Toxi4

2 exploits Active since Apr 2023
CVE-2023-33253 NOMISEC HIGH WORKING POC
LabCollector 6.0-6.15 - Authenticated Remote Code Execution via Message Function File Upload
LabCollector 6.0 though 6.15 allows remote code execution. An authenticated remote low-privileged user can upload an executable PHP file and execute system commands. The vulnerability is in the message function, and is due to insufficient validation of the file (such as shell.jpg.php.shell) being sent.
4 stars
CVSS 8.8
CVE-2023-30459 NOMISEC HIGH WORKING POC
SmartPTT SCADA 1.1.0.0 - Authenticated Remote Code Execution via C# Script Upload
SmartPTT SCADA 1.1.0.0 allows remote code execution (when the attacker has administrator privileges) by writing a malicious C# script and executing it on the server (via server settings in the administrator control panel on port 8101, by default).
3 stars
CVSS 7.2