Biggest News Aggregation in the World
๐Ÿ“ฐ Exploit Author News

Page 2 - Exploit Author News Today

Fast, Ad-Free News Updates

Stay updated with breaking news from Exploit Author. Real-time updates on events, politics, business and more.

Elasticsearch 8.5.3 Stack Overflow - KizzMyAnthia.com

# Exploit Author: TOUHAMI KASBAOUI# Vendor Homepage: https://elastic.co/# Version: 8.5.3 / OpenSearch# Tested on: Ubuntu 20.04 LTS# CVE : CVE-2023-31419# Ref: https://github.com/sqrtZeroKnowledge/Elasticsearch-Exploit-CVE-2023-31419import requestsimport randomimport stringes_url = 'http://localhost:9200' # Replace with your Elasticsearch server URLindex_name = '*'payload = "/*" * 10000 + "" +"'" * 999verify_ssl = Falseusername = 'elasti...
Exploit Author Vendor Homepage Search Query

Free And Open Source Inventory Management System 1.0 SQL Injection

# Exploit Title: Free and Open Source Inventory Management System 1.0 - Unauthenticated SQL Injection# Exploit Author: Sefa Ozan# Date: 16/09/2023# Vendor: MAYURIK# Vendor Homepage: https://mayurik.com/# Software Link: https://www.sourcecodester.com/php/16741/free-and-open-source-inventory-management-system-php-source-code.html# Tested on: Windows 10 Pro & Ubuntu 22.04## Description:The `pid[]` parameter is vulnerable to Time Based SQL injection attacks. To prove the existence of the vulnera...
Sefa Ozan Software Link Exploit Title Open Source Inventory Management System Exploit Author Vendor Homepage

Academy LMS 6.2 Cross Site Scripting - KizzMyAnthia.com

# Exploit Title: Academy LMS 6.2 - Reflected XSS# Exploit Author: CraCkEr# Date: 29/08/2023# Vendor: Creativeitem# Vendor Homepage: https://creativeitem.com/# Software Link: https://demo.creativeitem.com/academy/# Tested on: Windows 10 Pro# Impact: Manipulate the content of the site# CVE: CVE-2023-4973# CWE: CWE-79 - CWE-74 - CWE-707## GreetingsThe_PitBull, Raz0r, iNs, SadsouL, His0k4, Hussin X, Mr. SQL , MoizSid09, indoushkaCryptoJob (Twitter)
Software Link Exploit Title Exploit Author Vendor Homepage

Academy LMS 6.2 SQL Injection - KizzMyAnthia.com

# Exploit Title: Academy LMS 6.2 - SQL Injection# Exploit Author: CraCkEr# Date: 29/08/2023# Vendor: Creativeitem# Vendor Homepage: https://creativeitem.com/# Software Link: https://demo.creativeitem.com/academy/# Tested on: Windows 10 Pro# Impact: Database Access# CVE: CVE-2023-4974# CWE: CWE-89 / CWE-74 / CWE-707## GreetingsThe_PitBull, Raz0r, iNs, SadsouL, His0k4, Hussin X, Mr. SQL , MoizSid09, indoushkaCryptoJob (Twitter) twitter.com/0x0CryptoJob## DescriptionSQL injection attacks
Software Link Exploit Title Exploit Author Vendor Homepage

OpenCart CMS 4.0.2.2 Brute Force - KizzMyAnthia.com

# Exploit Title: OpenCart CMS v4.0.2.2 Login Vulnerability# Date: 5-9-2023# Category: Web Application [CMS]# Exploit Author: Rajdip Dey Sarkar# Version: 4.0.2.2# Tested on: Windows/Kali# CVE: CVE-2023-40834Description:----------------OpenCart CMS version 4.0.2.2 is susceptible to login brute-force attacks,where attackers can repeatedly try to guess login credentials without anyprotective mechanisms in place.Vulnerable Parameter:-----------------------`Password`Steps to reproduce:----------------...
Rajdip Dey Sarkar Exploit Title Web Application Exploit Author Rajdip Dey Initial Login Attempt

Stay Updated with Latest News

Get breaking news updates delivered to your inbox

Browse All News โ†’

