CVE HUB ๐Ÿ‘พ
789 subscribers
19.3K links
Github Red team resource push
Github ็บข้˜Ÿ่ต„ๆบๆŽจ้€
Cve/Rce/Exploit/Redteam/ๆผๆดžๅˆฉ็”จ/็บข้˜Ÿ

Channel push 24/7 (real time)
้ข‘้“ๅ…จๅคฉๅ€™ๆŽจ้€(ๅฎžๆ—ถ)
Download Telegram
๐Ÿ‘พKEYWORD SERVICE ๐Ÿท#exploit
Name: Akebi-GC
Github: https://github.com/Akebi-Group/Akebi-GC
๐Ÿ‘พKEYWORD SERVICE ๐Ÿท#exploit
Name: CTF-Solutions
Github: https://github.com/DragonTechRoyale/CTF-Solutions
๐Ÿ‘พCVE SERVICE ๐Ÿท#CVE
Mumber: CVE-2022-31138
Github: https://github.com/ly1g3/Mailcow-CVE-2022-31138
Describe:
mailcow is a mailserver suite. Prior to mailcow-dockerized version 2022-06a, an extended privilege vulnerability can be exploited by manipulating the custom parameters regexmess, skipmess, regexflag, delete2foldersonly, delete2foldersbutnot, regextrans2, pipemess, or maxlinelengthcmd to execute arbitrary code. Users should update their mailcow instances with the `update.sh` script in the mailcow root directory to 2022-06a or newer to receive a patch for this issue. As a temporary workaround, the Syncjob ACL can be removed from all mailbox users, preventing changes to those settings.
๐Ÿ‘พCVE SERVICE ๐Ÿท#CVE
Mumber: CVE-2022-31245
Github: https://github.com/ly1g3/Mailcow-CVE-2022-31245
Describe:
mailcow before 2022-05d allows a remote authenticated user to inject OS commands and escalate privileges to domain admin via the --debug option in conjunction with the ---PIPEMESS option in Sync Jobs.