GeunSam2

4 exploits Active since Jan 2017
CVE-2017-5487 NOMISEC MEDIUM WORKING POC
Wordpress < 4.7 - Information Disclosure
wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not properly restrict listings of post authors, which allows remote attackers to obtain sensitive information via a wp-json/wp/v2/users request.
2 stars
CVSS 5.3
CVE-2018-10118 NOMISEC MEDIUM WORKING POC
Monstra CMS 3.0.4 - XSS
Monstra CMS 3.0.4 has Stored XSS via the Name field on the Create New Page screen under the admin/index.php?id=pages URI, related to plugins/box/pages/pages.admin.php.
1 stars
CVSS 4.8
CVE-2018-11564 NOMISEC MEDIUM WORKING POC
Pagekit < 1.0.13 - XSS
Stored XSS in YOOtheme Pagekit 1.0.13 and earlier allows a user to upload malicious code via the picture upload feature. A user with elevated privileges could upload a photo to the system in an SVG format. This file will be uploaded to the system and it will not be stripped or filtered. The user can create a link on the website pointing to "/storage/poc.svg" that will point to http://localhost/pagekit/storage/poc.svg. When a user comes along to click that link, it will trigger a XSS attack.
1 stars
CVSS 4.8
CVE-2018-8718 NOMISEC HIGH WORKING POC
Mailer Plugin 1.20 for Jenkins 2.111 - CSRF
Cross-site request forgery (CSRF) vulnerability in the Mailer Plugin 1.20 for Jenkins 2.111 allows remote authenticated users to send unauthorized mail as an arbitrary user via a /descriptorByName/hudson.tasks.Mailer/sendTestMail request.
1 stars
CVSS 8.0