Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
186 commits
Select commit Hold shift + click to select a range
2415054
Update update_readme.py
Mr-xn Feb 27, 2026
9238172
docs: 更新 2 篇文章 - 九佳易管理系统 picHY.ashx SQL 注入漏洞 | 大蚂蚁 (BigAnt) 即时通讯系统 安装…
github-actions[bot] Feb 27, 2026
9f715b5
docs: 更新 1 篇文章 - 青龙面板最新版v2.20.1 鉴权绕过致RCE [skip ci]
github-actions[bot] Feb 27, 2026
bde24c2
docs: 更新 1 篇文章 - 大蚂蚁 (BigAnt) 即时通讯系统 moveDept SQL注入漏洞 [skip ci]
github-actions[bot] Feb 27, 2026
4011e68
Create security audit report for Qinglong v2.20.1
Mr-xn Feb 27, 2026
fc5cc5c
Add files via upload
Mr-xn Feb 27, 2026
194bc49
add qinglong-auth-bypass2rce/青龙(qinglong)面板权限绕过致未授权远程代码执行(RCE)漏洞分析复现
Mr-xn Feb 27, 2026
d484232
add 青龙(qinglong)面板权限绕过致未授权远程代码执行(RCE)漏洞分析复现
Mr-xn Feb 27, 2026
cdafdd0
docs: 更新 1 篇文章 - 九佳易管理系统 Ajax_XT.ashx SQL 注入漏洞 [skip ci]
github-actions[bot] Feb 28, 2026
3393578
docs: 更新 1 篇文章 - 九佳易管理系统 PrivilegedCodeDestroy.asmx SQL注入漏洞 [skip ci]
github-actions[bot] Mar 1, 2026
ae435b9
docs: 更新 1 篇文章 - 大蚂蚁 (BigAnt) 即时通讯系统 updateLoginName SQL注入漏洞 [skip ci]
github-actions[bot] Mar 1, 2026
54556b7
docs: 更新 1 篇文章 - 深信服运维安全管理系统 change_net 远程命令执行漏洞 [skip ci]
github-actions[bot] Mar 2, 2026
1094eb2
docs: 更新 1 篇文章 - 深信服运维安全管理系统 del_net 远程命令执行漏洞 [skip ci]
github-actions[bot] Mar 3, 2026
7b230d0
docs: 更新 1 篇文章 - 深信服运维安全管理系统 del_route 远程命令执行漏洞 [skip ci]
github-actions[bot] Mar 4, 2026
2e4df8c
docs: 更新 1 篇文章 - 深信服运维安全管理系统 getLdap 远程命令执行漏洞 [skip ci]
github-actions[bot] Mar 6, 2026
4c23abe
Initial plan
Copilot Mar 6, 2026
7f075b9
reorganize: create iot/, web/, privesc/, pc/ dirs and move loose md f…
Copilot Mar 6, 2026
934a4a3
Merge pull request #31 from Mr-xn/copilot/organize-project-structure
Mr-xn Mar 6, 2026
755cfa8
docs: 更新 1 篇文章 - 深信服运维安全管理系统 save_SNMP 远程命令执行漏洞 [skip ci]
github-actions[bot] Mar 7, 2026
e2dbf8f
docs: 更新 1 篇文章 - 深信服运维安全管理系统 csspost/update 远程命令执行漏洞 [skip ci]
github-actions[bot] Mar 8, 2026
cef004a
docs: 更新 1 篇文章 - 深信服运维安全管理系统 upload_file 远程命令执行漏洞 [skip ci]
github-actions[bot] Mar 9, 2026
57e4046
docs: 更新 1 篇文章 - 深信服运维安全管理系统 del_patch 远程命令执行漏洞 [skip ci]
github-actions[bot] Mar 10, 2026
2f63804
docs: 更新 1 篇文章 - 深信服运维安全管理系统 install_patch 远程命令执行漏洞 [skip ci]
github-actions[bot] Mar 11, 2026
3d1fe2e
docs: 更新 1 篇文章 - 深信服运维安全管理系统 remote_get_clip_img 远程命令执行漏洞 [skip ci]
github-actions[bot] Mar 12, 2026
7fb1684
docs: 更新 1 篇文章 - 深信服运维安全管理系统 uninstall_patch 远程命令执行漏洞 [skip ci]
github-actions[bot] Mar 13, 2026
1ba9995
docs: 更新 1 篇文章 - 深信服运维安全管理系统 get_clip_img 远程命令执行漏洞 [skip ci]
github-actions[bot] Mar 14, 2026
31ac4c3
docs: 更新 1 篇文章 - 深信服运维安全管理系统 down_load 远程命令执行漏洞 [skip ci]
github-actions[bot] Mar 15, 2026
bbaaa4c
docs: 更新 1 篇文章 - 深信服运维安全管理系统 port_validate 远程命令执行漏洞 [skip ci]
github-actions[bot] Mar 16, 2026
f71acca
Initial plan
Copilot Mar 16, 2026
94aa543
Add Webpack_extract to README tools section near Webpackfind
Copilot Mar 16, 2026
2805981
Merge pull request #32 from Mr-xn/copilot/update-readme-for-webpack-e…
Mr-xn Mar 16, 2026
4ad78ef
Bump pyopenssl from 19.0 to 26.0.0 in /BlueKeep
dependabot[bot] Mar 16, 2026
b506108
docs: 更新 1 篇文章 - 深信服运维安全管理系统 save_strategy 远程命令执行漏洞 [skip ci]
github-actions[bot] Mar 17, 2026
a56eee7
Initial plan
Copilot Mar 17, 2026
2829884
docs: add NX_Firmware to README IOT section
Copilot Mar 17, 2026
b8c255b
Merge pull request #34 from Mr-xn/copilot/add-description-to-readme
Mr-xn Mar 17, 2026
8ae14d6
Merge pull request #33 from Mr-xn/dependabot/pip/BlueKeep/pyopenssl-2…
Mr-xn Mar 17, 2026
3d96ed1
docs: 更新 1 篇文章 - 深信服运维安全管理系统 generate_certificate 远程命令执行漏洞 [skip ci]
