fuzzlove

9 exploits Active since May 2019
CVE-2019-18873 NOMISEC CRITICAL WORKING POC
FUDForum 3.0.9 - Stored Cross-Site Scripting and Remote Code Execution via User-Agent Header
FUDForum 3.0.9 is vulnerable to Stored XSS via the User-Agent HTTP header. This may result in remote code execution. An attacker can use a user account to fully compromise the system via a GET request. When the admin visits user information under "User Manager" in the control panel, the payload will execute. This will allow for PHP files to be written to the web root, and for code to execute on the remote server. The problem is in admsession.php and admuser.php.
7 stars
CVSS 9.0
CVE-2019-12185 NOMISEC HIGH WORKING POC
elabftw 1.8.5 - Authenticated Arbitrary File Upload via EntityController
eLabFTW 1.8.5 is vulnerable to arbitrary file uploads via the /app/controllers/EntityController.php component. This may result in remote command execution. An attacker can use a user account to fully compromise the system using a POST request. This will allow for PHP files to be written to the web root, and for code to execute on the remote server.
7 stars
CVSS 8.8
CVE-2020-3452 NOMISEC HIGH WORKING POC
Cisco ASA 9.6-9.6.4.42 & FTD 6.2.3-6.2.3.16 Unauthenticated Path Traversal
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks and read sensitive files on a targeted system. The vulnerability is due to a lack of proper input validation of URLs in HTTP requests processed by an affected device. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences to an affected device. A successful exploit could allow the attacker to view arbitrary files within the web services file system on the targeted device. The web services file system is enabled when the affected device is configured with either WebVPN or AnyConnect features. This vulnerability cannot be used to obtain access to ASA or FTD system files or underlying operating system (OS) files.
6 stars
CVSS 7.5
CVE-2019-12169 NOMISEC HIGH WORKING POC
ATutor 2.2.1-2.2.4 - Path Traversal and Arbitrary File Upload via Language Import ZIP Archive
ATutor 2.2.4 allows Arbitrary File Upload and Directory Traversal, resulting in remote code execution via a ".." pathname in a ZIP archive to the mods/_core/languages/language_import.php (aka Import New Language) or mods/_standard/patcher/index_admin.php (aka Patcher) component.
3 stars
CVSS 8.8
CVE-2019-12170 NOMISEC HIGH WRITEUP
ATutor <= 2.2.4 - Authenticated Arbitrary File Upload via Backup ZIP Archive
ATutor through 2.2.4 is vulnerable to arbitrary file uploads via the mods/_core/backups/upload.php (aka backup) component. This may result in remote command execution. An attacker can use the instructor account to fully compromise the system using a crafted backup ZIP archive. This will allow for PHP files to be written to the web root, and for code to execute on the remote server.
2 stars
CVSS 8.8
CVE-2024-44258 NOMISEC HIGH WORKING POC
iPadOS < 17.7.1 - Arbitrary File Write via Symlink Handling
This issue was addressed with improved handling of symlinks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, tvOS 18.1, visionOS 2.1. Restoring a maliciously crafted backup file may lead to modification of protected system files.
1 stars
CVSS 7.1
CVE-2022-35411 NOMISEC CRITICAL WORKING POC
rpc.py < 0.6.0 - Unauthenticated Remote Code Execution via Pickle Deserialization
rpc.py through 0.6.0 allows Remote Code Execution because an unpickle occurs when the "serializer: pickle" HTTP header is sent. In other words, although JSON (not Pickle) is the default data format, an unauthenticated client can cause the data to be processed with unpickle.
1 stars
CVSS 9.8
CVE-2024-33722 GITHUB MEDIUM WRITEUP
SOPlanning 1.52.00 - Authenticated SQL Injection via projets.php statut[] Parameter
SOPlanning 1.52.00 is vulnerable to SQL Injection by an authenticated user via projets.php with statut[].
CVSS 6.3
CVE-2024-33724 GITHUB MEDIUM WRITEUP
SOPlanning 1.52.00 - Cross-Site Scripting via groupe_id Parameter
SOPlanning 1.52.00 is vulnerable to Cross Site Scripting (XSS) via the groupe_id parameter to process/groupe_save.php.
CVSS 5.4