diff --git a/addons/index.html b/addons/index.html index 03fb373195..fbf165decb 100644 --- a/addons/index.html +++ b/addons/index.html @@ -180,7 +180,7 @@
-
+
@@ -193,7 +193,7 @@ | Tag | +Link | +
|---|---|
| Remote Code Execution (React2Shell) | ++ |
| Tag | +Link | +
|---|---|
| Remote Code Execution (React2Shell) | ++ |
Alert ID: 6.
+This rule identifies servers running vulnerable versions of React Server Components with Next.js, which will allow remote attackers to execute arbitrary code.
+The rule is based on the PoC detailed on https://slcyber.io/research-center/high-fidelity-detection-mechanism-for-rsc-next-js-rce-cve-2025-55182-cve-2025-66478/.
+It verifies that the server is running vulnerable React Server Components with Next.js, and that the remote code execution (RCE) vulnerability is present without causing any damage. +It forces an error via a malformed multipart request and checks for the presence of a string which confirms RCE is possible.
+Latest code: React2ShellScanRule.java
+Alert ID: 40048.
+Detect CVE-2012-1823 to perform Remote Code Execution on a PHP-CGI based web server.
Latest code: RemoteCodeExecutionCve20121823ScanRule.java
diff --git a/docs/sbom/ascanrules/index.html b/docs/sbom/ascanrules/index.html index e86fb62110..4fae835fcf 100644 --- a/docs/sbom/ascanrules/index.html +++ b/docs/sbom/ascanrules/index.html @@ -122,9 +122,9 @@This page contains a list of all the libraries involved in building version 75 of the
+
This page contains a list of all the libraries involved in building version 77 of the
"Active scanner rules" add-on.
-
You may download the full Software Bill Of Materials (SBOM) JSON file +
You may download the full Software Bill Of Materials (SBOM) JSON file for this add-on.
| bcmail-jdk18on | -1.77 | +1.83 | Bouncy Castle Licence |
| bcpkix-jdk18on | -1.77 | +1.83 | Bouncy Castle Licence |
| bcprov-jdk18on | -1.77 | +1.83 | Bouncy Castle Licence |
| bcutil-jdk18on | -1.77 | +1.83 | Bouncy Castle Licence |
| commons-io | -2.20.0 | +2.21.0 | Apache-2.0 |
| flyway-core | -11.15.0 | +11.18.0 | Apache-2.0 |
| flyway-database-hsqldb | -11.15.0 | +11.18.0 | Apache-2.0 |
| graaljs | -0.11.0 | +0.12.0 | |
| lombok | -1.18.40 | +1.18.42 | MIT |
| network | -0.24.0 | +0.25.0 | |
| oast | -0.23.0 | +0.24.0 | UPL-1.0 | +
| rhino | +1.8.0 | +MPL-2.0 | +|
| rsyntaxtextarea | 3.5.3 | @@ -1043,7 +1049,7 @@||
| sqlite-jdbc | -3.50.3.0 | +3.51.1.0 | Apache-2.0 | - 162 + 163 | diff --git a/docs/team/psiinon/index.html b/docs/team/psiinon/index.html index 2937aa9abb..933e496659 100644 --- a/docs/team/psiinon/index.html +++ b/docs/team/psiinon/index.html @@ -205,7 +205,7 @@
| Technology | +
|---|
| Remote Code Execution (React2Shell) | +
| Technology | +
|---|
| Remote Code Execution (React2Shell) | +