github-actions[bot] Mar 18, 2026
477925e
docs: 更新 1 篇文章 - 深信服运维安全管理系统 update_date 远程命令执行漏洞 [skip ci]
github-actions[bot] Mar 19, 2026
c7ed81b
Add Wireshark-MCP to tools section (#35)
Copilot Mar 19, 2026
99e3141
docs: 更新 1 篇文章 - 深信服运维安全管理系统 upload_CN 远程命令执行漏洞 [skip ci]
github-actions[bot] Mar 20, 2026
8609539
Add ByPassTamperPlus to README.md (#36)
Copilot Mar 20, 2026
a03ac05
docs: 更新 1 篇文章 - 深科特 LEAN MES系统 ChooseLineAndRes.ashx SQL 注入漏洞 [skip ci]
github-actions[bot] Mar 22, 2026
eca771d
docs: 更新 1 篇文章 - 深科特 LEAN MES系统 /Handler/SMTLoadingMaterial.ashx SQL注…
github-actions[bot] Mar 23, 2026
13723b6
docs: 更新 1 篇文章 - 深科特 LEAN MES系统 EquipmentTree.ashx SQL注入漏洞 [skip ci]
github-actions[bot] Mar 24, 2026
91b5bf6
docs: 更新 1 篇文章 - 深科特 LEAN MES系统 UploadPortraits.ashx 文件上传漏洞 [skip ci]
github-actions[bot] Mar 24, 2026
45eb8b1
Add DarkSword iOS exploit repositories to README (#37)
Copilot Mar 24, 2026
80c4af8
docs: 更新 1 篇文章 - 深科特 LEAN MES系统 /Handler/FileSync.ashx 任意文件读取/上传/删除/S…
github-actions[bot] Mar 25, 2026
0b33df2
docs: 更新 1 篇文章 - 深科特 LEAN MES系统 DownLoad.aspx 任意文件读取漏洞 [skip ci]
github-actions[bot] Mar 26, 2026
d7688b3
docs: 更新 1 篇文章 - 深科特 LEAN MES系统 /Handler/MobileAppLogin.ashx SQL注入漏洞 …
github-actions[bot] Mar 26, 2026
575f274
docs: 更新 1 篇文章 - 深科特 LEAN MES系统 PrintUpdate.ashx 任意文件读取/上传/删除漏洞 [skip…
github-actions[bot] Mar 27, 2026
797e3b6
docs: 更新 1 篇文章 - 深科特 LEAN MES系统 TestManagePlatform.ashx SQL注入漏洞 [skip…
github-actions[bot] Mar 28, 2026
8e29dd9
Add ProcIR Windows incident response tool to README (#40)
Copilot Mar 28, 2026
f05665b
docs: 更新 1 篇文章 - 深科特 LEAN MES系统 UploadHander.ashx 文件上传漏洞 [skip ci]
github-actions[bot] Mar 29, 2026
b712c5a
docs: 更新 1 篇文章 - 深科特 LEAN MES系统 CreateMenus.aspx 任意文件上传漏洞 [skip ci]
github-actions[bot] Mar 31, 2026
21e4ead
docs: 更新 1 篇文章 - 深科特 LEAN MES系统 AutoComplete.ashx SQL注入漏洞 [skip ci]
github-actions[bot] Apr 1, 2026
e420c21
Add trajan CI/CD pipeline security scanner to tools section in README…
Copilot Apr 2, 2026
c6fd742
Add clawgod to tools section in README (#42)
Copilot Apr 2, 2026
9a6e8fb
Add Payloader to tools section in README (#43)
Copilot Apr 2, 2026
e0f4448
docs: 更新 1 篇文章 - 深科特 LEAN MES系统 ChooseImage.aspx 任意文件上传/删除漏洞 [skip ci]
github-actions[bot] Apr 2, 2026
374fd13
Add vphone-aio to IOT Device & Mobile Phone section (#44)
Copilot Apr 3, 2026
f4e909e
docs: 更新 1 篇文章 - 深科特 LEAN MES系统 SetDataSource.aspx SQL注入漏洞 [skip ci]
github-actions[bot] Apr 3, 2026
cceacd8
Add kslkatz_bof link to README tools section (#45)
Copilot Apr 3, 2026
ebad1a9
docs: 更新 1 篇文章 - CLIProxyAPI /v1internal:method 未授权访问漏洞 [skip ci]
github-actions[bot] Apr 3, 2026
feda568
Add Shannon-related security tools to README (#46)
Copilot Apr 6, 2026
4f90735
docs: 更新 1 篇文章 - 孚盟云CRM AjaxTrackInfo.ashx SQL注入漏洞 [skip ci]
github-actions[bot] Apr 6, 2026
36dda05
docs: 更新 1 篇文章 - 孚盟云CRM DingHandler.ashx SQL注入漏洞 [skip ci]
github-actions[bot] Apr 7, 2026
7b64bc1
Add Podroid to IOT Device & Mobile Phone section in README (#47)
Copilot Apr 7, 2026
688b8b4
docs: 更新 1 篇文章 - 孚盟云CRM PriceList.ashx SQL注入漏洞 [skip ci]
github-actions[bot] Apr 8, 2026
387ee9a
docs: 更新 1 篇文章 - 孚盟云CRM WorkFlowHandler.ashx SQL注入漏洞 [skip ci]
github-actions[bot] Apr 9, 2026
51bb3d9
docs: 更新 1 篇文章 - 孚盟云CRM AddInquiry.aspx SQL注入漏洞 [skip ci]
github-actions[bot] Apr 10, 2026
8843313
docs: 更新 1 篇文章 - 孚盟云CRM OrderLook.aspx SQL注入漏洞 [skip ci]
github-actions[bot] Apr 11, 2026
b93fdde
Add Rockxy HTTP debugging proxy tool to README tools section (#48)
Copilot Apr 11, 2026
273a067
Add ysogate link to README near ysomap entry (#49)
