dldygnl

3 exploits Active since Sep 2019
CVE-2021-24741 NOMISEC CRITICAL WORKING POC
Support Board WordPress <3.3.4 - SQL Injection
The Support Board WordPress plugin before 3.3.4 does not escape multiple POST parameters (such as status_code, department, user_id, conversation_id, conversation_status_code, and recipient_id) before using them in SQL statements, leading to SQL injections which are exploitable by unauthenticated users.
2 stars
CVSS 9.8
CVE-2021-24807 NOMISEC MEDIUM WRITEUP
Support Board WP <3.3.5 - XSS
The Support Board WordPress plugin before 3.3.5 allows Authenticated (Agent+) users to perform Cross-Site Scripting attacks by placing a payload in the notes field, when an administrator or any authenticated user go to the chat the XSS will be automatically executed.
1 stars
CVSS 5.4
CVE-2019-16113 NOMISEC HIGH WORKING POC
Bludit 3.9.2 - RCE
Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .jpg file name, and then this PHP code can write other PHP code to a ../ pathname.
CVSS 8.8