flex0geek

5 exploits Active since Sep 2015
CVE-2015-6967 GITHUB c WORKING POC
Nibbleblog < 4.0.4 - Unrestricted File Upload
Unrestricted file upload vulnerability in the My Image plugin in Nibbleblog before 4.0.5 allows remote administrators to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in content/private/plugins/my_image/image.php.
20 stars
CVE-2020-28038 GITHUB MEDIUM c WRITEUP
Wordpress < 5.5.2 - XSS
WordPress before 5.5.2 allows stored XSS via post slugs.
20 stars
CVSS 6.1
CVE-2021-3156 GITHUB HIGH c WORKING POC
Sudo Heap-Based Buffer Overflow
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.
20 stars
CVSS 7.8
CVE-2022-24355 GITHUB HIGH c WORKING POC
TP-Link TL-WR940N 3.20.1 Build 200316 Rel.34392n - RCE
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link TL-WR940N 3.20.1 Build 200316 Rel.34392n (5553) routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the parsing of file name extensions. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-13910.
20 stars
CVSS 8.8
CVE-2023-4911 GITHUB HIGH c WORKING POC
Glibc Tunables Privilege Escalation CVE-2023-4911 (aka Looney Tunables)
A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges.
20 stars
CVSS 7.8