PoC-in-GitHub/2019/CVE-2019-5418.json

280 lines
9.7 KiB
JSON
Raw Normal View History

2019-12-08 14:19:20 +01:00
[
2021-04-04 17:10:08 +02:00
{
"id": 175966226,
"name": "CVE-2019-5418",
"full_name": "mpgn\/CVE-2019-5418",
"owner": {
"login": "mpgn",
"id": 5891788,
"avatar_url": "https:\/\/avatars.githubusercontent.com\/u\/5891788?v=4",
"html_url": "https:\/\/github.com\/mpgn"
},
"html_url": "https:\/\/github.com\/mpgn\/CVE-2019-5418",
"description": "CVE-2019-5418 - File Content Disclosure on Ruby on Rails",
"fork": false,
"created_at": "2019-03-16T11:58:18Z",
2023-09-28 14:53:01 +02:00
"updated_at": "2023-09-28T10:59:28Z",
2021-04-06 05:11:05 +02:00
"pushed_at": "2021-04-05T21:28:36Z",
2023-09-28 14:53:01 +02:00
"stargazers_count": 192,
"watchers_count": 192,
2022-11-08 07:19:29 +01:00
"has_discussions": false,
2023-05-25 02:28:33 +02:00
"forks_count": 24,
2021-09-13 23:12:57 +02:00
"allow_forking": true,
2021-10-06 23:13:51 +02:00
"is_template": false,
2022-06-28 20:20:29 +02:00
"web_commit_signoff_required": false,
2021-10-06 23:13:51 +02:00
"topics": [
"rails"
],
2021-10-01 23:13:10 +02:00
"visibility": "public",
2023-05-25 02:28:33 +02:00
"forks": 24,
2023-09-28 14:53:01 +02:00
"watchers": 192,
2023-06-19 15:46:37 +02:00
"score": 0,
2023-06-22 02:26:12 +02:00
"subscribers_count": 4
2021-04-04 17:10:08 +02:00
},
2022-08-05 02:16:53 +02:00
{
"id": 176323109,
"name": "CVE-2019-5418",
"full_name": "omarkurt\/CVE-2019-5418",
"owner": {
"login": "omarkurt",
"id": 1712468,
"avatar_url": "https:\/\/avatars.githubusercontent.com\/u\/1712468?v=4",
"html_url": "https:\/\/github.com\/omarkurt"
},
"html_url": "https:\/\/github.com\/omarkurt\/CVE-2019-5418",
"description": "File Content Disclosure on Rails Test Case - CVE-2019-5418",
"fork": false,
"created_at": "2019-03-18T16:09:13Z",
"updated_at": "2021-06-23T14:36:20Z",
"pushed_at": "2019-03-18T16:15:25Z",
"stargazers_count": 5,
"watchers_count": 5,
2022-11-08 07:19:29 +01:00
"has_discussions": false,
2023-06-12 20:30:51 +02:00
"forks_count": 2,
2022-08-05 02:16:53 +02:00
"allow_forking": true,
"is_template": false,
"web_commit_signoff_required": false,
"topics": [
"cve-2019-5418",
"ror",
"vulnerable-app"
],
"visibility": "public",
2023-06-12 20:30:51 +02:00
"forks": 2,
2022-08-05 02:16:53 +02:00
"watchers": 5,
2023-06-19 15:46:37 +02:00
"score": 0,
"subscribers_count": 0
2022-08-05 02:16:53 +02:00
},
{
"id": 176545257,
"name": "CVE-2019-5418-Scanner",
"full_name": "brompwnie\/CVE-2019-5418-Scanner",
"owner": {
"login": "brompwnie",
"id": 8638589,
"avatar_url": "https:\/\/avatars.githubusercontent.com\/u\/8638589?v=4",
"html_url": "https:\/\/github.com\/brompwnie"
},
"html_url": "https:\/\/github.com\/brompwnie\/CVE-2019-5418-Scanner",
"description": "A multi-threaded Golang scanner to identify Ruby endpoints vulnerable to CVE-2019-5418",
"fork": false,
"created_at": "2019-03-19T15:38:01Z",
2023-09-28 14:53:01 +02:00
"updated_at": "2023-09-28T10:59:36Z",
2022-08-05 02:16:53 +02:00
"pushed_at": "2019-03-21T17:26:06Z",
2023-09-28 14:53:01 +02:00
"stargazers_count": 35,
"watchers_count": 35,
2022-11-08 07:19:29 +01:00
"has_discussions": false,
2022-08-05 02:16:53 +02:00
"forks_count": 16,
"allow_forking": true,
"is_template": false,
"web_commit_signoff_required": false,
"topics": [],
"visibility": "public",
"forks": 16,
2023-09-28 14:53:01 +02:00
"watchers": 35,
