๐ฐ Exploit Title News
Page 11 - Exploit Title News Today
Fast, Ad-Free News Updates
Stay updated with breaking news from Exploit Title. Real-time updates on events, politics, business and more.
May 6, 2023
#Exploit Title: Ulicms-2023.1 sniffing-vicuna - Remote Code Execution (RCE)#Application: Ulicms#Version: 2023.1-sniffing-vicuna#Bugs: RCE#Technology: PHP#Vendor URL: https://en.ulicms.de/#Software Link: https://www.ulicms.de/content/files/Releases/2023.1/ulicms-2023.1-sniffing-vicuna-full.zip#Date of found: 04-05-2023#Author: Mirabbas Aฤalarov#Tested on: Linux 2. Technical Details & POC========================================steps: 1. Login to account and edit profile.2.Upload new Avatar3. ...
May 5, 2023
# Exploit Title: Jedox 2020.2.5 - Remote Code Execution via Configurable Storage Path# Date: 28/04/2023# Exploit Author: Team Syslifters / Christoph MAHRL, Aron MOLNAR, Patrick PIRKER and Michael WEDL# Vendor Homepage: https://jedox.com# Version: Jedox 2020.2 (20.2.5) and older# CVE : CVE-2022-47878Introduction=================Incorrect input validation for the default storage path variable in the settings page allows remote,
May 5, 2023
# Exploit Title: Jedox 2020.2.5 - Disclosure of Database Credentials via Improper Access Controls# Date: 28/04/2023# Exploit Author: Team Syslifters / Christoph MAHRL, Aron MOLNAR, Patrick PIRKER and Michael WEDL# Vendor Homepage: https://jedox.com# Version: Jedox 2020.2 (20.2.5) and older# CVE : CVE-2022-47874Introduction=================Improper access controls in `/tc/rpc` allows remote authenticated users to view details of database
May 5, 2023
# Exploit Title: Jedox 2022.4.2 - Disclosure of Database Credentials via Connection Checks# Date: 28/04/2023# Exploit Author: Team Syslifters / Christoph MAHRL, Aron MOLNAR, Patrick PIRKER and Michael WEDL# Vendor Homepage: https://jedox.com# Version: Jedox 2022.4 (22.4.2) and older# CVE : CVE-2022-47880Introduction=================An information disclosure vulnerability in `/be/rpc.php` allows remote authenticated users with the appropriate permissions to
May 5, 2023
# Exploit Title: EasyPHP Webserver 14.1 - Multiple Vulnerabilities (RCE andPath Traversal)# Discovery by: Rafael Pedrero# Discovery Date: 2022-02-06# Vendor Homepage: https://www.easyphp.org/# Software Link : https://www.easyphp.org/# Tested Version: 14.1# Tested on: Windows 7 and 10# Vulnerability Type: Remote Command Execution (RCE)CVSS v3: 9.8CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCWE: CWE-78Vulnerability description: There is an OS Command Injection in EasyPHPWebserver
May 4, 2023
# Exploit Title: Unauthenticated SQL injection- Google Dork:- Date: 27.04.2023- Exploit Author: Lucas Noki (0xPrototype)- Vendor Homepage: https://github.com/vogtmh- Software Link: https://github.com/vogtmh/cmaps- Version: 8.0- Tested on: Mac, Windows, Linux- CVE : CVE-2023-29809*Description:*The vulnerability found is an SQL injection. The `bookmap` parameter is vulnerable. When visiting the page: http://192.168.0.56/rest/booking/index.php?mode=list&bookmap=test we get the normal JSON respo...
May 4, 2023
# Exploit Title: Reflected Cross Site Scripting- Google Dork:- Date: 27.04.2023- Exploit Author: Lucas Noki (0xPrototype)- Vendor Homepage: https://github.com/vogtmh- Software Link: https://github.com/vogtmh/cmaps- Version: 8.0- Tested on: Mac, Windows, Linux- CVE : CVE-2023-29808*Description:*The vulnerability found is Reflected Cross Site Scripting. When the `/index.php?map=overview&findme=` endpoint is hit with a request where the "findme" parameter contains a malicious
May 3, 2023
# Exploit Title: PHPJabbers Simple CMS 5.0 - SQL Injection# Date: 2023-04-29# Exploit Author: Ahmet รmit BAYRAM# Vendor Homepage: https://www.phpjabbers.com/faq.php# Software Link: https://www.phpjabbers.com/simple-cms/# Version: 5.0# Tested on: Kali Linux### Request ###GET/simplecms/index.php?action=pjActionGetFile&column=created&controller=pjAdminFiles&direction=DESC&page=0&rowCount=10HTTP/1.1Accept: */*x-requested-with: XMLHttpRequestReferer: https://localhost/simplecms/p...
May 2, 2023
# Exploit Title: Mobile Mouse 3.6.0.4 Remote Code Execution v2 # Date: Apr28, 2023# Exploit Author: Chokri Hammedi# Vendor Homepage: https://mobilemouse.com/# Software Link: https://www.mobilemouse.com/downloads/setup.exe# Version: 3.6.0.4# Tested on: Windows 10 Enterprise LTSC Build 17763#!/usr/bin/env python3import socketfrom time import sleepimport argparseimport threadingfrom impacket import smbserverdef smb_server(lhost, file_to_serve):server = smbserver.SimpleSMBServer(listenAddress=lhost,...
April 28, 2023
# Exploit Title: MilleGPG5 5.9.2 (Gennaio 2023) - Local Privilege Escalation / Incorrect Access Control# Date: 2023-04-28# Exploit Author: Andrea Intilangelo# Vendor Homepage: https://millegpg.it/# Software Homepage: https://millegpg.it - https://millewin.it/prodotti/governo-clinico-3/# Software Link: https://www.millegpg.it/download/MilleGPGInstall.exe# Version: 5.9.2# Tested on: Microsoft Windows 10 Enterprise x64 22H2, build 19045.2913# CVE: CVE-2023-25438MilleGPG / MilleGPG5 also known as &q...