Copilot Apr 11, 2026
4c30648
Add SysWhispers4 link to README near SysWhispers3 entry (#50)
Copilot Apr 11, 2026
3c5af3e
docs: 更新 1 篇文章 - 孚盟云CRM FormDefault.aspx、FormDefaultCommon.aspx 多处SQL…
github-actions[bot] Apr 12, 2026
cba3136
docs: 更新 1 篇文章 - 天地伟业Easy7 queryRoomName SQL注入漏洞 [skip ci]
github-actions[bot] Apr 14, 2026
c9c71ce
docs: 更新 1 篇文章 - 天地伟业Easy7 queryRoomConfigs SQL注入漏洞 [skip ci]
github-actions[bot] Apr 15, 2026
213bb5c
Add nano-analyzer and Tomcat JMX→RCE resources to README (#51)
Copilot Apr 15, 2026
e23ed5b
Add anything-analyzer to tools section in README (#52)
Copilot Apr 15, 2026
2dfb62b
docs: 更新 1 篇文章 - 天地伟业Easy7 UploadOwnerImage.jsp 文件上传漏洞 [skip ci]
github-actions[bot] Apr 16, 2026
582a972
docs: 更新 1 篇文章 - mdserver-web(夸父面板)≤0.18.4 多处未授权访问 + 信息泄露 + RCE 漏洞分析 …
github-actions[bot] Apr 16, 2026
cb89622
Add RedSun Windows Defender privilege escalation link to README (#53)
Copilot Apr 17, 2026
d6cb39a
docs: 更新 1 篇文章 - 天地伟业Easy7 GetOtherDomainServer.jsp SSRF漏洞 [skip ci]
github-actions[bot] Apr 17, 2026
0d086bd
docs: 更新 1 篇文章 - 天地伟业Easy7 getInquestIdByRoomId SQL注入漏洞 [skip ci]
github-actions[bot] Apr 18, 2026
cbaa44a
docs: 补充 CVE-2026-0827 和 BlueSAM 到 README (#54)
Copilot Apr 18, 2026
af1242f
Add link to ultimate code audit checklist
Mr-xn Apr 18, 2026
99c6ce6
Add raptor to tools section in README (#55)
Copilot Apr 19, 2026
d1d9dfa
docs: 更新 1 篇文章 - 天地伟业Easy7 getInquestRoomChannelInfo SQL注入漏洞 [skip ci]
github-actions[bot] Apr 19, 2026
a94ecb7
docs: 更新 1 篇文章 - V2Board 信息泄露漏洞至权限绕过接管账户(CVE-2026-39912)分析复现 [skip ci]
github-actions[bot] Apr 20, 2026
6568d59
Add UnDefend Windows Defender DOS tool to README after RedSun entry (…
Copilot Apr 20, 2026
d68b23a
docs: 更新 1 篇文章 - 天地伟业Easy7 isHashCameraAuth SQL注入漏洞 [skip ci]
github-actions[bot] Apr 21, 2026
b530c68
docs: 更新 1 篇文章 - 天地伟业Easy7 getConfigInfoList SQL注入漏洞 [skip ci]
github-actions[bot] Apr 22, 2026
3ba9403
docs: 更新 1 篇文章 - 天地伟业Easy7 capture 命令执行漏洞 [skip ci]
github-actions[bot] Apr 23, 2026
abc6deb
docs: 更新 1 篇文章 - 天地伟业Easy7 uploadLedImage 文件上传漏洞 [skip ci]
github-actions[bot] Apr 24, 2026
3aa177c
docs: 更新 1 篇文章 - 天地伟业Easy7 /Easy7/rest/file/delete 文件删除漏洞 [skip ci]
github-actions[bot] Apr 25, 2026
bba9ddc
docs: 更新 1 篇文章 - 天地伟业Easy7 /Easy7/rest/file/downloadFile 文件读取漏洞 [skip…
github-actions[bot] Apr 26, 2026
4080414
docs: 更新 1 篇文章 - 天地伟业Easy7 /Easy7/rest/file/uploadIdsHttpFile SSRF+文件…
github-actions[bot] Apr 27, 2026
9dc3e13
docs: 更新 1 篇文章 - 孚盟云CRM CustomizeReportSelectMould.aspx SQL注入漏洞 [skip…
github-actions[bot] Apr 28, 2026
0451098
docs: 更新 1 篇文章 - 孚盟云CRM ClientNameCard.aspx SQL注入漏洞 [skip ci]
github-actions[bot] Apr 29, 2026
eb74e0c
docs: 更新 1 篇文章 - 孚盟云CRM BusinessPrice.aspx SQL注入漏洞 [skip ci]
github-actions[bot] Apr 30, 2026
e0a901b
Add Java Ghost Bits (Black Hat Asia 2026) links to IOT section (#57)
Copilot Apr 30, 2026
46e8295
add Asia-26-Bai-Cast-Attack-Ghost-Bits-4.23.pdf
Mr-xn Apr 30, 2026
db611dc
docs: 更新 1 篇文章 - 孚盟云CRM BusinessPriceListList.aspx SQL注入漏洞 [skip ci]
github-actions[bot] May 1, 2026
793ee17
docs: add GBitsTools, GbitsGen, ghost-bits-lab, BLACKHAT_Asia2026 to …
Copilot May 1, 2026
7000601
docs: add Pentest-Swarm-AI to README tools section (#59)
Copilot May 3, 2026
806f647
docs: 更新 1 篇文章 - 天地伟业Easy7 /Easy7/rest/file/uploadFile 文件上传漏洞 [skip ci]
github-actions[bot] May 6, 2026
bff8f1f
docs: 更新 1 篇文章 - 天地伟业Easy7 /Easy7/rest/file/deleteFile 文件删除漏洞 [skip ci]
github-actions[bot] May 7, 2026
4622982
docs: 更新 1 篇文章 - 天地伟业Easy7 /Easy7/rest/file/download 文件读取漏洞 [skip ci]
github-actions[bot] May 8, 2026