Kingo ROOT 1.5.8 Unquoted Service Path - KizzMyAnthia.com

#Exploit Title: Kingo ROOT 1.5.8 - Unquoted Service Path#Date: 8/22/2023#Exploit Author: Anish Feroz (ZEROXINN)#Vendor Homepage: https://www.kingoapp.com/#Software Link: https://www.kingoapp.com/android-root/download.htm#Version: 1.5.8.3353#Tested on: Windows 10 Pro-------------Discovering Unquoted Path--------------C:UsersAnish>sc qc KingoSoftService[SC] QueryServiceConfig SUCCESSSERVICE_NAME: KingoSoftServiceTYPE : 110 WIN32_OWN_PROCESS (interactive)START_TYPE : 2 AUTO_STARTERROR_CONTROL : ...
Usersusmanappdatalocalkingosoftkingo Rootupdate Anish Feroz Service Path Software Link Exploit Title Unquoted Service

FileMage Gateway 1.10.9 Local File Inclusion - KizzMyAnthia.com

# Exploit Title: FileMage Gateway 1.10.9 - Local File Inclusion# Date: 8/22/2023# Exploit Author: Bryce "Raindayzz" Harty # Vendor Homepage: https://www.filemage.io/# Version: Azure Versions < 1.10.9# Tested on: All Azure deployments < 1.10.9 # CVE : CVE-2023-39026# Technical Blog - https://raindayzz.com/technicalblog/2023/08/20/FileMage-Vulnerability.html# Patch from vendor - https://www.filemage.io/docs/updates.htmlimport requestsimport warningswarnings.filterwarnings("ign...
Bryce Raindayzz Harty Exploit Title Filemage Gateway Local File Exploit Author Vendor Homepage

CSZ CMS 1.3.0 Cross Site Scripting - KizzMyAnthia.com

# Exploit Title: CSZ CMS 1.3.0 - Stored Cross-Site Scripting (Plugin 'Gallery')# Date: 2023/08/18# CVE: CVE-2023-38911# Exploit Author: Daniel Gonzรกlez# Vendor Homepage: https://www.cszcms.com/# Software Link: https://github.com/cskaza/cszcms# Version: 1.3.0# Tested on: CSZ CMS 1.3.0# Description:# CSZ CMS 1.3.0 is affected by a cross-site scripting (XSS) feature that allows attackers to execute arbitrary web scripts or HTML
Daniel Gonz Software Link Exploit Title Stored Cross Site Scripting Exploit Author Vendor Homepage

AdminLTE PiHole Broken Access Control - KizzMyAnthia.com

# Exploit Title: AdminLTE PiHole < 5.18 - Broken Access Control# Google Dork: [inurl:admin/scripts/pi-hole/phpqueryads.php](https://vuldb.com/?exploit_googlehack.216554)# Date: 21.12.2022# Exploit Author: kv1to# Version: Pi-hole v5.14.2; FTL v5.19.2; Web Interface v5.17# Tested on: Raspbian / Debian# Vendor: https://github.com/pi-hole/AdminLTE/security/advisories/GHSA-6qh8-6rrj-7497# CVE : CVE-2022-23513In case of an attack, the threat actor will obtain the ability to perform an unauthorized ...
Raspbian Debian Exploit Title Google Dork Exploit Author Web Interface Proof Of Concept

PlayTube 3.0.1 Information Disclosure - KizzMyAnthia.com

# Exploit Title: PlayTube 3.0.1 - Redirect Information Disclosure# Exploit Author: CraCkEr# Date: 19/08/2023# Vendor: PlayTube# Vendor Homepage: https://playtubescript.com/# Software Link: https://demo.playtubescript.com/# Tested on: Windows 10 Pro# Impact: Sensitive Information Leakage# CVE: CVE-2023-4714# CWE: CWE-200 - CWE-284 - CWE-266## GreetingsThe_PitBull, Raz0r, iNs, SadsouL, His0k4, Hussin X, Mr. SQL , MoizSid09, indoushkaCryptoJob (Twitter) twitter.com/0x0CryptoJob## DescriptionInforma...
Software Link Administration Panel Exploit Title Redirect Information Exploit Author Vendor Homepage

Explore More Categories

World News India News Business Technology Sports Entertainment Health Science