CronUp / Vulnerabilidades

121 stars 28 forks source link

Check for the newest bypass of missing URL encoding #1

Closed LuemmelSec closed 2 years ago

LuemmelSec commented 2 years ago

Take newest bypass into consideration: https://doublepulsar.com/proxynotshell-the-story-of-the-claimed-zero-day-in-microsoft-exchange-5c63d963a9e9

Fix: Change the input {REQUEST_URI} to {UrlDecode:{REQUEST_URI}} https://twitter.com/honoki/status/1577653238517596160