80cab04
docs: 更新 1 篇文章 - 天地伟业Easy7 /Easy7/rest/user/getAuthorityByUserId SQL注…
github-actions[bot] May 9, 2026
d25071d
Add Dirty Frag to the Linux privilege escalation section in README (#60)
Copilot May 9, 2026
881fc93
docs: 更新 1 篇文章 - 天地伟业Easy7 /Easy7/rest/user/IsPermissible SQL注入漏洞 [sk…
github-actions[bot] May 10, 2026
dc14de9
docs: 更新 1 篇文章 - 天地伟业Easy7 /Easy7/rest/user/getAuthorityByUserId SQL注…
github-actions[bot] May 11, 2026
82a8f01
docs: 更新 1 篇文章 - 孚盟云CRM BusinessPriceOk.aspx SQL注入漏洞 [skip ci]
github-actions[bot] May 12, 2026
f13cf8e
docs: 更新 1 篇文章 - 孚盟云CRM BusinessPriceReport.aspx SQL注入漏洞 [skip ci]
github-actions[bot] May 13, 2026
e420f06
docs: 更新 1 篇文章 - 孚盟云CRM BusiPriceOkPrint.aspx SQL注入漏洞 [skip ci]
github-actions[bot] May 14, 2026
95422f6
docs: Add CVE-2026-34621 (Adobe Acrobat SSRF/JS injection) and CVE-20…
Copilot May 16, 2026
05eeb7c
docs: add zenproxy link to proxy tools list (#63)
Copilot May 17, 2026
12ce4a2
docs: 更新 1 篇文章 - 用友 NC 系统 IMsgCenterWebService SQL注入漏洞 [skip ci]
github-actions[bot] May 18, 2026
87cce6f
Add CACM (Linux权限维持+后渗透工具) to 提权辅助相关 section in README.md (#65)
Copilot May 23, 2026
ad9d7a3
docs: add Copy-Fail Kubernetes PoC link to CVE-2026-31431 entries (#66)
Copilot May 25, 2026
68fff2a
Add CIFSwitch link to Linux privilege escalation section in README (#68)
Copilot May 29, 2026
65db36a
docs: add TongWeb exploit and plugin links to README (#69)
Copilot May 29, 2026
db7fbca
Bump urllib3 from 1.26.5 to 2.7.0 in /discuz-ml-rce (#61)
dependabot[bot] May 29, 2026
a6d696d
docs: 更新 1 篇文章 - 孚盟云CRM LoadMailAttachFile.aspx 任意文件读取/移动 [skip ci]
github-actions[bot] May 31, 2026
68be565
docs: 更新 1 篇文章 - 孚盟云CRM Inquiry.aspx SQL注入漏洞 [skip ci]
github-actions[bot] Jun 1, 2026
fcdbf59
docs: add PrismSpace link to README (#70)
Copilot Jun 1, 2026
9d29d15
docs: 更新 1 篇文章 - 孚盟云CRM Price_detail.aspx SQL注入漏洞 [skip ci]
github-actions[bot] Jun 2, 2026
c0807eb
docs: 更新 1 篇文章 - 孚盟云CRM ProductGrid.aspx SQL注入漏洞 [skip ci]
github-actions[bot] Jun 3, 2026
740254c
docs: 更新 1 篇文章 - 孚盟云CRM AjaxProductList.ashx SQL注入漏洞 [skip ci]
github-actions[bot] Jun 4, 2026
e62e6ea
Add AgonySec/ThinkPHPGUI to README tools section (#71)
Copilot Jun 4, 2026
7460fb4
Add AssppJailbroken to IOT Device&Mobile Phone section in README.md (…
Copilot Jun 4, 2026
32e3427
docs: 更新 1 篇文章 - 孚盟云CRM ProductList.aspx SQL注入漏洞 [skip ci]
github-actions[bot] Jun 5, 2026
6189766
docs: 更新 1 篇文章 - 孚盟云CRM Product_field.aspx SQL注入漏洞 [skip ci]
github-actions[bot] Jun 6, 2026
038c80d
Add Nginx HTTP/2 Bomb Exploit links to README.md (#73)
Copilot Jun 6, 2026
327e686
docs: 更新 1 篇文章 - 孚盟云CRM ProductDetail.aspx SQL注入漏洞 [skip ci]
github-actions[bot] Jun 7, 2026
8351d32
docs: 更新 1 篇文章 - 孚盟云CRM ProductSelect.aspx SQL注入漏洞 [skip ci]
github-actions[bot] Jun 8, 2026
ab65351
Add LuaN1aoAgent cognitive AI pentesting agent to tools list (#74)
Copilot Jun 8, 2026
a0ab651
docs: 更新 1 篇文章 - CVE-2026-8054 高危前台无需认证 SQL 注入漏洞(Pre-auth SQL Injecti…
github-actions[bot] Jun 8, 2026
0e08d7c
docs: add GitHub PoC link for CVE-2026-8054 (#75)
Copilot Jun 9, 2026
4ef08e6
docs: 更新 1 篇文章 - 孚盟云CRM ProviderList.aspx SQL注入漏洞 [skip ci]
github-actions[bot] Jun 9, 2026
5255cfa
docs: 更新 1 篇文章 - 孚盟云CRM ProductDetail.aspx SQL注入漏洞 [skip ci]
github-actions[bot] Jun 10, 2026
e57bca1
Add Anthropic-Cybersecurity-Skills to README.md under tools section (…
Copilot Jun 10, 2026
6a97254
docs: 更新 1 篇文章 - 大蚂蚁 (BigAnt) 即时通讯系统 user_expire_post SQL注入漏洞 [skip ci]
github-actions[bot] Jun 11, 2026
9ec7b9c
Add BishopFox CVE-2026-34908-check to README.md (#77)
