194 Commits

Author SHA1 Message Date
Medicean
e64faad6d9 (Update Vul: Spring) Spring Data REST PATCH请求代码执行漏洞(CVE-2017-8046)
删除原 jar 包中 mongodb 依赖
2017-09-29 13:08:50 +08:00
Medicean
21b9b4e30d (Add Vul: Spring) Spring Data REST PATCH请求代码执行漏洞(CVE-2017-8046) 2017-09-29 03:18:17 +08:00
Medicean
7e2ec8bb13 (Update Vul: Tomcat) Merge #13 thx @b1ueb0y
增加CVE-2017-12615利用脚本
2017-09-21 10:18:59 +08:00
b1ueb0y
c78e15fe96 增加CVE-2017-12615利用脚本 2017-09-21 09:54:33 +08:00
Medicean
a24343e39b (Add Vul: Tomcat) Tomcat 远程代码执行漏洞 (CVE-2017-12615) 2017-09-21 00:47:08 +08:00
Medicean
0f217f72ee (Update Vul: JBoss) 更新 JBoss 「Java 反序列化」过程远程命令执行漏洞README 2017-09-12 11:53:07 +08:00
Medicean
11f2e72495 (Add Vul: JBoss) JBoss 「Java 反序列化」过程远程命令执行漏洞(CVE-2015-8103) 2017-09-12 11:20:39 +08:00
Medicean
5629f0fac1 (Add Base: JBoss) as6 and as7 image 2017-09-12 11:19:52 +08:00
Medicean
e96bd7c312 (Update Vul: Struts2) 更新 S2-033、S2-devMode Exp 2017-09-09 16:16:15 +08:00
Medicean
15e7faace7 (Update Vul: Struts2) 更新 S2-037 Exp 2017-09-09 15:59:52 +08:00
Medicean
41a20c11d7 (Add Base: default) 添加默认镜像
$ docker run -i -t medicean/vulapps:latest
2017-09-09 15:36:30 +08:00
Medicean
83ce5c4933 更新致谢列表 Thx @b1ueb0y #12 2017-09-08 16:13:44 +08:00
Medicean
a35d9eab27 (Fix Vul: Struts2) 更新为可回显Exp #12 2017-09-08 16:06:09 +08:00
Medicean
e4e324d2e7 (Update Vul: Struts2) 新增S2-053 Exp 说明 2017-09-08 01:11:26 +08:00
Medicean
3ce5b6a521 (Add Vul: Struts2) Struts2 远程代码执行漏洞(S2-053) 2017-09-08 00:56:15 +08:00
Medicean
a5550df0b0 (Update Vul: Struts2) S2-052 添加修复方案 2017-09-06 14:41:18 +08:00
Medicean
2ddc9fc920 (Add Vul: Struts2) Struts2 XStreamHandler 远程代码执行漏洞(S2-052、 CVE-2017-9805)环境 2017-09-06 10:19:23 +08:00
Medicean
707a6f988a (Add Vul: SSH) SSH 命令注入漏洞(CVE-2017-1000117) 2017-08-13 02:54:47 +08:00
Medicean
4b35af325c (Update Base: lamp) 更换 apt 源 2017-08-13 01:44:26 +08:00
Medicean
f9934750ff (Update Vul: supervisor) 更新 CVE-2017-11610 说明 2017-07-28 13:12:49 +08:00
Medicean
6316fc69b9 (Update Vul: supervisor) 更新 CVE-2017-11610 说明
该 Exp 会导致 supervisord 进程退出,生产环境中请慎用
2017-07-28 09:39:15 +08:00
Medicean
7e0fb0860d (Add Vul: Supervisor) Remote Code Execution(CVE-2017-11610) 2017-07-28 00:41:04 +08:00
Medicean
a41d0a89ca (Update Tools: Hawkeye) 更新配置,增加邮件端口设置
已解决SMTP SSL问题
2017-07-19 09:40:07 +08:00
Medicean
e058392404 (Add Tools: Hawkeye) 新增 Hawkeye, Github 泄露监控系统 2017-07-18 12:19:34 +08:00
Medicean
5fc86ddea8 (Fix Vul: Nginx) 修复 index.html 中图片路径 2017-07-17 10:17:03 +08:00
Medicean
65617a8503 (Update Vul: Nginx) Nginx整数溢出漏洞 CVE-2017-7529 添加 PoC 2017-07-14 16:03:15 +08:00
Medicean
144ca258eb (Update Vul: Nginx) Nginx整数溢出漏洞 CVE-2017-7529 更新 README 2017-07-14 12:49:17 +08:00
Medicean
fab93315be (Update Vul: Nginx) Nginx整数溢出漏洞 CVE-2017-7529 使用说明 2017-07-14 11:52:57 +08:00
Medicean
e1818dfac9 (Add Vul: Nginx) Nginx整数溢出漏洞 (CVE-2017-7529) 2017-07-14 11:03:29 +08:00
Medicean
f01a02a3d2 (Update Vul: Struts2) 更新 s2-048.war struts-core 为 2.3.32
http://struts.apache.org/docs/version-notes-2332.html
2017-07-08 13:03:03 +08:00
Medicean
b984b4b09a (Add Vul: Struts2) Struts2-struts1-plugin 插件远程代码执行漏洞(S2-048) 2017-07-07 23:57:35 +08:00
Medicean
662798c6d8 (Add Vul: Drupal)Drupal PECL YAML parser 远程代码执行漏洞(CVE-2017-6920) 2017-06-29 22:32:22 +08:00
Medicean
a251366ed5 (fix Base: Drupal) fix config_directories 2017-06-29 21:41:04 +08:00
Medicean
1676f66abb (Add Base: Drupal) add Drupal 8.3.0 2017-06-29 20:21:52 +08:00
Medicean
86ee14f3b0 (Add Vul: FFmpeg) FFmpeg 文件读取漏洞(CVE-2017-9993) 2017-06-28 22:15:32 +08:00
Medicean
0b2590024d (Add Vul: Spring WebFlow) Spring WebFlow 远程代码执行漏洞(CVE-2017-4971) 2017-06-18 02:26:53 +08:00
Medicean
ca2caf7ad0 update .gitattributes 2017-06-17 12:11:21 +08:00
Medicean
20f838b535 (Update Tool: XunFeng) 直接使用官方仓库 2017-06-17 11:19:38 +08:00
Medicean
e658a3c037 (Update: README) 修正 wordpress 6 Exp 2017-06-17 01:48:06 +08:00
Medicean
ae62313f75 (Add Vul: WordPress) WordPress <= 4.6 命令执行漏洞(PHPMailer)(CVE-2016-10033) 2017-06-17 01:33:43 +08:00
Medicean
6c3dd7ad97 update struts2 index 2017-06-16 23:17:03 +08:00
undefined
27741e4ffa Thanks @zerokeeper 👍
For contributing struts2 vulnerable environments.

