๐ฐ Exploit Author News
Page 10 - Exploit Author News Today
Fast, Ad-Free News Updates
Stay updated with breaking news from Exploit Author. Real-time updates on events, politics, business and more.
May 19, 2023
# Exploit Title: Bludit CMS v3.14.1 - Stored Cross-Site Scripting (XSS)(Authenticated)# Date: 2023-04-15# Exploit Author: Rahad Chowdhury# Vendor Homepage: https://www.bludit.com/# Software Link: https://github.com/bludit/bludit/releases/tag/3.14.1# Version: 3.14.1# Tested on: Windows 10, PHP 7.4.29, Apache 2.4.53# CVE: CVE-2023-31698SVG Payload-------------save this SVG file xss.svgSteps to Reproduce:1. At first login your admin panel.2. then go to setting and click logo
May 8, 2023
# Exploit Title: Stored-XSS in FICO Origination Manager Decision Module 4.8.1 Leads to Session Hijacking# Date: 2023-05-07# Exploit Author: Matei Josephs# Vendor Homepage: https://www.fico.com/# Version: FICO Origination Manager Decision Module 4.8.1# CVE : CVE-2023-30056, CVE-2023-30057Introduction=================Multiple stored cross-site scripting (XSS) vulnerabilities in FICO Origination Manager Decision Module 4.8.1 allow to execute code in the context of
May 6, 2023
# Exploit Title: Codigo Markdown Editor v1.0.1 (Electron) - Arbitrary Code Execution# Date: 2023-05-03# Exploit Author: 8bitsec# Vendor Homepage: https://alfonzm.github.io/codigo/# Software Link: https://github.com/alfonzm/codigo-app# Version: 1.0.1# Tested on: [Mac OS 13]Release Date:=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D2023-05-03Product & Service Introduction:=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D==3D=3D=3D=3D=3D=3DA Markdown editor & notes app ma...
May 6, 2023
# Exploit Title: Online Pizza Ordering System 1.0 - Unauthenticated File Upload# Date: 03/05/2023# Exploit Author: URGAN # Vendor Homepage: https://www.sourcecodester.com/php/16166/online-pizza-ordering-system-php-free-source-code.html# Software Link: https://www.sourcecodester.com/sites/default/files/download/oretnom23/php-opos.zip# Version: v1.0# Tested on: LAMP Fedora Server 27 (Twenty Seven) Apache/2.4.34 (Fedora) 10.2.19-MariaDB PHP 7.1.23 # CVE: CVE-2023-2246#!/usr/bin/env python3# coding:...
May 5, 2023
# Exploit Title: Jedox 2020.2.5 - Remote Code Execution via Configurable Storage Path# Date: 28/04/2023# Exploit Author: Team Syslifters / Christoph MAHRL, Aron MOLNAR, Patrick PIRKER and Michael WEDL# Vendor Homepage: https://jedox.com# Version: Jedox 2020.2 (20.2.5) and older# CVE : CVE-2022-47878Introduction=================Incorrect input validation for the default storage path variable in the settings page allows remote,
May 5, 2023
# Exploit Title: Jedox 2020.2.5 - Disclosure of Database Credentials via Improper Access Controls# Date: 28/04/2023# Exploit Author: Team Syslifters / Christoph MAHRL, Aron MOLNAR, Patrick PIRKER and Michael WEDL# Vendor Homepage: https://jedox.com# Version: Jedox 2020.2 (20.2.5) and older# CVE : CVE-2022-47874Introduction=================Improper access controls in `/tc/rpc` allows remote authenticated users to view details of database
May 5, 2023
# Exploit Title: Jedox 2022.4.2 - Disclosure of Database Credentials via Connection Checks# Date: 28/04/2023# Exploit Author: Team Syslifters / Christoph MAHRL, Aron MOLNAR, Patrick PIRKER and Michael WEDL# Vendor Homepage: https://jedox.com# Version: Jedox 2022.4 (22.4.2) and older# CVE : CVE-2022-47880Introduction=================An information disclosure vulnerability in `/be/rpc.php` allows remote authenticated users with the appropriate permissions to
May 4, 2023
# Exploit Title: Unauthenticated SQL injection- Google Dork:- Date: 27.04.2023- Exploit Author: Lucas Noki (0xPrototype)- Vendor Homepage: https://github.com/vogtmh- Software Link: https://github.com/vogtmh/cmaps- Version: 8.0- Tested on: Mac, Windows, Linux- CVE : CVE-2023-29809*Description:*The vulnerability found is an SQL injection. The `bookmap` parameter is vulnerable. When visiting the page: http://192.168.0.56/rest/booking/index.php?mode=list&bookmap=test we get the normal JSON respo...
May 4, 2023
# Exploit Title: Reflected Cross Site Scripting- Google Dork:- Date: 27.04.2023- Exploit Author: Lucas Noki (0xPrototype)- Vendor Homepage: https://github.com/vogtmh- Software Link: https://github.com/vogtmh/cmaps- Version: 8.0- Tested on: Mac, Windows, Linux- CVE : CVE-2023-29808*Description:*The vulnerability found is Reflected Cross Site Scripting. When the `/index.php?map=overview&findme=` endpoint is hit with a request where the "findme" parameter contains a malicious
May 3, 2023
# Exploit Title: PHPJabbers Simple CMS 5.0 - SQL Injection# Date: 2023-04-29# Exploit Author: Ahmet รmit BAYRAM# Vendor Homepage: https://www.phpjabbers.com/faq.php# Software Link: https://www.phpjabbers.com/simple-cms/# Version: 5.0# Tested on: Kali Linux### Request ###GET/simplecms/index.php?action=pjActionGetFile&column=created&controller=pjAdminFiles&direction=DESC&page=0&rowCount=10HTTP/1.1Accept: */*x-requested-with: XMLHttpRequestReferer: https://localhost/simplecms/p...