Copilot Jun 11, 2026
9c93371
docs: 更新 1 篇文章 - 大蚂蚁 (BigAnt) 即时通讯系统 uploadMultipleFile 任意文件上传漏洞 [ski…
github-actions[bot] Jun 12, 2026
2f610f2
docs: 更新 1 篇文章 - 大蚂蚁 (BigAnt) 即时通讯系统 Pan/Upload/upload 文件上传漏洞 [skip ci]
github-actions[bot] Jun 13, 2026
e36ed50
docs: 更新 1 篇文章 - 大蚂蚁 (BigAnt) 即时通讯系统 getFileTrueAddress SQL注入漏洞 [skip…
github-actions[bot] Jun 14, 2026
59a9430
docs: 更新 1 篇文章 - 大蚂蚁 (BigAnt) 即时通讯系统 downloadSharedFile 任意文件读取漏洞 [ski…
github-actions[bot] Jun 15, 2026
28b8672
docs: 更新 1 篇文章 - 大蚂蚁 (BigAnt) 即时通讯系统 clearUserDevice SQL注入漏洞 [skip ci]
github-actions[bot] Jun 16, 2026
b65bff0
docs: 更新 1 篇文章 - 大蚂蚁 (BigAnt) 即时通讯系统 admin/secret/edit SQL注入漏洞 [skip ci]
github-actions[bot] Jun 17, 2026
f272edd
docs: 更新 1 篇文章 - 大蚂蚁 (BigAnt) 即时通讯系统 admin/Upload/upload 文件上传漏洞 [skip…
github-actions[bot] Jun 18, 2026
e0be4cb
docs: 更新 1 篇文章 - LiteLLM v1.84.0 安全漏洞完整分析报告 [skip ci]
github-actions[bot] Jun 23, 2026
4e4cc62
RootHawk:整合多种已公开本地提权漏洞(如 Dirty Pipe、PwnKit、Polkit 3560 等)的一键化 Linux 提…
Mr-xn Jun 27, 2026
4023534
add Linux提权】CVE-2026-43503:(DirtyClone)
Mr-xn Jun 27, 2026
622927a
add reverse-skill 一个面向逆向工程、渗透测试和安全研究的技能路由包,支持 AI 编码助手自动选择合适的工作流和工具链,涵…
Mr-xn Jun 28, 2026
8b378b1
add 【Linux提权】CVE‑2026‑46331:packet_edit_meme
Mr-xn Jun 28, 2026
95fbc64
add freellmapi:一个免费 LLM API 聚合服务,提供兼容 OpenAI 的统一接口,可无缝调用多个免费大模型,非常适合个…
Mr-xn Jun 28, 2026
aad3c03
add jadx-ai-mcp:为 Jadx 提供 MCP 扩展,使 AI 工具能够直接调用本地 Jadx 进行 APK/DEX 反编译、…
Mr-xn Jun 28, 2026
87fce15
add NebulaPulsar:一个 Java/C# WebShell 漏洞利用与植入工具,作为 Alien 项目的概念验证(PoC),…
Mr-xn Jun 28, 2026
71a8cd5
add 添加两款OSINT 工具sherlock和Aliens_eye
Mr-xn Jun 28, 2026
5162375
Add files via upload
Mr-xn Jun 28, 2026
6693085
Consolidate scattered CVE/exploit dirs and restore Markdown link form…
Copilot Jul 4, 2026
29ff1f0
Add Darkmoon (#80)
Dark-Moon-X Jul 5, 2026
9b887ce
Bump requests in /vuln_pocs/exploit-tools/tp5-getshell (#79)
dependabot[bot] Jul 5, 2026
8b90213
add 【Linux提权】 CVE‑2026‑46242(Bad Epoll)
Mr-xn Jul 5, 2026
1ba941c
Add Upload_Auto_Fuzz tool description to README
Mr-xn Jul 15, 2026
4686235
docs: 更新 1 篇文章 - 用友U8Cloud XChangeServlet SQL注入漏洞+XXE漏洞 [skip ci]
github-actions[bot] Jul 16, 2026
6fb2c3e
add CVE-2026-63030 + CVE-2026-60137: pre-authentication SQL injection…
Mr-xn Jul 18, 2026
70ddd57
update wp2shell scripts
Mr-xn Jul 18, 2026
bdef3cd
add wp2shell + lab
Mr-xn Jul 18, 2026
61571b6
Update README.md
Mr-xn Jul 19, 2026
31091af
add Fastjson 1.2.68-1.2.83 版本默认配置在特定场景下的反序列化RCE实现
Mr-xn Jul 20, 2026
d32962f
docs: 更新 1 篇文章 - Fastjson 1.2.83 默认配置下的远程代码执行RCE [skip ci]
github-actions[bot] Jul 20, 2026
189289e
add RCE PoC for Redis 6.2.22, 7.4.9, 8.6.4, 8.8.0
Mr-xn Jul 23, 2026
170547e
add 【Windows提取】CVE-2026-54121:利用 Certighost 漏洞伪造域控(Domain Controller)…
Mr-xn Jul 25, 2026
bc8c6ce
docs: 更新 1 篇文章 - 用友U8Cloud extsystem.dst 接口SQL注入漏洞 [skip ci]
github-actions[bot] Jul 27, 2026
ef68370
docs: 更新 1 篇文章 - 金和OA C6 PlanGiveOut.aspx SQL注入漏洞+越权访问IDOR漏洞+XSS漏洞 [s…
github-actions[bot] Jul 30, 2026
08be292
Fix typos in vulnerability links in README.md
Mr-xn Aug 1, 2026
7bde93d
add FastJson2 Hash 碰撞 RCE 分析与复现
Mr-xn Aug 1, 2026
d492180
Remove FastJson2 RCE analysis entry from README
Mr-xn Aug 1, 2026
d7190f2
Add files via upload
Mr-xn Aug 2, 2026
210458c
Add files via upload
Mr-xn Aug 2, 2026
0d4818c
Update FastJson2 section in README
Mr-xn Aug 2, 2026
6602db5
Add files via upload
Mr-xn Aug 2, 2026
8dd4bd1
Add new resources and links in README
Mr-xn Aug 2, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
1 change: 0 additions & 1 deletion BlueKeep/requirements.txt

