mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-29 09:41:05 +00:00
29 lines
1.2 KiB
Markdown
29 lines
1.2 KiB
Markdown
![]() |
### [CVE-2018-18074](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-18074)
|
||
|

|
||
|

|
||
|

|
||
|
|
||
|
### Description
|
||
|
|
||
|
The Requests package before 2.20.0 for Python sends an HTTP Authorization header to an http URI upon receiving a same-hostname https-to-http redirect, which makes it easier for remote attackers to discover credentials by sniffing the network.
|
||
|
|
||
|
### POC
|
||
|
|
||
|
#### Reference
|
||
|
- https://www.oracle.com/security-alerts/cpujul2022.html
|
||
|
|
||
|
#### Github
|
||
|
- https://github.com/ARPSyndicate/cvemon
|
||
|
- https://github.com/GiuseppeMP/udacity-fundamentos-ia-machine-learning
|
||
|
- https://github.com/Prudent777/Game-4X-maker
|
||
|
- https://github.com/Prudent777/KnowledgeLink-Pro
|
||
|
- https://github.com/SahanaKhushi/iplmatchpredictor2020
|
||
|
- https://github.com/aertyyujhgfd/JARVIS-dans-Iron-man
|
||
|
- https://github.com/colonelmeow/appsecctf
|
||
|
- https://github.com/duo-labs/narrow
|
||
|
- https://github.com/jrak1204/overstock_test
|
||
|
- https://github.com/sbmthakur/packj
|
||
|
- https://github.com/seal-community/patches
|
||
|
- https://github.com/vanschelven/fpvs
|
||
|
|