CTF-hacker

3 exploits Active since Dec 2022
CVE-2023-38948 GITEE HIGH
jizhi CMS 1.9.5 - Code Injection
An arbitrary file download vulnerability in the /c/PluginsController.php component of jizhi CMS 1.9.5 allows attackers to execute arbitrary code via downloading a crafted plugin.
CVSS 7.2
CVE-2023-38947 GITEE HIGH
WBCE CMS 1.6.1 - Code Injection
An arbitrary file upload vulnerability in the /languages/install.php component of WBCE CMS v1.6.1 allows attackers to execute arbitrary code via a crafted PHP file.
CVSS 7.2
CVE-2022-4349 GITEE MEDIUM
CTF-hacker pwn - CSRF
A vulnerability classified as problematic has been found in CTF-hacker pwn. This affects an unknown part of the file delete.html. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-215109 was assigned to this vulnerability.
CVSS 4.3