Skip to content

记录在漏洞复现/研究过程中编写的 Poc/Exp

Notifications You must be signed in to change notification settings

dudek-marcin/Poc-Exp

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

24 Commits
 
 

Repository files navigation

Poc-Exp

记录在漏洞复现/研究过程中编写的 PoC/Exp

# Poc框架
pocsuite3

Apache Flink

Citrix

  • 🎯 cve-2020-8209(Citrix XenMobile 目录遍历/任意文件读取漏洞)

Confluence

  • 🎯 cve-2019-3396(Atlassian Confluence 路径穿越漏洞)

Eyou(亿邮)

  • 🎯 wooyun-2013-028987
  • 🎯 wooyun-2014-056245
  • 🎯 wooyun-2014-058301(亿邮 命令执行漏洞-storage_explore.php)
  • 🎯 wooyun-2014-061538(亿邮 敏感信息泄漏漏洞-sysinfo.html)
  • 🎯 wooyun-2014-070551
  • 🎯 wooyun-2014-072314(亿邮 SQL注入漏洞-print_addfeelog.php)
  • 🎯 wooyun-2015-0101419
  • 🎯 wooyun-2015-0135406

Lanproxy

Jboss

Phpstudy

Resin

  • 🎯 cve-2006-1953(Resin Windows 目录遍历漏洞-/C:%5C/)
  • 🎯 cve-2006-2437(Resin 任意文件读取漏洞-viewfile)
  • 🎯 cnnvd-200705-315(Resin Windows %20 目录遍历漏洞-/%20../web-inf/)
  • 🎯 cve-xxx-xxxx(Resin 任意文件读取漏洞-inputFile)
  • 🎯 cve-xxx-xxxx(Resin SSRF漏洞-inputFile)

Spring

  • 🎯 cve-xxxx-xxxx(SpringBoot Actuator未授权访问漏洞)
  • 🎯 cve-2018-1271(Spring MVC目录穿越/遍历漏洞)
  • 🎯 cve-2019-3799(Spring Cloud Config Server 路径穿越/任意文件读取漏洞)
  • 🎯 cve-2020-5405(Spring Cloud Config Server路径遍历漏洞)
  • 🎯 cve-2020-5410(Spring Cloud Config目录穿越/遍历漏洞)
  • 🎯 cve-2020-5412(Spring Cloud Netflix Hystrix Dashboard SSRF漏洞-proxy.stream) 2021-01-07

Thinkadmin

  • 🎯 cve-2020-25540(thinkadmin 目录遍历/任意文件读取漏洞)
  • 🎯 cnvd-2020-33163
  • 🎯 微擎 v0.7 SQL注入漏洞-notify.php 2021-01-08

Weaver(泛微)

Webmin

Yonyou(用友)

  • 🎯 cnvd-2020-49261(用友GRP-U8 XXE漏洞-xp_cmdshell)
  • 🎯 禅知Pro v1.6 前台任意文件读取漏洞-file.php?pathname= 2021-01-08

About

记录在漏洞复现/研究过程中编写的 Poc/Exp

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages