Biggest News Aggregation in the World
📰 Exploit Author News

Page 8 - Exploit Author News Today

Fast, Ad-Free News Updates

Stay updated with breaking news from Exploit Author. Real-time updates on events, politics, business and more.

D-Link DAP-1325 Insecure Direct Object Reference

# Exploit Title: D-Link DAP-1325 - Broken Access Control# Date: 27-06-2023# Exploit Author: ieduardogoncalves# Contact : twitter.com/0x00dia# Vendor : www.dlink.com# Version: Hardware version: A1 # Firmware version: 1.01# Tested on:All Platforms1) DescriptionSecurity vulnerability known as "Unauthenticated access to settings" or "Unauthenticated configuration download". This vulnerability occurs when a device, such as a repeater, allows the
Exploit Title Broken Access Exploit Author Login Page

Alkacon OpenCMS 15.0 Cross Site Scripting - KizzMyAnthia.com

# Exploit Title: Alkacon OpenCMS 15.0 - Multiple Cross-Site Scripting# Date: 1/07/2023# Exploit Author: tmrswrr# Vendor Homepage: http://www.opencms.org# Software Link: https://github.com/alkacon/opencms-core# Version: v15.0POC:1 ) Login in demo page , go to this urlhttps://demo.opencms.org/workplace#!explorer/8b72b2fe-180f-11ee-b326-0242ac11002b!!/sites/livedemo!!/.galleries/livedemo/!!2 ) Click /.galleries/ , after right click any png file , open gallery, write in search button this payload3 )...
Alkacon Open Software Link Exploit Title Multiple Cross Site Exploit Author Vendor Homepage

PrestaShop Winbiz Payment Improper Limitation

# Exploit Title: PrestaShop Winbiz Payment module - Improper Limitation of a Pathname to a Restricted Directory# Date: 2023-06-20# Dork: /modules/winbizpayment/downloads/download.php# country: Iran# Exploit Author: Amirhossein Bahramizadeh# Category : webapps# Vendor Homepage: https://shop.webbax.ch/modules-pour-winbiz/153-module-prestashop-winbiz-payment-reverse.html# Version: 17.1.3 (REQUIRED)# Tested on: Windows/Linux# CVE : CVE-2023-30198import requestsimport stringimport random# The base UR...
Amirhossein Bahramizadeh Exploit Title Prestashop Winbiz Payment Improper Limitation Exploit Author Vendor Homepage

Microsoft SharePoint Enterprise Server 2016 Spoofing

// Exploit Title: Microsoft SharePoint Enterprise Server 2016 - Spoofing// Date: 2023-06-20// country: Iran// Exploit Author: Amirhossein Bahramizadeh// Category : Remote// Vendor Homepage:// Microsoft SharePoint Foundation 2013 Service Pack 1// Microsoft SharePoint Server Subscription Edition// Microsoft SharePoint Enterprise Server 2013 Service Pack 1// Microsoft SharePoint Server 2019// Microsoft SharePoint Enterprise Server 2016// Tested on: Windows/Linux//
Internetopen Mozilla Amirhossein Bahramizadeh Microsoft Sharepoint Foundation Service Pack Exploit Title Microsoft Sharepoint Enterprise Server

Smart Office Web 20.28 Information Disclosure / Insecure Direct Object Reference

# Exploit Title: Smart Office Web 20.28 - Remote Information Disclosure (Unauthenticated)# Shodan Dork:: inurl:"https://www.shodan.io/search?query=smart+office"# Date: 09/Dec/2022# Exploit Author: Tejas Nitin Pingulkar (https://cvewalkthrough.com/)# Vendor Homepage: https://smartofficepayroll.com/# Software Link: https://smartofficepayroll.com/downloads# Version: Smart Office Web 20.28 and before# CVE Number : CVE-2022-47075 and CVE-2022-47076# CVSS : 7.5 (High)# Reference : https://cv...
Tejas Nitin Pingulkar Smart Office Web Software Link Exploit Title Remote Information Disclosure Shodan Dork

