Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update CVE-2023-27524.yaml #7654

Merged
merged 1 commit into from
Jul 10, 2023
Merged

Update CVE-2023-27524.yaml #7654

merged 1 commit into from
Jul 10, 2023

Conversation

E1A
Copy link
Contributor

@E1A E1A commented Jul 10, 2023

Template / PR Information

This vulnerability lays in the standard SECRET_KEY, with this secret key you can forge your own cookies to login as an admin. The only problem with the original script is that most of the cookies don't work. I've changed these cookies with this PR so that they work. I've added a screenshot where nuclei_yaml includes my cookies and org_nulei.yaml is the original script, I've tested this on a few vulnerable hosts and as you can see in the screenshots it has more hits.

Template Validation

I've validated this template locally?

  • YES
  • NO

ss

@ritikchaddha ritikchaddha added the good first issue Good for newcomers label Jul 10, 2023
@ritikchaddha ritikchaddha self-assigned this Jul 10, 2023
@ritikchaddha ritikchaddha added the Done Ready to merge label Jul 10, 2023
@ritikchaddha
Copy link
Contributor

Hello @E1A, We appreciate your efforts in updating the template and making it more suitable, Your contribution has been truly valuable to us. Cheers! 🍻

You can join our discord server. It's a great place to connect with fellow contributors and stay updated with the latest developments. Thank you once again

@ritikchaddha ritikchaddha merged commit 6474aae into projectdiscovery:main Jul 10, 2023
3 checks passed
@E1A
Copy link
Contributor Author

E1A commented Jul 10, 2023

Thanks! Already joined the discord and has very helpfull so far. Was this pr eligible with the defcon31 contest? Or was the pr only the bonus point

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Done Ready to merge good first issue Good for newcomers
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants