MarkLee131

26 exploits Active since Mar 2017
CVE-2026-23679 WRITEUP MEDIUM WRITEUP
libusb < 1.0.30 NULL Pointer Dereference in parse_interface()
libusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allows attackers to crash applications by supplying a malformed USB configuration descriptor where an interface claims bNumEndpoints greater than zero but is followed by a class-specific descriptor whose bLength exceeds the remaining buffer size, causing parse_interface() to return early without allocating the endpoint array. Attackers can exploit this flaw through libusb_get_active_config_descriptor or libusb_get_config_descriptor by providing crafted descriptors via virtualized USB passthrough, file-based descriptor parsing, or network sources, causing any application iterating over endpoints to dereference a NULL endpoint pointer and crash.
CVSS 6.2
CVE-2026-47104 WRITEUP MEDIUM WRITEUP
libusb < 1.0.30 Out-of-Bounds Read in parse_iad_array()
libusb before version 1.0.30 contains a one-byte out-of-bounds read vulnerability in parse_iad_array() in descriptor.c that allows attackers to trigger a denial of service by supplying a malformed USB descriptor whose bLength equals size minus one, causing the bounds check to use the original buffer size instead of the remaining size. Attackers in virtualized environments with USB passthrough can supply crafted descriptors through libusb_get_active_interface_association_descriptors or libusb_get_interface_association_descriptors to read one byte past the end of the malloc allocation, resulting in a denial of service.
CVSS 4.0
CVE-2017-6478 WRITEUP MEDIUM WRITEUP
mangoswebv4 < 4.0.8 - Reflected Cross-Site Scripting via Install Step Parameter
paintballrefjosh/MaNGOSWebV4 before 4.0.8 is vulnerable to a reflected XSS in install/index.php (step parameter).
CVSS 6.1
CVE-2018-25080 WRITEUP LOW WRITEUP
mobiledetect < 2.8.32 - Cross-Site Scripting via $_SERVER['PHP_SELF'] in session_example.php
A vulnerability, which was classified as problematic, has been found in MobileDetect 2.8.31. This issue affects the function initLayoutType of the file examples/session_example.php of the component Example. The manipulation of the argument $_SERVER['PHP_SELF'] leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2.8.32 is able to address this issue. The identifier of the patch is 31818a441b095bdc4838602dbb17b8377d1e5cce. It is recommended to upgrade the affected component. The identifier VDB-220061 was assigned to this vulnerability.
CVSS 3.5
CVE-2019-16693 WRITEUP CRITICAL WRITEUP
phpipam < 1.4 - SQL Injection via Custom Fields Order Table Parameter
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/order.php table parameter when action=add is used.
CVSS 9.8
CVE-2019-25024 WRITEUP CRITICAL WORKING POC
OpenRepeater <2.2 - Command Injection
OpenRepeater (ORP) before 2.2 allows unauthenticated command injection via shell metacharacters in the functions/ajax_system.php post_service parameter.
CVSS 9.8
CVE-2020-15716 WRITEUP MEDIUM WRITEUP
RosarioSIS 6.7.2 - Cross-Site Scripting via Preferences.php Tab Parameter
RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the Preferences.php script. A remote attacker could exploit this vulnerability using the tab parameter in a crafted URL.
CVSS 6.1
CVE-2020-15718 WRITEUP MEDIUM WRITEUP
RosarioSIS 6.7.2 - Cross-Site Scripting via PrintSchedules.php include_inactive Parameter
RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the PrintSchedules.php script. A remote attacker could exploit this vulnerability using the include_inactive parameter in a crafted URL.
CVSS 6.1
CVE-2020-20969 WRITEUP HIGH WRITEUP
Pluck 4.7.10 - Remote Code Execution via Trashcan Restore Item File Upload
File Upload vulnerability in PluckCMS v.4.7.10 allows a remote attacker to execute arbitrary code via the trashcan_restoreitem.php file.
CVSS 7.2
CVE-2020-29607 WRITEUP HIGH WRITEUP
Pluck CMS < 4.7.13 - Authenticated Remote Code Execution via File Upload Restriction Bypass
A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access in the host through the "manage files" functionality, which may result in remote code execution.