2023-06-19 15:46:37 +02:00
"score": 0,
2023-07-03 02:29:41 +02:00
"subscribers_count": 3
2022-08-05 02:16:53 +02:00
},
2019-12-08 14:19:20 +01:00
{
2019-12-12 06:14:27 +01:00
"id": 177236589,
"name": "Rails-doubletap-RCE",
"full_name": "mpgn\/Rails-doubletap-RCE",
2019-12-12 05:48:20 +01:00
"owner": {
2019-12-12 06:14:27 +01:00
"login": "mpgn",
"id": 5891788,
2021-01-21 16:10:20 +01:00
"avatar_url": "https:\/\/avatars.githubusercontent.com\/u\/5891788?v=4",
2019-12-12 06:14:27 +01:00
"html_url": "https:\/\/github.com\/mpgn"
2019-12-12 05:48:20 +01:00
},
2019-12-12 06:14:27 +01:00
"html_url": "https:\/\/github.com\/mpgn\/Rails-doubletap-RCE",
"description": "RCE on Rails 5.2.2 using a path traversal (CVE-2019-5418) and a deserialization of Ruby objects (CVE-2019-5420)",
2019-12-12 05:48:20 +01:00
"fork": false,
2019-12-12 06:14:27 +01:00
"created_at": "2019-03-23T02:52:31Z",
2023-12-08 13:42:34 +01:00
"updated_at": "2023-12-08T09:20:13Z",
2023-01-19 13:33:38 +01:00
"pushed_at": "2023-01-19T12:13:40Z",
2023-12-08 13:42:34 +01:00
"stargazers_count": 128,
"watchers_count": 128,
2022-11-08 07:19:29 +01:00
"has_discussions": false,
2023-12-11 19:44:54 +01:00
"forks_count": 33,
2021-09-13 23:12:57 +02:00
"allow_forking": true,
2021-10-06 23:13:51 +02:00
"is_template": false,
2022-06-28 20:20:29 +02:00
"web_commit_signoff_required": false,
2021-10-06 23:13:51 +02:00
"topics": [
"rails"
],
2021-10-01 23:13:10 +02:00
"visibility": "public",
2023-12-11 19:44:54 +01:00
"forks": 33,
2023-12-08 13:42:34 +01:00
"watchers": 128,
2023-06-19 15:46:37 +02:00
"score": 0,
2023-06-22 02:26:12 +02:00
"subscribers_count": 7
2022-08-05 02:16:53 +02:00
},
{
"id": 178527770,
"name": "CVE-2019-5418",
"full_name": "takeokunn\/CVE-2019-5418",
"owner": {
"login": "takeokunn",
"id": 11222510,
"avatar_url": "https:\/\/avatars.githubusercontent.com\/u\/11222510?v=4",
"html_url": "https:\/\/github.com\/takeokunn"
},
"html_url": "https:\/\/github.com\/takeokunn\/CVE-2019-5418",
"description": null,
"fork": false,
"created_at": "2019-03-30T07:40:11Z",
"updated_at": "2019-10-24T19:07:56Z",
"pushed_at": "2019-03-30T07:54:58Z",
"stargazers_count": 2,
"watchers_count": 2,
2022-11-08 07:19:29 +01:00
"has_discussions": false,
2022-08-05 02:16:53 +02:00
"forks_count": 2,
"allow_forking": true,
"is_template": false,
"web_commit_signoff_required": false,
"topics": [],
"visibility": "public",
"forks": 2,
"watchers": 2,
2023-06-19 15:46:37 +02:00
"score": 0,
"subscribers_count": 2
2022-08-05 02:16:53 +02:00
},
{
"id": 178909066,
"name": "RailroadBandit",
"full_name": "Bad3r\/RailroadBandit",
"owner": {
"login": "Bad3r",
"id": 25513724,
"avatar_url": "https:\/\/avatars.githubusercontent.com\/u\/25513724?v=4",
"html_url": "https:\/\/github.com\/Bad3r"
},
"html_url": "https:\/\/github.com\/Bad3r\/RailroadBandit",
"description": "a demo for Ruby on Rails CVE-2019-5418",
"fork": false,
"created_at": "2019-04-01T17:02:57Z",
2023-04-12 14:36:16 +02:00
"updated_at": "2023-04-12T09:49:39Z",
2022-08-05 02:16:53 +02:00
"pushed_at": "2019-04-11T22:45:52Z",
2023-04-12 14:36:16 +02:00
"stargazers_count": 2,
"watchers_count": 2,
2022-11-08 07:19:29 +01:00
"has_discussions": false,
2022-08-05 02:16:53 +02:00
"forks_count": 0,
"allow_forking": true,
"is_template": false,
"web_commit_signoff_required": false,
"topics": [],
"visibility": "public",
"forks": 0,
