Skip to content

Releases: ricardojba/poi-slinger

2.0

25 Mar 10:11
bdf3de4
Compare
Choose a tag to compare
2.0

Add payload Symfony/RCE5

1.9

14 Feb 18:19
2a5546a
Compare
Choose a tag to compare
1.9

Context menu bug fix.

1.8

08 Jan 22:44
350509f
Compare
Choose a tag to compare
1.8

Add payloads WordPress/PHPExcel (1-6)

Fix (lack of) encoding on payloads:

  • Yii2 < 2.0.38 (CVE-2020-15148) (1)
  • ZendFramework ? <= 1.12.20 (4)
  • WordPress/P/WooCommerce <= 3.4.0 (2)

1.7

04 Jan 18:00
0a84239
Compare
Choose a tag to compare
1.7

Add Yii2 RCE2 - a variant of Yii2 RCE1
More info here: https://blog.redteam-pentesting.de/2021/deserialization-gadget-chain/

1.6

09 Dec 11:53
207606c
Compare
Choose a tag to compare
1.6

Updated affected versions for Monolog payloads
Add CVE identification for Yii2 RCE2
CodeIgniter4 smaller payload

1.5

28 Nov 17:36
cbf94a5
Compare
Choose a tag to compare
1.5

Fixed payload typos and errors
Added new PHPGCC POP Chains

  • WordPress/WooCommerce/RCE2
  • ZendFramework/RCE4
  • Yii2/RCE1
  • Laravel/RCE7

1.4

27 Jul 10:02
c8f5eec
Compare
Choose a tag to compare
1.4

Fix extension unloading

1.3

22 May 14:00
0e27a94
Compare
Choose a tag to compare
1.3
Fix extension unloading

Threads not exiting after extension unloading on the Extender Tab
"Any extensions that start background threads or open system resources (such as files or database connections) should register a listener and terminate threads / close resources when the extension is unloaded."
REF: https://portswigger.net/burp/extender/api/burp/IExtensionStateListener.html

1.2

20 May 17:46
6e36308
Compare
Choose a tag to compare
1.2
New Build

Added new PHPGCC POP Chains
Fixed payload typos and errors
Fixed hard coded use of HTTPS