This file was deleted.

514 changes: 343 additions & 171 deletions README.md

Large diffs are not rendered by default.

Binary file added books/Asia-26-Bai-Cast-Attack-Ghost-Bits-4.23.pdf
Binary file not shown.
219 changes: 219 additions & 0 deletions books/CVE-2026-41844 Spring Framework 开放重定向漏洞浅析.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,219 @@
# CVE-2026-41844 Spring Framework 开放重定向漏洞浅析
> QIANXIN Team
> 来源:https://forum.butian.net/share/4951

# 0x00 CVE-2026-41844

![image.png](https://cdn-yg-zzbm.yun.qianxin.com/attack-forum/2026/07/attach-7aff2d3e51062d3e9e80e4782993df689e9f780d.png)
**主要影响范围:**

Spring Framework:

- 7.0.0 - 7.0.7
- 6.2.0 - 6.2.18
- 6.1.0 - 6.1.27
- 5.3.0 - 5.3.48

以及不再支持维护的版本同样受到影响。

# 0x01 漏洞分析与复现

## 1.1 分析过程

以spring-webmvc 6.0.7为例。

当Spring MVC接收到请求时,Servlet容器会调用DispatcherServlet的service方法(方法的实现在其父类FrameworkServlet中定义):

![image.png](https://cdn-yg-zzbm.yun.qianxin.com/attack-forum/2026/07/attach-7a6ba78d145096ca19d0db32a7a1f01aa2e8838c.png)

经过一系列的处理后,会调用doDispatch方法处理:

![image.png](https://cdn-yg-zzbm.yun.qianxin.com/attack-forum/2026/07/attach-71d0c79c4f4784f9079b3da74df6dbe0009daa50.png)

在doDispatch方法中,经过一系列处理获取到url 和 Handler 映射关系后(HandlerAdapter),springMVC就可以根据请求的uri来找到对应的Controller和method,然后处理和响应请求。详细的分析可见[https://forum.butian.net/share/2214](https://forum.butian.net/share/2214)

![image.png](https://cdn-yg-zzbm.yun.qianxin.com/attack-forum/2026/07/attach-9e259a96ec119b855f92b25d5a18c5a907a688fb.png)

找到对应的HandlerAdapter后,会调用对应的Handler方法,也就是执行Controller里的业务逻辑了,执行完成之后会返回一个ModleAndView对象,然后渲染视图并进行返回,这里的逻辑是本次漏洞的分析的关键:

![image.png](https://cdn-yg-zzbm.yun.qianxin.com/attack-forum/2026/07/attach-4e164661dc717221e5ba9e65bee6bcbd9f69c78f.png)

在获取到ModelAndView对象后,这里会调用applyDefaultViewName处理,这里是Spring 的默认视图解析逻辑:

![image.png](https://cdn-yg-zzbm.yun.qianxin.com/attack-forum/2026/07/attach-58c3dd615e1cf07bbb5dd51174fddb0de5e1b5f9.png)

查看具体的代码逻辑,首先检查 mv 是否为 null(如果代码添加了 `@ResponseBody` 注解,mv 就为 null),然后判断 mv 中是否包含视图,如果对应的Controller代码中未显式指定视图名时,则调用 getDefaultViewName 方法去获取默认的视图名,并将获取到的默认视图名赋值给 mv:

