#漏洞 RCE Exploit in BIG-IP.
CVE-2021-22986, CVE-2021-22987
python f5_rce.py -u https://ip_target
python f5_rce.py -f ip_list.txt
python f5_rce.py -c "$commend"
https://github.com/h4x0r-dz/RCE-Exploit-in-BIG-IP
CVE-2021-22986, CVE-2021-22987
python f5_rce.py -u https://ip_target
python f5_rce.py -f ip_list.txt
python f5_rce.py -c "$commend"
https://github.com/h4x0r-dz/RCE-Exploit-in-BIG-IP
GitHub
GitHub - h4x0r-dz/RCE-Exploit-in-BIG-IP
Contribute to h4x0r-dz/RCE-Exploit-in-BIG-IP development by creating an account on GitHub.
#工具 Lazyrecon是一个子域发现工具,可发现并解析有效的子域并执行SSRF / LFI / SQLi模糊测试。它具有简单的模块化体系结构,并针对与Wayback机器一起使用时的速度进行了优化。
https://github.com/storenth/lazyrecon/
https://github.com/storenth/lazyrecon/
GitHub
GitHub - storenth/lazyrecon: Wicked sick v2.0 script is intended to automate your reconnaissance process in an organized fashion.
Wicked sick v2.0 script is intended to automate your reconnaissance process in an organized fashion. - storenth/lazyrecon
#漏洞 MessageSolution 企业邮件归档管理系统信息泄露漏洞 CNVD-2021-10543
https://mp.weixin.qq.com/s/jehAIIYWrpkLtGvGN-LtFA
https://mp.weixin.qq.com/s/jehAIIYWrpkLtGvGN-LtFA
Weixin Official Accounts Platform
(CNVD-2021-10543)|MessageSolution 企业邮件归档管理系统 EEA 存在信息泄露漏洞
0x01 漏洞说明MessageSolution企业邮件归档管理系统 EEA是北京易讯思达科技开发有限公司开
#bountytip 403 Forbidden Page Bypass — Rare Exploitation of frequently seen Vulnerability
https://uduthalavankumar.medium.com/403-forbidden-page-bypass-rare-exploitation-of-frequently-seen-vulnerability-ee16c434add7
https://uduthalavankumar.medium.com/403-forbidden-page-bypass-rare-exploitation-of-frequently-seen-vulnerability-ee16c434add7
#漏洞 Adobe ColdFusion 远程代码执行漏洞(CVE-2021-21087)
https://github.com/projectdiscovery/nuclei-templates/pull/1128/files
https://github.com/projectdiscovery/nuclei-templates/pull/1128/files
GitHub
Added CVE-2021-21087 by Daviey · Pull Request #1128 · projectdiscovery/nuclei-templates
Vulnerability in Adobe ColdFusion which is improper input
validation which leads to arbitrary code execution.
Signed-off-by: Dave Walker (Daviey) email@daviey.com
validation which leads to arbitrary code execution.
Signed-off-by: Dave Walker (Daviey) email@daviey.com
#漏洞 [CVE-2021-21123] Google Chrome Bug Bounty $5.000 File System Access API - vulnerabilities
https://github.com/Puliczek/CVE-2021-21123-PoC-Google-Chrome
https://github.com/Puliczek/CVE-2021-21123-PoC-Google-Chrome
GitHub
GitHub - Puliczek/CVE-2021-21123-PoC-Google-Chrome: 🐱💻 👍 Google Chrome - File System Access API - vulnerabilities reported by…
🐱💻 👍 Google Chrome - File System Access API - vulnerabilities reported by Maciej Pulikowski | Total Bug Bounty Reward: $5.000 | CVE-2021-21123 and 5 more... - Puliczek/CVE-2021-21123-PoC-Google-Ch...
#漏洞 MobileIron MDM Contains Static Key Allowing Account Enumeration
https://www.optiv.com/explore-optiv-insights/source-zero/mobileiron-mdm-contains-static-key-allowing-account-enumeration
https://www.optiv.com/explore-optiv-insights/source-zero/mobileiron-mdm-contains-static-key-allowing-account-enumeration
Optiv
MobileIron MDM Contains Static Key Allowing Account Enumeration
MobileIron MDM exposes account enumeration and SFA to unauthenticated attacks. This analysis details how to mitigate this vulnerability.