Biggest News Aggregation in the World
📰 Exploit Author News

Page 6 - Exploit Author News Today

Fast, Ad-Free News Updates

Stay updated with breaking news from Exploit Author. Real-time updates on events, politics, business and more.

October CMS 3.4.4 Cross Site Scripting - KizzMyAnthia.com

#Exploit Title: October CMS v3.4.4 - Stored Cross-Site Scripting (XSS) (Authenticated)#Date: 29 June 2023#Exploit Author: Okan Kurtulus#Vendor Homepage: https://octobercms.com#Version: v3.4.4#Tested on: Ubuntu 22.04#CVE : N/A# Proof of Concept:1– Install the system through the website and log in with any user with file upload authority.2– Select "Media" in the top menu. Prepare an SVG file using
Okan Kurtulus Exploit Title Stored Cross Site Scripting Exploit Author Vendor Homepage

Joomla Solidres 2.13.3 Cross Site Scripting - KizzMyAnthia.com

# Exploit Title: Joomla Solidres 2.13.3 - Reflected XSS# Exploit Author: CraCkEr# Date: 28/07/2023# Vendor: Solidres Team# Vendor Homepage: http://solidres.com/# Software Link: https://extensions.joomla.org/extension/vertical-markets/booking-a-reservations/solidres/# Demo: http://demo.solidres.com/joomla# Tested on: Windows 10 Pro# Impact: Manipulate the content of the site ## GreetingsThe_PitBull, Raz0r, iNs, SadsouL, His0k4, Hussin X, Mr. SQL , MoizSid09, indoushka CryptoJob (Twitter) twitter....
Joomla Solidres Software Link Solidres Team Exploit Title Exploit Author Vendor Homepage

Online Piggery Management System 1.0 Shell Upload

#!/bin/bash# Exploit Title: Online Piggery Management System v1.0 - unauthenticated file upload vulnerability# Date: July 12 2023# Exploit Author: 1337kid# Software Link: https://www.sourcecodester.com/php/11814/online-pig-management-system-basic-free-version.html# Version: 1.0# Tested on: Ubuntu# CVE : CVE-2023-37629## chmod +x exploit.sh# ./exploit.sh web_url# ./exploit.sh http://127.0.0.1:8080/echo " _____ _____ ___ __ ___ ____ ________ __ ___ ___ "echo " / __ / /
Software Link Exploit Title Online Piggery Management System Exploit Author

Hikvision Hybrid SAN Ds-a71024 SQL Injection - KizzMyAnthia.com

# Exploit Title: Hikvision Hybrid SAN Ds-a71024 Firmware - Multiple Remote Code Execution# Date: 16 July 2023# Exploit Author: Thurein Soe# CVE : CVE-2022-28171# Vendor Homepage: https://www.hikvision.com# Software Link: N/A# Refence Link: https://cve.report/CVE-2022-28171# Version: Filmora 12: Ds-a71024 Firmware, Ds-a71024 Firmware Ds-a71048r-cvs Firmware Ds-a71048 Firmware Ds-a71072r Firmware Ds-a71072r Firmware Ds-a72024 Firmware Ds-a72024 Firmware Ds-a72048r-cvs Firmware Ds-a72072r
Software Link Exploit Title Hikvision Hybrid Multiple Remote Code Exploit Author Vendor Homepage

Stay Updated with Latest News

Get breaking news updates delivered to your inbox

Browse All News →

Foody Friend 1.0 Arbitrary File Upload / Cross Site Scripting

# Exploit Title: Foody Friend 1.0 - Arbitrary File Upload# Exploit Author: CraCkEr# Date: 12/07/2023# Vendor: Bug Finder# Vendor Homepage: https://bugfinder.net/# Software Link: https://bugfinder.net/product/foody-friend-a-saas-based-web-app-food-ordering-bot-for-telegram-and-messenger/25# Tested on: Windows 10 Pro# Impact: Allows User to upload files to the web server## DescriptionAllows Attacker to upload malicious files onto the server, such as Stored XSS## Steps to Reproduce:1.
Software Link Exploit Title Foody Friend Arbitrary File Exploit Author Vendor Homepage

TP-Link TL-WR740N Directory Traversal - KizzMyAnthia.com

# Exploit Title: TP-Link TL-WR740N - Authenticated Directory Transversal# Date: 13/7/2023# Exploit Author: Anish Feroz (Zeroxinn)# Vendor Homepage: http://www.tp-link.com# Version: TP-Link TL-WR740n 3.12.11 Build 110915 Rel.40896n# Tested on: TP-Link TL-WR740N---------------------------POC---------------------------Request-------GET /help/../../../etc/shadow HTTP/1.1Host: 192.168.0.1:8082Authorization: Basic YWRtaW46YWRtaW4=Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Wi...
Anish Feroz Zeroxinn Exploit Title Authenticated Directory Exploit Author Anish Feroz Vendor Homepage

Travelable 1.0 Cross Site Scripting - KizzMyAnthia.com

# Exploit Title: Travelable 1.0 - Stored XSS# Exploit Author: CraCkEr# Date: 15/07/2023# Vendor: travelmate.com# Vendor Homepage: https://www.codester.com/items/43963/travelable-trek-management-solution# Software Link: https://travel.codeswithbipin.com/# Tested on: Windows 10 Pro# Impact: Manipulate the content of the site## DescriptionAllow Attacker to inject malicious code into website, give ability to steal sensitiveinformation, manipulate data, and launch additional attacks.Path: /[random-nu...
Software Link Exploit Title Exploit Author Vendor Homepage Guest User

BloodBank 1.1 SQL Injection - KizzMyAnthia.com

# Exploit Title: BloodBank 1.1 - SQL Injection# Exploit Author: CraCkEr# Date: 15/07/2023# Vendor: phpscriptpoint# Vendor Homepage: https://phpscriptpoint.com/# Software Link: https://demo.phpscriptpoint.com/bloodbank/# Tested on: Windows 10 Pro# Impact: Database Access## DescriptionSQL injection attacks can allow unauthorized access to sensitive data, modification ofdata and crash the application or make it unavailable, leading to lost revenue anddamage to
Software Link Exploit Title Exploit Author Vendor Homepage

Carlisting 1.6 Cross Site Scripting - KizzMyAnthia.com

# Exploit Title: Carlisting 1.6 - Reflected XSS# Exploit Author: CraCkEr# Date: 16/07/2023# Vendor: phpscriptpoint# Vendor Homepage: https://phpscriptpoint.com/# Software Link: https://demo.phpscriptpoint.com/carlisting/# Tested on: Windows 10 Pro# Impact: Manipulate the content of the site## DescriptionThe attacker can send to victim a link containing a malicious URL in an email or instant messagecan perform a wide variety
Software Link Exploit Title Exploit Author Vendor Homepage

Explore More Categories

World News India News Business Technology Sports Entertainment Health Science