Skip to content
This repository was archived by the owner on Oct 16, 2024. It is now read-only.

Commit b65558c

Browse files
cvex dir2 update
1 parent e7cfd28 commit b65558c

File tree

10 files changed

+119
-38
lines changed

10 files changed

+119
-38
lines changed

data/cvex_data/cvex_v2.json

Lines changed: 68 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,9 +1,74 @@
11
{
22
"cvex_v2_directory" : [
33
{
4-
"cveid": "todo",
5-
"cvexid": "todo",
6-
"authors":["todo"]
4+
"cveid": "CVE-XPLOR",
5+
"cvexid": "CVEX-XPLOR",
6+
"authors":["racheljiang310"],
7+
"version": 2.0,
8+
"domain": "ghcr.io/ucsb-seclab",
9+
"images": ["demo/client", "demo/server", "demo/listener"],
10+
"description": "A Proof of Concept Demonstration of our CVEX model/framework",
11+
"page": "/CVEX-XPLOR/"
12+
},
13+
{
14+
"cveid": "CVE-2017-1000499",
15+
"cvexid": "CVEX-2017-1000499",
16+
"authors":["racheljiang310"],
17+
"version": 2.0,
18+
"domain": "ghcr.io/ucsb-seclab",
19+
"images": ["cvex-2017-1000499/client", "cvex-2017-1000499/server", "cvex-2017-1000499/db", "cvex-2017-1000499/listener"],
20+
"description": "phpMyAdmin versions 4.7.x (prior to 4.7.6.1/4.7.7) are vulnerable to a CSRF weakness. By deceiving a user to click on a crafted URL, it is possible to perform harmful database operations such as deleting records, dropping/truncating tables etc.",
21+
"page": "/CVEX-2017-1000499/"
22+
},
23+
{
24+
"cveid": "CVE-2023-28155",
25+
"cvexid": "CVEX-2023-28155",
26+
"authors":["racheljiang310"],
27+
"version": 2.0,
28+
"domain": "ghcr.io/ucsb-seclab",
29+
"images": ["cvex-2023-28155/listener", "cvex-2023-28155/client", "cvex-2023-28155/bad_server", "cvex-2023-28155/php_server"],
30+
"description": "The Request package through 2.88.1 for Node.js allows a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS, or HTTPS to HTTP). This vulnerability only affects products that are no longer supported by the maintainer.",
31+
"page": "/CVEX-2023-28155/"
32+
},
33+
{
34+
"cveid": "CVE-2023-31419",
35+
"cvexid": "CVEX-2023-31419",
36+
"authors":["racheljiang310"],
37+
"version": 2.0,
38+
"domain": "ghcr.io/ucsb-seclab",
39+
"images": ["cvex-2023-31419/client","cvex-2023-31419/server","cvex-2023-31419/listener"],
40+
"description": "A flaw was discovered in Elasticsearch, affecting the _search API that allowed a specially crafted query string to cause a Stack Overflow and ultimately a Denial of Service.",
41+
"page": "/CVEX-2023-31419/"
42+
},
43+
{
44+
"cveid": "CVE-2023-42282",
45+
"cvexid": "CVEX-2023-42282",
46+
"authors":["racheljiang310"],
47+
"version": 2.0,
48+
"domain": "ghcr.io/ucsb-seclab",
49+
"images": ["cvex-2023-42282/client", "cvex-2023-42282/server", "cvex-2023-42282/listener"],
50+
"description": "The ip package before 1.1.9 for Node.js might allow SSRF because some IP addresses (such as 0x7f.1) are improperly categorized as globally routable via isPublic.",
51+
"page": "/CVEX-2023-42282/"
52+
},
53+
{
54+
"cveid": "CVE-2024-21508",
55+
"cvexid": "CVEX-2024-21508",
56+
"authors":["racheljiang310"],
57+
"version": 2.0,
58+
"domain": "ghcr.io/ucsb-seclab",
59+
"images": ["cvex-2023-42282/client", "cvex-2023-42282/server", "cvex-2023-42282/listener"],
60+
"description": "Found in versions of the mysql2 <= 3.9.4, this vulnerability allows for Remote Code Execution (RCE) through the readCodeFor function, due to improper validation of the supportBigNumbers and bigNumberStrings values. The potential impact includes high integrity and confidentiality impact, as well as high availability impact.",
61+
"page": "/CVEX-2024-21508/"
62+
},
63+
{
64+
"cveid": "CVE-2023-0286",
65+
"cvexid": "CVEX-2023-0286",
66+
"authors":["yarwinliu"],
67+
"version": 2.0,
68+
"domain": "ghcr.io/ucsb-seclab",
69+
"images": ["cvex-2024-21508/listener", "cvex-2024-21508/server", "cvex-2024-21508/client"],
70+
"description": "Clones openssl version 3.0.7, containing a vulnerability that attributes the wrong variable type (ASN1_TYPE rather than ASN1_STRING) to a x509 address, allowing elevation of privilege.",
71+
"page": "/CVEX-2023-0286/"
772
}
873
]
974
}

