๐ฐ Exploit Title News
Page 9 - Exploit Title News Today
Fast, Ad-Free News Updates
Stay updated with breaking news from Exploit Title. Real-time updates on events, politics, business and more.
June 20, 2023
# Exploit Title: Student Study Center Management System v1.0 - Stored Cross-Site Scripting (XSS)# Date of found: 12/05/2023# Exploit Author: VIVEK CHOUDHARY @sudovivek# Version: V1.0# Tested on: Windows 10# Vendor Homepage: https://phpgurukul.com# Software Link: https://phpgurukul.com/student-study-center-management-system-using-php-and-mysql/# CVE: CVE-2023-33580# CVE URL: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-33580Vulnerability Description -The Student Study Center Management...
June 16, 2023
# Exploit Title: Online Art gallery project 1.0 - Arbitrary File Upload (Unauthenticated)# Google Dork: n/a# Date: 14/06/2023# Exploit Author: Ramil Mustafayev# Vendor Homepage: https://github.com/projectworldsofficial# Software Link: https://github.com/projectworlds32/Art-Gallary-php/archive/master.zip# Version: 1.0# Tested on: Windows 10, XAMPP for Windows 8.0.28 / PHP 8.0.28# CVE : n/a# Vulnerability Description:## Online Art Gallery Project 1.0 allows unauthenticated users to
June 15, 2023
# Exploit Title: PyLoad 0.5.0 - Pre-auth Remote Code Execution (RCE)# Date: 06-10-2023# Credits: bAu @bauh0lz # Exploit Author: Gabriel Lima (0xGabe)# Vendor Homepage: https://pyload.net/# Software Link: https://github.com/pyload/pyload# Version: 0.5.0# Tested on: Ubuntu 20.04.6# CVE: CVE-2023-0297import requests, argparseparser = argparse.ArgumentParser()parser.add_argument('-u', action='store', dest='url', required=True, help='Target url.')parser.add_arg...
June 14, 2023
# Exploit Title: Online Examination System Project 1.0 - Cross-site request forgery (CSRF)# Google Dork: n/a# Date: 09/06/2023# Exploit Author: Ramil Mustafayev (kryptohaker)# Vendor Homepage: https://github.com/projectworldsofficial/online-examination-systen-in-php# Software Link: https://github.com/projectworlds32/online-examination-systen-in-php/archive/master.zip# Version: 1.0# Tested on: Windows 10, XAMPP for Windows 8.0.28 / PHP 8.0.28# CVE : n/aOnline Examination System Project
June 10, 2023
# Exploit Title: Path Traversal Vulnerability in Thruk Monitoring Web Interface โค 3.06# Date: 08-Jun-2023# Exploit Author: Galoget Latorre (@galoget)# CVE: CVE-2023-34096 (Galoget Latorre)# Vendor Homepage: https://thruk.org/# Software Link: https://github.com/sni/Thruk/archive/refs/tags/v3.06.zip# Software Link + Exploit + PoC (Backup): https://github.com/galoget/Thruk-CVE-2023-34096# CVE Author Blog: https://galogetlatorre.blogspot.com/2023/06/cve-2023-34096-path-traversal-thruk.html# GitHub...
June 1, 2023
# Exploit Title: Faculty Evaluation System 1.0 - Unauthenticated File Upload# Date: 5/29/2023# Author: Alex Gan# Vendor Homepage: https://www.sourcecodester.com/php/14635/faculty-evaluation-system-using-phpmysqli-source-code.html# Software Link: https://www.sourcecodester.com/sites/default/files/download/oretnom23/eval_2.zip# Version: 1.0# Tested on: LAMP Fedora server 38 (Thirty Eight) Apache/2.4.57 10.5.19-MariaDB PHP 8.2.6# CVE: CVE-2023-33440# References: https://nvd.nist.gov/vuln/detail/CVE...
May 29, 2023
Exploit Title: Camaleon CMS v2.7.0 - Server-Side Template Injection (SSTI)Exploit Author: PARAG BAGULCVE: CVE-2023-30145## DescriptionCamaleon CMS v2.7.0 was discovered to contain a Server-Side TemplateInjection (SSTI) vulnerability via the formats parameter.## Affected ComponentAll versions below 2.7.0 are affected.## AuthorParag Bagul## Steps to Reproduce1. Open the target URL: `https://target.com/admin/media/upload`2. Upload any file and intercept the request.3. In
May 29, 2023
# Exploit Title: Sql Injection on one site credentials can be use on other sites- Google Dork:" Designed and Developed by e-Biz Technocrats Pvt.Ltd "- Date: 05/11/2023- Exploit Author: K1LL3rB4LL- Tested on: Mac, Windows, LinuxDescription:The vulnerability found is an SQL injection. You may run the site thru automated sql injection or manually doing sql injection
May 26, 2023
#!/usr/bin/python3# Exploit Title: SCM Manager 1.60 - Cross-Site Scripting Stored (Authenticated)# Google Dork: intitle:"SCM Manager" intext:1.60# Date: 05-25-2023# Exploit Author: neg0x (https://github.com/n3gox/CVE-2023-33829)# Vendor Homepage: https://scm-manager.org/# Software Link: https://scm-manager.org/docs/1.x/en/getting-started/# Version: 1.2
May 26, 2023
Exploit Title: Zenphoto 1.6 - Multiple stored XSSApplication: Zenphoto-1.6 xss pocVersion: 1.6 Bugs: XSSTechnology: PHPVendor URL: https://www.zenphoto.org/news/zenphoto-1.6/Software Link: https://github.com/zenphoto/zenphoto/archive/v1.6.zipDate of found: 01-05-2023Author: Mirabbas AฤalarovTested on: Linux 2. Technical Details & POC========================================###XSS-1###steps: 1. create new album 2. write Album Description : 3. save and view album http://localhost/zenphoto-1.6/...