Laravel
Laravel Pentesting / Exploits
Detection
Version
Enumeration
SSTI
SSTICVE
CVE-2021-3129 (Remote Code Execution)

Exposed environment variable

RCE
Exposed log files
Debug mode
Laravel FileManager

.env
Decrypt Cookie
Laravel crypto killer - Deserialization attacks
CVE-2024-55555 - Invoice Ninja
CVE-2024-48987 - Snipe IT - XSRF-TOKEN serialization
CVE-2024-55556 - Crater - Vulnerable SESSION_DRIVER cookie
Cookie
Checks 'laravel_session' cookies for known laravel 'APP_KEY'
Cookie Monster
Cookie Monster
APP_KEY - Bruteforce
APP_KEY top 10
Position
Number of public servers sharing it
APP_KEY
Description
Position
Number of public servers sharing it
APP_KEY
Description
Position since 2024
Scanners
Other exploits
Resources
Interesting Books
Interesting BooksSupport this Gitbook
Last updated
