Stp1t

2 exploits Active since Aug 2023
CVE-2023-40028 NOMISEC MEDIUM WORKING POC
Ghost < 5.59.1 - Authenticated Arbitrary File Read via Symlink Upload
Ghost is an open source content management system. Versions prior to 5.59.1 are subject to a vulnerability which allows authenticated users to upload files that are symlinks. This can be exploited to perform an arbitrary file read of any file on the host operating system. Site administrators can check for exploitation of this issue by looking for unknown symlinks within Ghost's `content/` folder. Version 5.59.1 contains a fix for this issue. All users are advised to upgrade. There are no known workarounds for this vulnerability.
1 stars
CVSS 4.9
CVE-2025-27591 NOMISEC MEDIUM WORKING POC
Below < 0.9.0 - Privilege Escalation via World-Writable Log Directory
A privilege escalation vulnerability existed in the Below service prior to v0.9.0 due to the creation of a world-writable directory at /var/log/below. This could have allowed local unprivileged users to escalate to root privileges through symlink attacks that manipulate files such as /etc/shadow.
CVSS 6.8