👾CVE SERVICE 🏷#CVE
Mumber: CVE-2022-38374
Github: https://github.com/azhurtanov/CVE-2022-38374
Describe:
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiADC 7.0.0 - 7.0.2 and 6.2.0 - 6.2.4 allows an attacker to execute unauthorized code or commands via the URL and User fields observed in the traffic and event logviews.
Mumber: CVE-2022-38374
Github: https://github.com/azhurtanov/CVE-2022-38374
Describe:
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiADC 7.0.0 - 7.0.2 and 6.2.0 - 6.2.4 allows an attacker to execute unauthorized code or commands via the URL and User fields observed in the traffic and event logviews.
GitHub
GitHub - azhurtanov/CVE-2022-38374
Contribute to azhurtanov/CVE-2022-38374 development by creating an account on GitHub.
👾CVE SERVICE 🏷#CVE
Mumber: CVE-2022-2650
Github: https://github.com/HackinKraken/CVE-2022-2650
Describe:
Improper Restriction of Excessive Authentication Attempts in GitHub repository wger-project/wger prior to 2.2.
Mumber: CVE-2022-2650
Github: https://github.com/HackinKraken/CVE-2022-2650
Describe:
Improper Restriction of Excessive Authentication Attempts in GitHub repository wger-project/wger prior to 2.2.
👾CVE SERVICE 🏷#CVE
Mumber: CVE-2022-22971
Github: https://github.com/tchize/CVE-2022-22971
Describe:
In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.
Mumber: CVE-2022-22971
Github: https://github.com/tchize/CVE-2022-22971
Describe:
In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.
GitHub
GitHub - tchize/CVE-2022-22971
Contribute to tchize/CVE-2022-22971 development by creating an account on GitHub.
** fscan ** 🔧Tool update
Tools name:fscan
Tools url:https://github.com/shadow1ng/fscan/commit/27c7e3977e6a2c412db7c6c452095075eb3d696c
commitUpdate log:
修改文件保存路径设置
Tools name:fscan
Tools url:https://github.com/shadow1ng/fscan/commit/27c7e3977e6a2c412db7c6c452095075eb3d696c
commitUpdate log:
修改文件保存路径设置
GitHub
修改文件保存路径设置 · shadow1ng/fscan@27c7e39
一款内网综合扫描工具,方便一键自动化、全方位漏扫扫描。. Contribute to shadow1ng/fscan development by creating an account on GitHub.
** Behinder ** 🔧Tool update
Tools name:Behinder
Tools url:https://github.com/rebeyond/Behinder/releases/tag/Behinder_v4.0.6
Update log:
### 2022.11.28 v4.0.6 更新日志
1.修复了Tomcat10中内存马植入无法连接的问题;
2.修复了asp版本内置传输协议的连接问题;
3.修复了传输协议在恢复默认时会出现错误的问题;
4.内置了Javafx库,修复了各类因为Javafx环境无法运行的问题;
5.修复了客户端兼容性问题,客户端兼容Java8至Java19;
6.新增“默认”连接模式,兼容冰蝎3默认服务端;
7.其他的一些优化。
Tools name:Behinder
Tools url:https://github.com/rebeyond/Behinder/releases/tag/Behinder_v4.0.6
Update log:
### 2022.11.28 v4.0.6 更新日志
1.修复了Tomcat10中内存马植入无法连接的问题;
2.修复了asp版本内置传输协议的连接问题;
3.修复了传输协议在恢复默认时会出现错误的问题;
4.内置了Javafx库,修复了各类因为Javafx环境无法运行的问题;
5.修复了客户端兼容性问题,客户端兼容Java8至Java19;
6.新增“默认”连接模式,兼容冰蝎3默认服务端;
7.其他的一些优化。
GitHub
Release Behinder_v4.0.6 · rebeyond/Behinder
2022.11.28 v4.0.6 更新日志
1.修复了Tomcat10中内存马植入无法连接的问题;
2.修复了asp版本内置传输协议的连接问题;
3.修复了传输协议在恢复默认时会出现错误的问题;
4.内置了Javafx库,修复了各类因为Javafx环境无法运行的问题;
5.修复了客户端兼容性问题,客户端兼容Java8至Java19;
6.新增“默认”连接模式,兼容冰蝎3默认服务端;
7.其...
1.修复了Tomcat10中内存马植入无法连接的问题;
2.修复了asp版本内置传输协议的连接问题;
3.修复了传输协议在恢复默认时会出现错误的问题;
4.内置了Javafx库,修复了各类因为Javafx环境无法运行的问题;
5.修复了客户端兼容性问题,客户端兼容Java8至Java19;
6.新增“默认”连接模式,兼容冰蝎3默认服务端;
7.其...