2023-04-12 14:36:16 +02:00
"watchers": 2,
2023-06-19 15:46:37 +02:00
"score": 0,
"subscribers_count": 1
2022-08-05 02:16:53 +02:00
},
2022-10-17 14:17:39 +02:00
{
2023-01-02 13:13:52 +01:00
"id": 212888337,
"name": "CVE-2019-5418-Rails3",
"full_name": "ztgrace\/CVE-2019-5418-Rails3",
"owner": {
"login": "ztgrace",
"id": 2554037,
"avatar_url": "https:\/\/avatars.githubusercontent.com\/u\/2554037?v=4",
"html_url": "https:\/\/github.com\/ztgrace"
},
"html_url": "https:\/\/github.com\/ztgrace\/CVE-2019-5418-Rails3",
"description": "Rails 3 PoC of CVE-2019-5418",
"fork": false,
"created_at": "2019-10-04T19:28:10Z",
"updated_at": "2019-10-04T19:29:56Z",
2023-07-14 02:28:00 +02:00
"pushed_at": "2023-07-13T22:14:58Z",
2023-01-02 13:13:52 +01:00
"stargazers_count": 0,
"watchers_count": 0,
"has_discussions": false,
"forks_count": 1,
"allow_forking": true,
"is_template": false,
"web_commit_signoff_required": false,
"topics": [],
"visibility": "public",
"forks": 1,
"watchers": 0,
2023-06-19 15:46:37 +02:00
"score": 0,
"subscribers_count": 2
2023-01-02 13:13:52 +01:00
},
{
"id": 222660643,
2022-10-17 14:17:39 +02:00
"name": "CVE-2019-5418",
2023-01-02 13:13:52 +01:00
"full_name": "random-robbie\/CVE-2019-5418",
2022-10-17 14:17:39 +02:00
"owner": {
2023-01-02 13:13:52 +01:00
"login": "random-robbie",
"id": 4902869,
"avatar_url": "https:\/\/avatars.githubusercontent.com\/u\/4902869?v=4",
"html_url": "https:\/\/github.com\/random-robbie"
2022-10-17 14:17:39 +02:00
},
2023-01-02 13:13:52 +01:00
"html_url": "https:\/\/github.com\/random-robbie\/CVE-2019-5418",
"description": null,
2022-10-17 14:17:39 +02:00
"fork": false,
2023-01-02 13:13:52 +01:00
"created_at": "2019-11-19T09:40:06Z",
"updated_at": "2021-04-26T19:41:51Z",
"pushed_at": "2019-11-19T09:41:18Z",
"stargazers_count": 5,
"watchers_count": 5,
2022-11-08 07:19:29 +01:00
"has_discussions": false,
2023-01-02 13:13:52 +01:00
"forks_count": 1,
2022-10-17 14:17:39 +02:00
"allow_forking": true,
"is_template": false,
"web_commit_signoff_required": false,
"topics": [],
"visibility": "public",
2023-01-02 13:13:52 +01:00
"forks": 1,
"watchers": 5,
2023-06-19 15:46:37 +02:00
"score": 0,
2023-06-25 02:26:29 +02:00
"subscribers_count": 3
2023-01-07 01:35:14 +01:00
},
{
"id": 552810113,
"name": "CVE-2019-5418",
"full_name": "kailing0220\/CVE-2019-5418",
"owner": {
"login": "kailing0220",
"id": 115863969,
"avatar_url": "https:\/\/avatars.githubusercontent.com\/u\/115863969?v=4",
"html_url": "https:\/\/github.com\/kailing0220"
},
"html_url": "https:\/\/github.com\/kailing0220\/CVE-2019-5418",
"description": "Ruby on Rails是一个 Web 应用程序框架,是一个相对较新的 Web 应用程序框架,构建在 Ruby 语言之上。这个漏洞主要是由于Ruby on Rails使用了指定参数的render file来渲染应用之外的视图我们可以通过修改访问某控制器的请求包通过“…\/…\/…\/…\/”来达到路径穿越的目的,然后再通过“{{”来进行模板查询路径的闭合,使得所要访问的文件被当做外部模板来解析。",
"fork": false,
"created_at": "2022-10-17T09:04:43Z",
2023-01-13 19:30:07 +01:00
"updated_at": "2023-01-13T12:24:23Z",
2023-01-07 01:35:14 +01:00
"pushed_at": "2022-10-17T09:17:42Z",
2023-01-13 19:30:07 +01:00
"stargazers_count": 2,
"watchers_count": 2,
2023-01-07 01:35:14 +01:00
"has_discussions": false,
"forks_count": 0,
"allow_forking": true,
"is_template": false,
"web_commit_signoff_required": false,
"topics": [],
"visibility": "public",
"forks": 0,
2023-01-13 19:30:07 +01:00
"watchers": 2,
2023-06-19 15:46:37 +02:00
"score": 0,
"subscribers_count": 1
2019-12-08 14:19:20 +01:00
}
]