![image.png](https://cdn-yg-zzbm.yun.qianxin.com/attack-forum/2026/07/attach-d7d6ddf0a277d092e9bea01c93c20074d9959680.png)

查看getDefaultViewName,看看具体获取默认视图名的逻辑:

![image.png](https://cdn-yg-zzbm.yun.qianxin.com/attack-forum/2026/07/attach-8665985be7d37bcdd595bf1649a76bb93d873e1e.png)

这里会继续调用viewNameTranslator#getViewName方法对请求进行处理。

viewNameTranslator 其实是 RequestToViewNameTranslator:

![image.png](https://cdn-yg-zzbm.yun.qianxin.com/attack-forum/2026/07/attach-cc432e55fa31276957246359535910482e376bbf.png)

![image.png](https://cdn-yg-zzbm.yun.qianxin.com/attack-forum/2026/07/attach-5af491a5a2a1957664273a91e18d4c5bc9b7bfe2.png)

本质上,在 SpringMVC 中,RequestToViewNameTranslator 接口只有一个默认的实现类DefaultRequestToViewNameTranslator,WebFlux 则是ViewResolutionResultHandler 。

在DefaultRequestToViewNameTranslator#getViewName方法中,**会从请求路径中直接提取字符串作为视图名**:

![image.png](https://cdn-yg-zzbm.yun.qianxin.com/attack-forum/2026/07/attach-cc9a702a17b6ab267cccef0cc06411855c60952f.png)

ServletRequestPathUtils#getCachedPathValue方法是统一获取请求路径的方法。具体的解析可见[https://forum.butian.net/share/2606。](https://forum.butian.net/share/2606%E3%80%82)

提取完请求路径后,会通过 transformPath 方法对路径进行处理,再分别加上前后缀后返回,默认的前后缀都是空字符串(如有需要,也可以进行配置)。

transformPath 方法则主要功能如下:

1. 去掉路径开始的 `/`
2. 去掉路径结尾的 `/`
3. 如果请求路径有扩展名,则去掉扩展名,例如请求路径是 `/1.txt`,经过这一步处理后,就变成了 `/1`

![image.png](https://cdn-yg-zzbm.yun.qianxin.com/attack-forum/2026/07/attach-cabe7d1f2f688feb30ce83e602883b60633d4017.png)

![image.png](https://cdn-yg-zzbm.yun.qianxin.com/attack-forum/2026/07/attach-b569289a69ddddbbb63b69d4088baeb90dcb381f.png)

4. 如果 separator 与 SLASH 不同,则替换原来的分隔符(一般情况下,默认是相同的)。

![image.png](https://cdn-yg-zzbm.yun.qianxin.com/attack-forum/2026/07/attach-9a8dd48be68c7b588415fbcdf9a163aff861b552.png)

这里以如下Controller为例:

```java
@GetMapping("/**")
public void catchAll() {

}
```

当正常请求/demo时,可以看到,因为没有显示指定视图,所以ModelAndView对象里的内容均为null:

![image.png](https://cdn-yg-zzbm.yun.qianxin.com/attack-forum/2026/07/attach-885d2da684b8f5a4ce13decea316679d13a992bb.png)

经过applyDefaultViewName方法处理后,取得对应的视图名,也就是默认的请求路径demo:

![image.png](https://cdn-yg-zzbm.yun.qianxin.com/attack-forum/2026/07/attach-7d86b67bbbe0dad2687f3a3717aaba56ee4c7cd5.png)

这里也就得到了漏洞的第一个成因:**当 Spring MVC 或 Spring WebFlux 应用未显式指定视图名时,视图名会默认从请求路径提取。**

处理完上述的一系列逻辑后,会调用processDispatchResult()进行异常处理、请求状态及触发请求完成事件,视图的渲染工作则交给了render()方法:

![image.png](https://cdn-yg-zzbm.yun.qianxin.com/attack-forum/2026/07/attach-c36c4f4dd4039691a506504fad537eb00ce93beb.png)

![image.png](https://cdn-yg-zzbm.yun.qianxin.com/attack-forum/2026/07/attach-63fe84eca740d397c9f3eb8b3e10b0be961c3c7d.png)

render()渲染过程中,如果ModelAndView中的viewName不为空,则调用resolveViewName从视图解析器获取对应的视图对象;否则使用ModelAndView#getview方法获取视图对象。

![image.png](https://cdn-yg-zzbm.yun.qianxin.com/attack-forum/2026/07/attach-47486c2f5fd2e80dead1e2c717ceef4e478c414c.png)

这里会进一步调用getCandidateViews方法进行处理,然后遍历所有的视图解析器,进行视图的创建与解析:

![image.png](https://cdn-yg-zzbm.yun.qianxin.com/attack-forum/2026/07/attach-059fe15e5edc2d21ce0d817a38fb4e2862bd78c4.png)

![image.png](https://cdn-yg-zzbm.yun.qianxin.com/attack-forum/2026/07/attach-a8dcc54516ca04b8fb24d08c26fdc02eeb8bbbc2.png)

而UrlBasedViewResolver会识别视图名中的特殊前缀,例如`redirect:` 会被解析为重定向,返回 302 响应跳转到后续指定的地址:

![image.png](https://cdn-yg-zzbm.yun.qianxin.com/attack-forum/2026/07/attach-883fb90a08d3b922e3bab52d123f338e124d376d.png)

