SecLists icon indicating copy to clipboard operation
SecLists copied to clipboard

please add this Unpublicly Paths in seclist that can leads to Mass Account Takeover And Sql on Oracle E-Business.

Open un9nplayer opened this issue 2 years ago • 5 comments

Vulnerable Oracel Database login path : /OA_HTML/AppsLocalLogin.jsp

1

Vulnerable Create User Path : /OA_HTML/ibeCAcpSSOReg.jsp an attacker can create a new user and get access to the database as a low user which is supposed not to be happening.

2

after that Attackers can take full access and leak mass user data publicly.

3

so, please add both paths in seclist in discovery for web-find.

un9nplayer avatar Jul 01 '22 15:07 un9nplayer

Feel free to make a pull request

g0tmi1k avatar Aug 02 '22 09:08 g0tmi1k

Feel free to make a pull request

I suspect that they made this issue because of the size of this repo; Some people don't want to have to clone 1.6GBs to be able to contribute :p

ItsIgnacioPortal avatar Aug 03 '22 09:08 ItsIgnacioPortal

Feel free to make a pull request

I suspect that they made this issue because of the size of this repo; Some people don't want to have to clone 1.6GBs to be able to contribute :p

well now you can do directly on github without cloning it

x0rld avatar Aug 16 '22 19:08 x0rld

Also, try pressing the period key on a repository's homepage to use a web version of VS Code that contains the repository's content. You can also pr directly from its view.

stampyzfanz avatar Aug 18 '22 07:08 stampyzfanz

Hi sir.. sorry needed the order please cancel the order 🙏

On Thu, 18 Aug 2022, 10:53 am stampyzfanz, @.***> wrote:

Also, try pressing the period key on a repository's homepage to use a web version of VS Code that contains the repository's content.

— Reply to this email directly, view it on GitHub https://github.com/danielmiessler/SecLists/issues/787#issuecomment-1219152308, or unsubscribe https://github.com/notifications/unsubscribe-auth/AZIQGCRHK26C4RJ6WK3N6GLVZXTYVANCNFSM52NAI7BQ . You are receiving this because you are subscribed to this thread.Message ID: @.***>

sumayanavha avatar Aug 18 '22 08:08 sumayanavha

Done (thanks to @molangning )

g0tmi1k avatar Nov 24 '23 10:11 g0tmi1k