public/404.html

Lines changed: 5 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -39,9 +39,10 @@
3939
<div class="navbar__first">
4040
<ul class="navbar__list borders">
4141
<li><a href="http://localhost:1313/">Home</a></li>
42-
<li><a href="./directoryv1/">CVEXv1.0 Directory</a></li>
43-
<li><a href="./directoryv2/">CVEXv2.0 Directory</a></li>
44-
<li><a href="./research/">Research Initiative</a></li>
42+
<li><a href="./research/">Statement</a></li>
43+
<li><a href="./directoryv1/">CVEX 1.0 Directory</a></li>
44+
<li><a href="./directoryv2/">CVEX 2.0 Directory</a></li>
45+
4546
<li>
4647
<button class="theme-toggle transparent"><svg class="theme-toggler" width="24" height="24" viewBox="0 0 48 48" fill="none" xmlns="http://www.w3.org/2000/svg">
4748
<path
@@ -69,7 +70,7 @@ <h1 class="post-title">404 — Page not found...</h1>
6970
</main>
7071
<footer class="site-footer">
7172
<p class="buildinfo">
72-
<time datetime="2024-06-02 15:13:16 PDT">Site built on: 2024-06-02 15:13:16 PDT</time>
73+
<time datetime="2024-06-02 15:48:55 PDT">Site built on: 2024-06-02 15:48:55 PDT</time>
7374
</p>
7475
<div class="copyright">
7576
<p></p>

public/CVEX-2017-1000499/index.html

Lines changed: 5 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -42,9 +42,10 @@
4242
<div class="navbar__first">
4343
<ul class="navbar__list borders">
4444
<li><a href="http://localhost:1313/">Home</a></li>
45-
<li><a href="../directoryv1/">CVEXv1.0 Directory</a></li>
46-
<li><a href="../directoryv2/">CVEXv2.0 Directory</a></li>
47-
<li><a href="../research/">Research Initiative</a></li>
45+
<li><a href="../research/">Statement</a></li>
46+
<li><a href="../directoryv1/">CVEX 1.0 Directory</a></li>
47+
<li><a href="../directoryv2/">CVEX 2.0 Directory</a></li>
48+
4849
<li>
4950
<button class="theme-toggle transparent"><svg class="theme-toggler" width="24" height="24" viewBox="0 0 48 48" fill="none" xmlns="http://www.w3.org/2000/svg">
5051
<path
@@ -85,7 +86,7 @@ <h1 class="post-title"><a href="http://localhost:1313/CVEX-2017-1000499/">CVEX-2
8586
</main>
8687
<footer class="site-footer">
8788
<p class="buildinfo">
88-
<time datetime="2024-06-02 15:13:16 PDT">Site built on: 2024-06-02 15:13:16 PDT</time>
89+
<time datetime="2024-06-02 15:48:55 PDT">Site built on: 2024-06-02 15:48:55 PDT</time>
8990
</p>
9091
<div class="copyright">
9192
<p></p>