至此,CVE-2026-41844的完整链路大致梳理清楚了。下面是具体的漏洞复现过程。

## 1.2 漏洞复现

以SpringMVC为例:

相关环境直接使用[https://github.com/andbin/spring-boot3-thymeleaf-basic-demo](https://github.com/andbin/spring-boot3-thymeleaf-basic-demo) 进行验证。

根据前面的分析,可以定义一个Controller如下:

```TypeScript
@Controller
public class MyController {

@GetMapping("/**")
public void catchAll() {

}
}
```

启动对应的application后,只需访问`http://ip:port/redirect:https://www.attack.com.any`,通过302跳转后即可重定向到`https://www.attack.com`

注意,根据前面的分析,在通过请求获取默认视图时,如果请求路径有扩展名,则去掉扩展名,这个拓展名会通过结尾最后一个`.`来区分。也就是说类似`www.attack.com`会被处理成`www.attack`,所以在最后构造poc时,要在实际跳转的域名后,增加类似`.any`的后缀,避免截断后无法正常跳转。

下面是具体的效果:

![image.png](https://cdn-yg-zzbm.yun.qianxin.com/attack-forum/2026/07/attach-b5e7b1741dde33d857d6b27e8de8c321f5efee63.png)

forward的转发同理,先定义一个转发的目标:

```TypeScript

@GetMapping("/internal/secret")
@ResponseBody public String internalEndpoint() {
return "[敏感信息] 内部系统配置接口,仅内网可访问";
}
```

只需请求`http://ip:port/forward:/internal/secret`即可成功转发:

![image.png](https://cdn-yg-zzbm.yun.qianxin.com/attack-forum/2026/07/attach-ed9f63a43f4960e31a4fa7b0adeaf4fae9b0cd48.png)

Spring WebFlux同理,这里就不再赘述了。
另外,WebFlux 原生不支持 `forward:` 内部转发,因此仅受 `redirect:` 开放重定向影响。

## 1.3 {\*spring}模式

在官方的漏洞通告中,仅仅提到了`/**`的场景,实际上Spring5及之后的PathPattern解析模式,还支持类似`{*spring}`的写法,与`/**`大同小异,那么是否也会存在风险呢?

查看官方文档:

Representation of a parsed path pattern. Includes a chain of path elements for fast matching and accumulates computed state for quick comparison of patterns.

`PathPattern` matches URL paths using the following rules:

- `?` matches one character
- `*` matches zero or more characters within a path segment
- `**` matches zero or more _path segments_ until the end of the path
- `{spring}` matches a _path segment_ and captures it as a variable named "spring"
- `{spring:[a-z]+}` matches the regexp `[a-z]+` as a path variable named "spring"
- `{*spring}` matches zero or more _path segments_ until the end of the path and captures it as a variable named "spring"

**Note:** In contrast to `[AntPathMatcher](https://docs.spring.io/spring-framework/docs/current/javadoc-api/org/springframework/util/AntPathMatcher.html)`, `**` is supported only at the end of a pattern. For example, `/pages/{}` is valid but `/pages/{}/details` is not. The same applies also to the capturing variant `{*spring}`. The aim is to eliminate ambiguity when comparing patterns for specificity.

根据官方文档的描述,其实`**`跟AntPathMatcher匹配规则区别不大,PathPattern在保持其匹配规则的基础上,新增了`{*spring}`的语法支持。

`{*spring}`表示匹配余下的path路径部分并将其赋值给名为spring的变量(变量名可以根据实际情况随意命名,与`@PathVariable`名称对应即可)。同时,`{*spring}`是可以匹配剩余所有path的,类似`/**`,只是功能更强,可以获取到这部分动态匹配到的内容。

```TypeScript
@GetMapping("/{*path}")
public void catchAll() {

}
```

可以发现,同样成功利用,这里与`/**`的配置区别只是解析模式的不同,不影响具体的漏洞触发:

![image.png](https://cdn-yg-zzbm.yun.qianxin.com/attack-forum/2026/07/attach-e01c770706eb665d265e0ca566f554beeb8810ad.png)

# 0x02 利用条件

综上所述,相关漏洞的利用条件可以总结如下:

1. 使用 Spring MVC 或 Spring WebFlux 框架
2. 配置了类似 `/**` 通配符路径与`{*path}`映射(如全局视图路由)
3. 对应路径的处理器未显式指定视图名称,依赖 Spring 自动从请求路径推导
4. 使用了继承自 `UrlBasedViewResolver` 的视图解析器(Thymeleaf等主流视图技术默认均满足)

# 0x03 修复方案

官方具体修复如下:[https://github.com/spring-projects/spring-framework/blob/v6.2.19/spring-webmvc/src/main/java/org/springframework/web/servlet/view/DefaultRequestToViewNameTranslator.java](https://github.com/spring-projects/spring-framework/blob/v6.2.19/spring-webmvc/src/main/java/org/springframework/web/servlet/view/DefaultRequestToViewNameTranslator.java)

通过请求获取完视图名后,新增对 `redirect:`、`forward:` 两个危险前缀的开头匹配校验。当匹配到危险前缀时直接抛出非法参数异常,由 Spring MVC 异常处理器转为 `400 Bad Request` 响应:

![image.png](https://cdn-yg-zzbm.yun.qianxin.com/attack-forum/2026/07/attach-ca608ed0990abedcfab14ae5c7667b9cea773cff.png)
1,094 changes: 1,094 additions & 0 deletions books/FastJson2 Hash 碰撞 RCE 分析与复现.html

Large diffs are not rendered by default.

Loading