Stay Updated with Latest News

Get breaking news updates delivered to your inbox

Browse All News →

WordPress Super Socializer 7.13.52 Cross Site Scripting

# Exploit Title: Super Socializer 7.13.52 - Reflected XSS# Dork: inurl: https://example.com/wp-admin/admin-ajax.php?action=the_champ_sharing_count&urls[%3Cimg%20src%3Dx%20onerror%3Dalert%28document%2Edomain%29%3E]=https://www.google.com# Date: 2023-06-20# Exploit Author: Amirhossein Bahramizadeh# Category : Webapps# Vendor Homepage: https://wordpress.org/plugins/super-socializer# Version: 7.13.52 (REQUIRED)# Tested on: Windows/Linux# CVE : CVE-2023-2779import requests# The URL of the vulnera...
Amirhossein Bahramizadeh Exploit Title Super Socializer Exploit Author Vendor Homepage

Nokia ASIKA 7.13.52 Private Key Disclosure - KizzMyAnthia.com

// Exploit Title: Nokia ASIKA 7.13.52 - Hard-coded private key disclosure// Date: 2023-06-20// Exploit Author: Amirhossein Bahramizadeh// Category : Hardware// Vendor Homepage: https://www.nokia.com/about-us/security-and-privacy/product-security-advisory/cve-2023-25187/// Version: 7.13.52 (REQUIRED)// Tested on: Windows/Linux// CVE : CVE-2023-25187#include #include #include #include #include #include #include #include #include #include #include // The IP address of the vulnerable devicechar *hos...
Amirhossein Bahramizadeh Exploit Title Exploit Author Vendor Homepage

WordPress Theme Medic 1.0.0 Weak Password Recovery Mechanism

# Exploit Title: WordPress Theme Medic v1.0.0 - Weak Password Recovery Mechanism for Forgotten Password# Dork: inurl:/wp-includes/class-wp-query.php# Date: 2023-06-19# Exploit Author: Amirhossein Bahramizadeh# Category : Webapps# Vendor Homepage: https://www.templatemonster.com/wordpress-themes/medic-health-and-medical-clinic-wordpress-theme-216233.html# Version: 1.0.0 (REQUIRED)# Tested on: Windows/Linux# CVE: CVE-2020-11027import requestsfrom bs4 import BeautifulSoupfrom datetime import dateti...
Amirhossein Bahramizadeh Exploit Title Wordpress Theme Medic Weak Password Recovery Mechanism Exploit Author Vendor Homepage

Student Study Center Management System 1.0 Cross Site Scripting

# Exploit Title: Student Study Center Management System v1.0 - Stored Cross-Site Scripting (XSS)# Date of found: 12/05/2023# Exploit Author: VIVEK CHOUDHARY @sudovivek# Version: V1.0# Tested on: Windows 10# Vendor Homepage: https://phpgurukul.com# Software Link: https://phpgurukul.com/student-study-center-management-system-using-php-and-mysql/# CVE: CVE-2023-33580# CVE URL: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-33580Vulnerability Description -The Student Study Center Management...
Software Link Student Study Center Management System Exploit Title Stored Cross Site Scripting Exploit Author Vendor Homepage

Online Art Gallery Project 1.0 Arbitrary File Upload

# Exploit Title: Online Art gallery project 1.0 - Arbitrary File Upload (Unauthenticated)# Google Dork: n/a# Date: 14/06/2023# Exploit Author: Ramil Mustafayev# Vendor Homepage: https://github.com/projectworldsofficial# Software Link: https://github.com/projectworlds32/Art-Gallary-php/archive/master.zip# Version: 1.0# Tested on: Windows 10, XAMPP for Windows 8.0.28 / PHP 8.0.28# CVE : n/a# Vulnerability Description:## Online Art Gallery Project 1.0 allows unauthenticated users to
Ramil Mustafayev Software Link Exploit Title Online Art Arbitrary File Upload Google Dork

Explore More Categories

World News India News Business Technology Sports Entertainment Health Science