public/CVEX-2023-28155/index.html

Lines changed: 5 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -42,9 +42,10 @@
4242
<div class="navbar__first">
4343
<ul class="navbar__list borders">
4444
<li><a href="http://localhost:1313/">Home</a></li>
45-
<li><a href="../directoryv1/">CVEXv1.0 Directory</a></li>
46-
<li><a href="../directoryv2/">CVEXv2.0 Directory</a></li>
47-
<li><a href="../research/">Research Initiative</a></li>
45+
<li><a href="../research/">Statement</a></li>
46+
<li><a href="../directoryv1/">CVEX 1.0 Directory</a></li>
47+
<li><a href="../directoryv2/">CVEX 2.0 Directory</a></li>
48+
4849
<li>
4950
<button class="theme-toggle transparent"><svg class="theme-toggler" width="24" height="24" viewBox="0 0 48 48" fill="none" xmlns="http://www.w3.org/2000/svg">
5051
<path
@@ -85,7 +86,7 @@ <h1 class="post-title"><a href="http://localhost:1313/CVEX-2023-28155/">CVEX-202
8586
</main>
8687
<footer class="site-footer">
8788
<p class="buildinfo">
88-
<time datetime="2024-06-02 15:13:16 PDT">Site built on: 2024-06-02 15:13:16 PDT</time>
89+
<time datetime="2024-06-02 15:48:55 PDT">Site built on: 2024-06-02 15:48:55 PDT</time>
8990
</p>
9091
<div class="copyright">
9192
<p></p>

public/CVEX-2023-31419/index.html

Lines changed: 5 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -42,9 +42,10 @@
4242
<div class="navbar__first">
4343
<ul class="navbar__list borders">
4444
<li><a href="http://localhost:1313/">Home</a></li>
45-
<li><a href="../directoryv1/">CVEXv1.0 Directory</a></li>
46-
<li><a href="../directoryv2/">CVEXv2.0 Directory</a></li>
47-
<li><a href="../research/">Research Initiative</a></li>
45+
<li><a href="../research/">Statement</a></li>
46+
<li><a href="../directoryv1/">CVEX 1.0 Directory</a></li>
47+
<li><a href="../directoryv2/">CVEX 2.0 Directory</a></li>
48+
4849
<li>
4950
<button class="theme-toggle transparent"><svg class="theme-toggler" width="24" height="24" viewBox="0 0 48 48" fill="none" xmlns="http://www.w3.org/2000/svg">
5051
<path
@@ -85,7 +86,7 @@ <h1 class="post-title"><a href="http://localhost:1313/CVEX-2023-31419/">CVEX-202
8586
</main>
8687
<footer class="site-footer">
8788
<p class="buildinfo">
88-
<time datetime="2024-06-02 15:13:16 PDT">Site built on: 2024-06-02 15:13:16 PDT</time>
89+
<time datetime="2024-06-02 15:48:55 PDT">Site built on: 2024-06-02 15:48:55 PDT</time>
8990
</p>
9091
<div class="copyright">
9192
<p></p>

public/categories/index.html

Lines changed: 5 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -39,9 +39,10 @@
3939
<div class="navbar__first">
4040
<ul class="navbar__list borders">
4141
<li><a href="http://localhost:1313/">Home</a></li>
42-
<li><a href="../directoryv1/">CVEXv1.0 Directory</a></li>
43-
<li><a href="../directoryv2/">CVEXv2.0 Directory</a></li>
44-
<li><a href="../research/">Research Initiative</a></li>
42+
<li><a href="../research/">Statement</a></li>
43+
<li><a href="../directoryv1/">CVEX 1.0 Directory</a></li>
44+
<li><a href="../directoryv2/">CVEX 2.0 Directory</a></li>
45+
4546
<li>
4647
<button class="theme-toggle transparent"><svg class="theme-toggler" width="24" height="24" viewBox="0 0 48 48" fill="none" xmlns="http://www.w3.org/2000/svg">
4748
<path
@@ -70,7 +71,7 @@ <h1 class="post-title">
7071
</main>
7172
<footer class="site-footer">
7273
<p class="buildinfo">
73-
<time datetime="2024-06-02 15:13:16 PDT">Site built on: 2024-06-02 15:13:16 PDT</time>
74+
<time datetime="2024-06-02 15:48:55 PDT">Site built on: 2024-06-02 15:48:55 PDT</time>
7475
</p>
7576
<div class="copyright">
7677
<p></p>