s2-001、s2-007、s2-008、s2-012、s2-013、s2-015、s2-016、s2-019、s2-029
2017-06-14 00:39:32 +08:00
undefined
f7ae374b12 Merge pull request #8 from zerokeeper/master
(Add Vul: struts2) 系列漏洞环境 

* s2-001
* s2-007
* s2-012
* s2-013
* s2-015
* s2-016
* s2-019
* s2-029
2017-06-13 18:44:00 +08:00
zerokeeper
d1c95be1b0 (Update Vul: Struts2) 更新 s2-045 PoC 与说明 2017-06-13 08:55:25 +00:00
zerokeeper
1850fd70ce (Update Vul: Struts2) 更新 s2-045 PoC 与说明 2017-06-13 08:54:21 +00:00
zerokeeper
2e22703df1 (Update Vul: Struts2) 更新 s2-045 PoC 与说明 2017-06-13 08:52:09 +00:00
zerokeeper
90575f4abb (Update Vul: Struts2) 更新 s2-045 PoC 与说明 2017-06-13 08:47:28 +00:00
zerokeeper
3e3a212789 Update README.md 2017-06-13 16:40:18 +08:00
zerokeeper
a734522e1c Create README.md 2017-06-13 16:39:53 +08:00
zerokeeper
448756e856 (Add Vul: Struts2) s2-029 2017-06-13 08:36:18 +00:00