GitHub.