github swisskyrepo/PayloadsAllTheThings 4.2
2025.1 - PayloadsAllTheThings - FERRETEDITOR

one month ago

This update brings significant new content, including dedicated pages for new vulnerability classes, fresh exploitation techniques for existing topics, and numerous quality-of-life improvements across the knowledge base.

πŸ“š New Vulnerability Pages

  • External Variable Modification: Complete new section covering PHP extract() function vulnerabilities, variable pollution, and security implications
  • Reverse Proxy Misconfigurations: Covering common Nginx misconfigurations.

πŸ”„ Enhanced Sections

  • Command Injection:

    • Added worstfit technique for argument injection
    • Enhanced with fullwidth character bypass methods
  • CSV Injection:

    • New Google Sheets exploitation section
    • Added formulas like IMPORTXML, IMPORTRANGE for data exfiltration
    • Enhanced with remote resource access techniques
  • File Inclusion:

    • New lightyear tool for blind file read primitives
    • Enhanced PHP filter exploitation techniques
  • Headless Browser:

    • New CVE exploitation section
    • Enhanced debugging port security implications
    • Added insecure flags and PDF rendering attack vectors
  • Java Deserialization:

    • Comprehensive JSON deserialization section (Jackson etc)
    • Enhanced with multiple attack vectors and exploitation techniques
  • SQL Injection:

    • New PDO Prepared Statements section

πŸ› Bug Fixes & Corrections

  • Fixed numerous formatting inconsistencies
  • Corrected broken internal links
  • Updated deprecated tool references
  • Standardized code block formatting
  • Standardized bullet points and list formatting across all sections
  • Automated markdown linting detection now runs on all pull requests and commits.

🌐 What's Changed

πŸ‘ŒNew Contributors

Full Changelog: 4.1...4.2

Don't miss a new PayloadsAllTheThings release

NewReleases is sending notifications on new releases.