mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-29 01:31:01 +00:00
29 lines
1.2 KiB
Markdown
29 lines
1.2 KiB
Markdown
### [CVE-2018-18074](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-18074)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
The Requests package before 2.20.0 for Python sends an HTTP Authorization header to an http URI upon receiving a same-hostname https-to-http redirect, which makes it easier for remote attackers to discover credentials by sniffing the network.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- https://www.oracle.com/security-alerts/cpujul2022.html
|
|
|
|
#### Github
|
|
- https://github.com/ARPSyndicate/cvemon
|
|
- https://github.com/GiuseppeMP/udacity-fundamentos-ia-machine-learning
|
|
- https://github.com/Prudent777/Game-4X-maker
|
|
- https://github.com/Prudent777/KnowledgeLink-Pro
|
|
- https://github.com/SahanaKhushi/iplmatchpredictor2020
|
|
- https://github.com/aertyyujhgfd/JARVIS-dans-Iron-man
|
|
- https://github.com/colonelmeow/appsecctf
|
|
- https://github.com/duo-labs/narrow
|
|
- https://github.com/jrak1204/overstock_test
|
|
- https://github.com/sbmthakur/packj
|
|
- https://github.com/seal-community/patches
|
|
- https://github.com/vanschelven/fpvs
|
|
|