public/cvex/index.html

Lines changed: 5 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -39,9 +39,10 @@
3939
<div class="navbar__first">
4040
<ul class="navbar__list borders">
4141
<li><a href="http://localhost:1313/">Home</a></li>
42-
<li><a href="../directoryv1/">CVEXv1.0 Directory</a></li>
43-
<li><a href="../directoryv2/">CVEXv2.0 Directory</a></li>
44-
<li><a href="../research/">Research Initiative</a></li>
42+
<li><a href="../research/">Statement</a></li>
43+
<li><a href="../directoryv1/">CVEX 1.0 Directory</a></li>
44+
<li><a href="../directoryv2/">CVEX 2.0 Directory</a></li>
45+
4546
<li>
4647
<button class="theme-toggle transparent"><svg class="theme-toggler" width="24" height="24" viewBox="0 0 48 48" fill="none" xmlns="http://www.w3.org/2000/svg">
4748
<path
@@ -80,7 +81,7 @@ <h2>See</h2><div class="post-entries">
8081
</main>
8182
<footer class="site-footer">
8283
<p class="buildinfo">
83-
<time datetime="2024-06-02 15:13:16 PDT">Site built on: 2024-06-02 15:13:16 PDT</time>
84+
<time datetime="2024-06-02 15:48:55 PDT">Site built on: 2024-06-02 15:48:55 PDT</time>
8485
</p>
8586
<div class="copyright">
8687
<p></p>

public/index.html

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -90,7 +90,7 @@ <h3 id="what-is-a-cvex">
9090
</main>
9191
<footer class="site-footer">
9292
<p class="buildinfo">
93-
<time datetime="2024-06-02 15:14:21 PDT">Site built on: 2024-06-02 15:14:21 PDT</time>
93+
<time datetime="2024-06-02 15:48:55 PDT">Site built on: 2024-06-02 15:48:55 PDT</time>
9494
</p>
9595
<div class="copyright">
9696
<p></p>

public/tags/index.html

Lines changed: 5 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -39,9 +39,10 @@
3939
<div class="navbar__first">
4040
<ul class="navbar__list borders">
4141
<li><a href="http://localhost:1313/">Home</a></li>
42-
<li><a href="../directoryv1/">CVEXv1.0 Directory</a></li>
43-
<li><a href="../directoryv2/">CVEXv2.0 Directory</a></li>
44-
<li><a href="../research/">Research Initiative</a></li>
42+
<li><a href="../research/">Statement</a></li>
43+
<li><a href="../directoryv1/">CVEX 1.0 Directory</a></li>
44+
<li><a href="../directoryv2/">CVEX 2.0 Directory</a></li>
45+
4546
<li>
4647
<button class="theme-toggle transparent"><svg class="theme-toggler" width="24" height="24" viewBox="0 0 48 48" fill="none" xmlns="http://www.w3.org/2000/svg">
4748
<path
@@ -70,7 +71,7 @@ <h1 class="post-title">
7071
</main>
7172
<footer class="site-footer">
7273
<p class="buildinfo">
73-
<time datetime="2024-06-02 15:13:16 PDT">Site built on: 2024-06-02 15:13:16 PDT</time>
74+
<time datetime="2024-06-02 15:48:55 PDT">Site built on: 2024-06-02 15:48:55 PDT</time>
7475
</p>
7576
<div class="copyright">
7677
<p></p>

themes/hugo-xterm/layouts/_default/directory2.html

Lines changed: 15 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -15,12 +15,21 @@ <h5>{{- with .Content }}
1515
{{ . }}
1616
{{- end }}</h5>
1717

18-
{{ range $.Site.Data.cvex_data.cvex_v2.cvex_v2_directory }}
19-
<strong>{{.cveid}}</strong>: {{ .cvexid }}
20-
<ul>
21-
<li>Authors: {{ delimit .authors ", " }}</li>
22-
</ul>
23-
{{ end }}
18+
<table>
19+
<tr>
20+
<th style="width:20%"><strong>CVEX</strong></th>
21+
<th style="width:50%"><strong>Description</strong></th>
22+
<th style="width:30%"><strong>Images</strong></th>
23+
</tr>
24+
{{ range $.Site.Data.cvex_data.cvex_v2.cvex_v2_directory }}
25+
<tr>
26+
<td><tt>{{ .cveid }}</tt></td>
27+
<!-- <td><tt><a href={{.cvexid}}>{{.cvexid}}</a></tt></td> -->
28+
<td><strong>Author |</strong> <tt>{{ delimit .authors ", " }}</tt> <br> {{.description}}</td>
29+
<td><strong>Domain | </strong>{{.domain}}<br><details><small><tt>{{ range .images }}{{.}}<br>{{end}}</tt></small></details></td>
30+
</tr>
31+
{{- end}}
32+
</table>
2433
</div>
2534

2635
<footer class="post-footer">

0 commit comments

Comments
 (0)