PkgRadar

Go modules · proxy.golang.org

github.com/Method-Security/webscan

DNS / OAST exfiltration: matched "oast.pro"

Why PkgRadar flagged v0.0.265

SeveritySignalEvidence
highDNS / OAST exfiltrationmatched "oast.pro" · github.com/method-security/[email protected]/utils/nuclei/templates/pentest/scan/cve/2017/CVE-2017-14725.yaml
highDNS / OAST exfiltrationmatched "oast.pro" · github.com/method-security/[email protected]/utils/nuclei/templates/pentest/scan/cve/2018/CVE-2018-11686.yaml
highDNS / OAST exfiltrationmatched "oast.fun" · github.com/method-security/[email protected]/utils/nuclei/templates/pentest/scan/cve/2019/CVE-2019-18394.yaml
highDNS / OAST exfiltrationmatched "oastify.com" · github.com/method-security/[email protected]/utils/nuclei/templates/pentest/scan/cve/2020/CVE-2020-11984.yaml
highDNS / OAST exfiltrationmatched "oast.fun" · github.com/method-security/[email protected]/utils/nuclei/templates/pentest/scan/cve/2020/CVE-2020-26948.yaml
highDNS / OAST exfiltrationmatched "oast.pro" · github.com/method-security/[email protected]/utils/nuclei/templates/pentest/scan/cve/2021/CVE-2021-40822.yaml
highDNS / OAST exfiltrationmatched "oast.pro" · github.com/method-security/[email protected]/utils/nuclei/templates/pentest/scan/cve/2022/CVE-2022-0597.yaml
highDNS / OAST exfiltrationmatched "oast.pro" · github.com/method-security/[email protected]/utils/nuclei/templates/pentest/scan/cve/2022/CVE-2022-23544.yaml
highDNS / OAST exfiltrationmatched "interactsh.com" · github.com/method-security/[email protected]/utils/nuclei/templates/pentest/scan/cve/2022/CVE-2022-40083.yaml
highDNS / OAST exfiltrationmatched "oast.fun" · github.com/method-security/[email protected]/utils/nuclei/templates/pentest/scan/cve/2022/CVE-2022-41412.yaml
highDNS / OAST exfiltrationmatched "oast.fun" · github.com/method-security/[email protected]/utils/nuclei/templates/pentest/scan/cve/2022/CVE-2022-42149.yaml
highDNS / OAST exfiltrationmatched "oast.pro" · github.com/method-security/[email protected]/utils/nuclei/templates/pentest/scan/cve/2023/CVE-2023-22432.yaml

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.265High risk1542026-06-16
v0.0.264High risk1542026-06-16
v0.0.263High risk1422026-06-15
v0.0.262High risk1422026-06-15
v0.0.260High risk1422026-06-14
v0.0.259High risk1422026-06-13
v0.0.258High risk1422026-06-13
v0.0.256High risk1422026-06-12
v0.0.247High risk1422026-06-12
v0.0.250High risk1422026-06-12
v0.0.249High risk1422026-06-12
v0.0.254High risk1422026-06-12
v0.0.252High risk1422026-06-10
v0.0.248High risk1422026-06-09
v0.0.242High risk1422026-06-04
v0.0.241High risk1422026-05-30
v0.0.239High risk1422026-05-30
v0.0.240High risk1422026-05-30

Block this in CI

PkgRadar gates github.com/Method-Security/webscan (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/Method-Security/[email protected]