alt3kx's repositories

CVE-2023-24055_PoC

CVE-2023-24055 PoC (KeePass 2.5x)

License:GPL-3.0Stargazers:254Issues:7Issues:0

wafaray

Enhance your malware detection with WAF + YARA (WAFARAY)

Language:ShellLicense:GPL-3.0Stargazers:106Issues:5Issues:2

CVE-2022-22965

Spring Framework RCE (CVE-2022-22965) Nmap (NSE) Checker (Non-Intrusive)

Language:LuaLicense:GPL-3.0Stargazers:101Issues:4Issues:2

CVE-2022-1388_PoC

F5 BIG-IP RCE exploitation (CVE-2022-1388)

License:GPL-3.0Stargazers:88Issues:2Issues:0

wafparan01d3

Quick WAF "paranoid" Doctor Evaluation | WAFPARAN01D3 Tool

Language:PythonLicense:GPL-3.0Stargazers:25Issues:4Issues:0

CVE-2022-22965_PoC

Spring Framework RCE (Quick pentest notes)

License:GPL-3.0Stargazers:17Issues:2Issues:0

CVE-2018-12463

XML external entity (XXE) vulnerability in /ssc/fm-ws/services in Fortify Software Security Center (SSC) 17.10, 17.20 & 18.10 (0day CVE-2018-12463)

License:GPL-3.0Stargazers:6Issues:3Issues:0

airdecloak-ng

My Aircrack-ng contribution with Thomas d'Otreppe

Language:CLicense:GPL-3.0Stargazers:4Issues:3Issues:0

CVE-2019-10685

A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Print Archive System v2015 release 2.6

CVE-2018-7690

The SSC REST API contains Insecure Direct Object Reference (IDOR) vulnerabilities in Fortify Software Security Center (SSC) 17.10, 17.20 & 18.10

License:LGPL-3.0Stargazers:2Issues:3Issues:0

CVE-2018-7691

The SSC REST API contains Insecure Direct Object Reference (IDOR) vulnerabilities in Fortify Software Security Center (SSC) 17.10, 17.20 & 18.10

License:LGPL-3.0Stargazers:2Issues:3Issues:0

papers

A handy collection of my public papers, all in one place.

License:GPL-3.0Stargazers:2Issues:4Issues:0

CVE-2001-0933

Cooolsoft PowerFTP Server 2.03 allows remote attackers to list the contents of arbitrary drives via a ls (LIST) command that includes the drive letter as an argument, e.g. "ls C:".

License:GPL-3.0Stargazers:1Issues:3Issues:0

CVE-2001-0934

Cooolsoft PowerFTP Server 2.03 allows remote attackers to obtain the physical path of the server root via the pwd command, which lists the full pathname.

License:GPL-3.0Stargazers:1Issues:4Issues:0

CVE-2001-1442

ISC INN 2.x - Command-Line Buffer Overflow

Language:CLicense:GPL-3.0Stargazers:1Issues:3Issues:0

CVE-2002-0200

Cyberstop Web Server for Windows 0.1 allows remote attackers to cause a denial of service via an HTTP request for an MS-DOS device name.

License:GPL-3.0Stargazers:1Issues:3Issues:0

CVE-2002-0201

Cyberstop Web Server for Windows 0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request, possibly triggering a buffer overflow.

Language:PerlLicense:GPL-3.0Stargazers:1Issues:3Issues:0

CVE-2009-4118

Cisco VPN Client - Integer Overflow Denial of Service

License:GPL-3.0Stargazers:1Issues:3Issues:0

CVE-2018-10732

Dataiku REST-API by default the software, allows anonymous access to functionality that allows an attacker to know valid users.

License:GPL-3.0Stargazers:1Issues:3Issues:0

CVE-2018-12596

Ektron Content Management System (CMS) 9.20 SP2, remote re-enabling users (CVE-2018–12596)

License:GPL-3.0Stargazers:1Issues:4Issues:0

CVE-2018-12597

CVE-2018-12597

License:GPL-3.0Stargazers:1Issues:3Issues:0

CVE-2018-12598

CVE-2018-12598

License:GPL-3.0Stargazers:1Issues:3Issues:0

CVE-2020-13457

CVE-2020-13457

License:GPL-3.0Stargazers:1Issues:4Issues:0

CVE-2001-0931

Directory traversal vulnerability in Cooolsoft PowerFTP Server 2.03 allows attackers to list or read arbitrary files and directories via a .. (dot dot) in (1) LS or (2) GET.

License:GPL-3.0Stargazers:0Issues:3Issues:0