👾CVE SERVICE 🏷#CVE
Mumber: CVE-2022-41413
Github: https://github.com/renmizo/CVE-2022-41413
Describe:
**
Mumber: CVE-2022-41413
Github: https://github.com/renmizo/CVE-2022-41413
Describe:
**
GitHub
GitHub - renmizo/CVE-2022-41413
Contribute to renmizo/CVE-2022-41413 development by creating an account on GitHub.
👾CVE SERVICE 🏷#CVE
Mumber: CVE-2022-41412
Github: https://github.com/renmizo/CVE-2022-41412
Describe:
**
Mumber: CVE-2022-41412
Github: https://github.com/renmizo/CVE-2022-41412
Describe:
**
GitHub
GitHub - renmizo/CVE-2022-41412
Contribute to renmizo/CVE-2022-41412 development by creating an account on GitHub.
👾CVE SERVICE 🏷#CVE
Mumber: CVE-2022-43369
Github: https://github.com/sudoninja-noob/CVE-2022-43369
Describe:
**
Mumber: CVE-2022-43369
Github: https://github.com/sudoninja-noob/CVE-2022-43369
Describe:
**
GitHub
GitHub - sudoninja-noob/CVE-2022-43369
Contribute to sudoninja-noob/CVE-2022-43369 development by creating an account on GitHub.
👾CVE SERVICE 🏷#CVE
Mumber: CVE-2022-45217
Github: https://github.com/sudoninja-noob/CVE-2022-45217
Describe:
**
Mumber: CVE-2022-45217
Github: https://github.com/sudoninja-noob/CVE-2022-45217
Describe:
**
GitHub
GitHub - sudoninja-noob/CVE-2022-45217
Contribute to sudoninja-noob/CVE-2022-45217 development by creating an account on GitHub.
** mimikatz ** 🔧Tool update
Tools name:mimikatz
Tools url:https://github.com/gentilkiwi/mimikatz/commit/c78b1cf37c517ae9d0e872447bb103da9fa6034a
commitUpdate log:
Revert to Visual Studio 2013 (due to an error in Microsoft headers, can't build in Win32)
Tools name:mimikatz
Tools url:https://github.com/gentilkiwi/mimikatz/commit/c78b1cf37c517ae9d0e872447bb103da9fa6034a
commitUpdate log:
Revert to Visual Studio 2013 (due to an error in Microsoft headers, can't build in Win32)
GitHub
Revert to Visual Studio 2013 (due to an error in Microsoft headers, c… · gentilkiwi/mimikatz@c78b1cf
…an't build in Win32)
👾CVE SERVICE 🏷#CVE
Mumber: CVE-2022-34721
Github: https://github.com/sandpix/CVE-2022-34721-RCE-POC
Describe:
Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-34722.
Mumber: CVE-2022-34721
Github: https://github.com/sandpix/CVE-2022-34721-RCE-POC
Describe:
Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-34722.
** fscan ** 🔧Tool update
Tools name:fscan
Tools url:https://github.com/shadow1ng/fscan/commit/6c6f522bc9c9167df0d291332c1baea316f13161
commitUpdate log:
修改文件保存路径设置
Tools name:fscan
Tools url:https://github.com/shadow1ng/fscan/commit/6c6f522bc9c9167df0d291332c1baea316f13161
commitUpdate log:
修改文件保存路径设置
GitHub
修改文件保存路径设置 · shadow1ng/fscan@6c6f522
一款内网综合扫描工具,方便一键自动化、全方位漏扫扫描。. Contribute to shadow1ng/fscan development by creating an account on GitHub.
👾CVE SERVICE 🏷#CVE
Mumber: CVE-2022-41049
Github: https://github.com/NathanScottGithub/CVE-2022-41049-POC
Describe:
Windows Mark of the Web Security Feature Bypass Vulnerability. This CVE ID is unique from CVE-2022-41091.
Mumber: CVE-2022-41049
Github: https://github.com/NathanScottGithub/CVE-2022-41049-POC
Describe:
Windows Mark of the Web Security Feature Bypass Vulnerability. This CVE ID is unique from CVE-2022-41091.
GitHub
GitHub - Nathan01110011/CVE-2022-41049-POC: POC of Microcorp vuln
POC of Microcorp vuln. Contribute to Nathan01110011/CVE-2022-41049-POC development by creating an account on GitHub.
👏1
👾CVE SERVICE 🏷#CVE
Mumber: CVE-2022-24491
Github: https://github.com/corelight/CVE-2022-24491
Describe:
Windows Network File System Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-24497.
Mumber: CVE-2022-24491
Github: https://github.com/corelight/CVE-2022-24491
Describe:
Windows Network File System Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-24497.
