#bountytip 403 Forbidden Page Bypass — Rare Exploitation of frequently seen Vulnerability
https://uduthalavankumar.medium.com/403-forbidden-page-bypass-rare-exploitation-of-frequently-seen-vulnerability-ee16c434add7
https://uduthalavankumar.medium.com/403-forbidden-page-bypass-rare-exploitation-of-frequently-seen-vulnerability-ee16c434add7
#漏洞 Adobe ColdFusion 远程代码执行漏洞(CVE-2021-21087)
https://github.com/projectdiscovery/nuclei-templates/pull/1128/files
https://github.com/projectdiscovery/nuclei-templates/pull/1128/files
GitHub
Added CVE-2021-21087 by Daviey · Pull Request #1128 · projectdiscovery/nuclei-templates
Vulnerability in Adobe ColdFusion which is improper input
validation which leads to arbitrary code execution.
Signed-off-by: Dave Walker (Daviey) email@daviey.com
validation which leads to arbitrary code execution.
Signed-off-by: Dave Walker (Daviey) email@daviey.com
#漏洞 [CVE-2021-21123] Google Chrome Bug Bounty $5.000 File System Access API - vulnerabilities
https://github.com/Puliczek/CVE-2021-21123-PoC-Google-Chrome
https://github.com/Puliczek/CVE-2021-21123-PoC-Google-Chrome
GitHub
GitHub - Puliczek/CVE-2021-21123-PoC-Google-Chrome: 🐱💻 👍 Google Chrome - File System Access API - vulnerabilities reported by…
🐱💻 👍 Google Chrome - File System Access API - vulnerabilities reported by Maciej Pulikowski | Total Bug Bounty Reward: $5.000 | CVE-2021-21123 and 5 more... - Puliczek/CVE-2021-21123-PoC-Google-Ch...
#漏洞 MobileIron MDM Contains Static Key Allowing Account Enumeration
https://www.optiv.com/explore-optiv-insights/source-zero/mobileiron-mdm-contains-static-key-allowing-account-enumeration
https://www.optiv.com/explore-optiv-insights/source-zero/mobileiron-mdm-contains-static-key-allowing-account-enumeration
Optiv
MobileIron MDM Contains Static Key Allowing Account Enumeration
MobileIron MDM exposes account enumeration and SFA to unauthenticated attacks. This analysis details how to mitigate this vulnerability.
#漏洞 CVE-2021-1732: win32kfull xxxCreateWindowEx callback out-of-bounds
https://iamelli0t.github.io/2021/03/25/CVE-2021-1732.html
https://iamelli0t.github.io/2021/03/25/CVE-2021-1732.html
iamelli0t’s blog
CVE-2021-1732: win32kfull xxxCreateWindowEx callback out-of-bounds
CVE-2021-1732 is a 0-Day vulnerability exploited by the BITTER APT organization in one operation which was disclosed in February this year[1][2][3]. This vulnerability exploits a user mode callback opportunity in win32kfull module to break the normal execution…
Hidden OAuth attack vectors
https://portswigger.net/research/hidden-oauth-attack-vectors
https://portswigger.net/research/hidden-oauth-attack-vectors
PortSwigger Research
Hidden OAuth attack vectors
Intro The OAuth2 authorization protocol has been under fire for the past ten years. You've probably already heard about plenty of "return_uri" tricks, token leakages, CSRF-style attacks on clients, an
#工具 OSINT tool to get information from a Github and Gitlab profile and find user's email addresses leaked on commits.
从Github或Gitlab配置文件中获取信息,并查找提交时泄露的用户电子邮件地址。
https://github.com/GONZOsint/gitrecon
从Github或Gitlab配置文件中获取信息,并查找提交时泄露的用户电子邮件地址。
https://github.com/GONZOsint/gitrecon
GitHub
GitHub - GONZOsint/gitrecon: OSINT tool to get information from a Github and Gitlab profile and find user's email addresses leaked…
OSINT tool to get information from a Github and Gitlab profile and find user's email addresses leaked on commits. - GONZOsint/gitrecon
#漏洞 Mybb associate CVE-2021-27890 & CVE-2021-27889 to RCE poc
https://github.com/xiaopan233/Mybb-XSS_SQL_RCE-POC
https://github.com/xiaopan233/Mybb-XSS_SQL_RCE-POC
GitHub
GitHub - xiaopan233/Mybb-XSS_SQL_RCE-POC: Mybb associate CVE-2021-27890 & CVE-2021-27889 to RCE poc
Mybb associate CVE-2021-27890 & CVE-2021-27889 to RCE poc - GitHub - xiaopan233/Mybb-XSS_SQL_RCE-POC: Mybb associate CVE-2021-27890 & CVE-2021-27889 to RCE poc