Skip to content

Instantly share code, notes, and snippets.

View enferas's full-sized avatar

Feras Al-Kassar enferas

  • Jean Monnet University
  • Saint-Etienne, France
View GitHub Profile
@enferas
enferas / CVE-2022-36747.md
Last active September 22, 2022 13:17
XSS vulnerability in Razor
@enferas
enferas / header_injection_phpipam.md
Created September 22, 2022 13:34
Header injection (SSRF) vulnerability in phpipam

Header injection vulnerability in phpipam https://github.com/phpipam/phpipam version v1.5.0

The path of the vulnerability:

<?php
//In file https://github.com/phpipam/phpipam/blob/master/app/admin/subnets/ripe-query.php
//line 21
// the source is $_POST[‘subnet’]
$res = $Subnets->resolve_ripe_arin ($_POST['subnet']);
@enferas
enferas / CVE-2022-34026.md
Created September 22, 2022 13:54
directory traversal in ICEcoder
@enferas
enferas / XSS_Cacti.md
Last active September 22, 2022 14:18
XSS vulnerability in Cacti
@enferas
enferas / XSS_pfesense.md
Created October 2, 2022 10:46
XSS in pfsense v2.5.2
@enferas
enferas / CVE-2023-23027.md
Last active January 21, 2023 12:19
XSS in expense management system sourcecodester
@enferas
enferas / CVE-2023-23026.md
Last active January 21, 2023 12:18
XSS in Sales Management System Source Codester
@enferas
enferas / CVE-2023-23024.md
Last active January 21, 2023 12:14
XSS in Book Store
@enferas
enferas / CVE-2023-23025.md
Last active January 21, 2023 12:17
XSS in Hotel Management System
@enferas
enferas / CVE-2023-23023.md
Last active January 21, 2023 12:13
XSS in Laundry Management System