GitHub
GitHub - corelight/CVE-2022-24491: A Zeek CVE-2022-24491 detector.
A Zeek CVE-2022-24491 detector. Contribute to corelight/CVE-2022-24491 development by creating an account on GitHub.
👾CVE SERVICE 🏷#CVE
Mumber: CVE-2022-31007
Github: https://github.com/gscharf/CVE-2022-31007-Python-POC
Describe:
eLabFTW is an electronic lab notebook manager for research teams. Prior to version 4.3.0, a vulnerability allows an authenticated user with an administrator role in a team to assign itself system administrator privileges within the application, or create a new system administrator account. The issue has been corrected in eLabFTW version 4.3.0. In the context of eLabFTW, an administrator is a user account with certain privileges to manage users and content in their assigned team/teams. A system administrator account can manage all accounts, teams and edit system-wide settings within the application. The impact is not deemed as high, as it requires the attacker to have access to an administrator account. Regular user accounts cannot exploit this to gain admin rights. A workaround for one if the issues is removing the ability of administrators to create accounts.
Mumber: CVE-2022-31007
Github: https://github.com/gscharf/CVE-2022-31007-Python-POC
Describe:
eLabFTW is an electronic lab notebook manager for research teams. Prior to version 4.3.0, a vulnerability allows an authenticated user with an administrator role in a team to assign itself system administrator privileges within the application, or create a new system administrator account. The issue has been corrected in eLabFTW version 4.3.0. In the context of eLabFTW, an administrator is a user account with certain privileges to manage users and content in their assigned team/teams. A system administrator account can manage all accounts, teams and edit system-wide settings within the application. The impact is not deemed as high, as it requires the attacker to have access to an administrator account. Regular user accounts cannot exploit this to gain admin rights. A workaround for one if the issues is removing the ability of administrators to create accounts.
GitHub
GitHub - gscharf/CVE-2022-31007-Python-POC
Contribute to gscharf/CVE-2022-31007-Python-POC development by creating an account on GitHub.
👾CVE SERVICE 🏷#CVE
Mumber: CVE-2022-26265
Github: https://github.com/Inplex-sys/CVE-2022-26265
Describe:
Contao Managed Edition v1.5.0 was discovered to contain a remote command execution (RCE) vulnerability via the component php_cli parameter.
Mumber: CVE-2022-26265
Github: https://github.com/Inplex-sys/CVE-2022-26265
Describe:
Contao Managed Edition v1.5.0 was discovered to contain a remote command execution (RCE) vulnerability via the component php_cli parameter.
GitHub
GitHub - SystemVll/CVE-2022-26265: The first proof of concept of the Contao CMS RCE
The first proof of concept of the Contao CMS RCE. Contribute to SystemVll/CVE-2022-26265 development by creating an account on GitHub.
👾CVE SERVICE 🏷#CVE
Mumber: CVE-2022-43680
Github: https://github.com/nidhi7598/G3_expat-2.2.6_CVE-2022-43680
Describe:
In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations.
Mumber: CVE-2022-43680
Github: https://github.com/nidhi7598/G3_expat-2.2.6_CVE-2022-43680
Describe:
In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations.
👍1
👾CVE SERVICE 🏷#CVE
Mumber: CVE-2022-44721
Github: https://github.com/purplededa/CVE-2022-44721-CsFalconUninstaller
Describe:
**
Mumber: CVE-2022-44721
Github: https://github.com/purplededa/CVE-2022-44721-CsFalconUninstaller
Describe:
**
👾CVE SERVICE 🏷#CVE
Mumber: CVE-2022-24112
Github: https://github.com/Acczdy/CVE-2022-24112_POC
Describe:
An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default configuration of Apache APISIX (with default API key) is vulnerable to remote code execution. When the admin key was changed or the port of Admin API was changed to a port different from the data panel, the impact is lower. But there is still a risk to bypass the IP restriction of Apache APISIX's data panel. There is a check in the batch-requests plugin which overrides the client IP with its real remote IP. But due to a bug in the code, this check can be bypassed.
Mumber: CVE-2022-24112
Github: https://github.com/Acczdy/CVE-2022-24112_POC
Describe:
An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default configuration of Apache APISIX (with default API key) is vulnerable to remote code execution. When the admin key was changed or the port of Admin API was changed to a port different from the data panel, the impact is lower. But there is still a risk to bypass the IP restriction of Apache APISIX's data panel. There is a check in the batch-requests plugin which overrides the client IP with its real remote IP. But due to a bug in the code, this check can be bypassed.
GitHub
GitHub - Acczdy/CVE-2022-24112_POC: CVE-2022-24112_POC
CVE-2022-24112_POC. Contribute to Acczdy/CVE-2022-24112_POC development by creating an account on GitHub.