CVSS 7.2
CVE-2020-5504 WRITEUP HIGH WRITEUP
phpMyAdmin <4.9.4-5.0.1 - SQL Injection
In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could inject custom SQL in place of their own username when creating queries to this page. An attacker must have a valid MySQL account to access the server.
CVSS 8.8
CVE-2021-40617 WRITEUP CRITICAL WRITEUP
openSIS 8.0 - SQL Injection via ForgotPassUserName.php
An SQL Injection vulnerability exists in openSIS Community Edition version 8.0 via ForgotPassUserName.php.
CVSS 9.8
CVE-2022-0088 WRITEUP HIGH WORKING POC
YOURLS < 1.8.3 - Cross-Site Request Forgery
Cross-Site Request Forgery (CSRF) in GitHub repository yourls/yourls prior to 1.8.3.
CVSS 7.4
CVE-2022-3766 WRITEUP MEDIUM WRITEUP
phpmyfaq < 3.1.8 - Reflected Cross-Site Scripting
Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.8.
CVSS 6.1
CVE-2022-4407 WRITEUP MEDIUM WRITEUP
phpmyfaq < 3.1.9 - Reflected Cross-Site Scripting
Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.9.
CVSS 6.1
CVE-2023-1211 WRITEUP HIGH WRITEUP
phpipam < 1.5.2 - SQL Injection
SQL Injection in GitHub repository phpipam/phpipam prior to v1.5.2.
CVSS 7.2
CVE-2023-30258 WRITEUP CRITICAL WRITEUP
magnusbilling 6.0.0-7.2.9 - Unauthenticated OS Command Injection
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary commands via unauthenticated HTTP request.
CVSS 9.8
CVE-2023-33362 WRITEUP CRITICAL WRITEUP
Piwigo 13.6.0 - SQL Injection via Profile Function
Piwigo 13.6.0 is vulnerable to SQL Injection via in the "profile" function.
CVSS 9.8
CVE-2024-34987 WRITEUP CRITICAL WRITEUP
PHPGurukul Online Fire Reporting System 1.2 - SQL Injection via Username Input Field
A SQL Injection vulnerability exists in the `ofrs/admin/index.php` script of PHPGurukul Online Fire Reporting System 1.2. The vulnerability allows attackers to bypass authentication and gain unauthorized access by injecting SQL commands into the username input field during the login process.
CVSS 9.1
CVE-2024-41358 WRITEUP MEDIUM WRITEUP
phpipam 1.6 - Cross-Site Scripting via Import Load Data
phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\import-export\import-load-data.php.
CVSS 6.1
CVE-2017-6396 WRITEUP MEDIUM WRITEUP
WebPageTest - Stored Cross-Site Scripting in compare-cf.php
An issue was discovered in WPO-Foundation WebPageTest 3.0. The vulnerability exists due to insufficient filtration of user-supplied data passed to the "webpagetest-master/www/compare-cf.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.
CVSS 6.1
CVE-2017-6537 WRITEUP MEDIUM WRITEUP
webpagetest 3.0 - Cross-Site Scripting via bgcolor Parameter in video/view.php
A Cross-Site Scripting (XSS) issue was discovered in webpagetest 3.0. The vulnerability exists due to insufficient filtration of user-supplied data (bgcolor) passed to the webpagetest-master/www/video/view.php URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.
CVSS 6.1
CVE-2017-6541 WRITEUP MEDIUM WRITEUP
webpagetest 3.0 - Cross-Site Scripting via benchmark and time Parameters
Multiple Cross-Site Scripting (XSS) issues were discovered in webpagetest 3.0. The vulnerabilities exist due to insufficient filtration of user-supplied data (benchmark, time) passed to the webpagetest-master/www/benchmarks/viewtest.php URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.
CVSS 6.1
CVE-2018-15899 WRITEUP MEDIUM WRITEUP
MiniCMS 1.10 - Cross-Site Scripting via Date Parameter
An issue was discovered in MiniCMS 1.10. There is a post.php?date= XSS vulnerability.
CVSS 6.1
CVE-2021-35438 WRITEUP MEDIUM WRITEUP
phpipam 1.4.3 - Reflected Cross-Site Scripting via IP Calculator
phpIPAM 1.4.3 allows Reflected XSS via app/dashboard/widgets/ipcalc-result.php and app/tools/ip-calculator/result.php of the IP calculator.
CVSS 6.1