sql3t0

9 exploits Active since May 2026
CVE-2023-24215 GITHUB CRITICAL WRITEUP
NOVUS AirGate 4G 1.1.16 - Info Disclosure
Incorrect access control in the /uci/get/ endpoint of NOVUS AirGate 4G firmware v1.1.16 allows unauthenticated attackers to obtain administrator credentials via a crafted POST request.
CVSS 9.1
CVE-2026-29962 GITHUB HIGH WRITEUP
HSC MailInspector 5.3.3-7 - Path Traversal
HSC MailInspector v5.3.3-7 contains a Local File Inclusion (LFI) vulnerability caused by improper control of user-supplied file paths. The endpoint /vendor/phpunit/phpunit.php processes user-controlled parameters that directly affect file access operations without adequate validation, sanitization, or path restriction. This allows a remote attacker to exploit Path Traversal techniques to read arbitrary files from the underlying operating system and application directories, leading to sensitive information disclosure.
CVSS 7.5
CVE-2026-29963 GITHUB HIGH WRITEUP
HSC MailInspector 5.3.3-7 - Path Traversal
HSC MailInspector 5.3.3-7 has a Path Traversal vulnerability due to improper validation of user-supplied input in the /tap/dw.php endpoint. The text parameter is used to construct file paths without adequate normalization or restriction to a safe base directory. A remote attacker can exploit this flaw to access arbitrary files on the underlying operating system, resulting in unauthorized disclosure of sensitive information.
CVSS 7.5
CVE-2026-29964 GITHUB MEDIUM WRITEUP
HSC MailInspector 5.3.3-7 - Cross-Site Scripting via /tap/tap.php Endpoint
HSC MailInspector v5.3.3-7 contains a Cross-Site Scripting (XSS) vulnerability in the /tap/tap.php endpoint due to improper neutralization of user-controlled input using alternate or obfuscated JavaScript syntax. The endpoint reflects unsanitized user input in HTTP responses without adequate output encoding, allowing a remote attacker to execute arbitrary JavaScript code in the context of a victim's browser.
CVSS 6.1
CVE-2026-29965 GITHUB MEDIUM WRITEUP
HSC MailInspector 5.3.3-7 - Cross-Site Scripting in WarningUrlPage Endpoint
HSC MailInspector 5.3.3-7 is vulnerable to Cross Site Scripting (XSS) in the /police/WarningUrlPage.php endpoint due to improper neutralization of user-supplied input that uses alternate or obfuscated JavaScript syntax.
CVSS 6.1
CVE-2026-29962 WRITEUP HIGH WRITEUP
HSC MailInspector 5.3.3-7 - Path Traversal
HSC MailInspector v5.3.3-7 contains a Local File Inclusion (LFI) vulnerability caused by improper control of user-supplied file paths. The endpoint /vendor/phpunit/phpunit.php processes user-controlled parameters that directly affect file access operations without adequate validation, sanitization, or path restriction. This allows a remote attacker to exploit Path Traversal techniques to read arbitrary files from the underlying operating system and application directories, leading to sensitive information disclosure.
CVSS 7.5
CVE-2026-29963 WRITEUP HIGH WRITEUP
HSC MailInspector 5.3.3-7 - Path Traversal
HSC MailInspector 5.3.3-7 has a Path Traversal vulnerability due to improper validation of user-supplied input in the /tap/dw.php endpoint. The text parameter is used to construct file paths without adequate normalization or restriction to a safe base directory. A remote attacker can exploit this flaw to access arbitrary files on the underlying operating system, resulting in unauthorized disclosure of sensitive information.
CVSS 7.5
CVE-2026-29964 WRITEUP MEDIUM WRITEUP
HSC MailInspector 5.3.3-7 - Cross-Site Scripting via /tap/tap.php Endpoint
HSC MailInspector v5.3.3-7 contains a Cross-Site Scripting (XSS) vulnerability in the /tap/tap.php endpoint due to improper neutralization of user-controlled input using alternate or obfuscated JavaScript syntax. The endpoint reflects unsanitized user input in HTTP responses without adequate output encoding, allowing a remote attacker to execute arbitrary JavaScript code in the context of a victim's browser.
CVSS 6.1
CVE-2026-29965 WRITEUP MEDIUM WRITEUP
HSC MailInspector 5.3.3-7 - Cross-Site Scripting in WarningUrlPage Endpoint
HSC MailInspector 5.3.3-7 is vulnerable to Cross Site Scripting (XSS) in the /police/WarningUrlPage.php endpoint due to improper neutralization of user-supplied input that uses alternate or obfuscated JavaScript syntax.
CVSS 6.1