Writeup Exploits

60,754 exploits tracked across all sources.

Sort: Activity Stars
CVE-2023-1178 WRITEUP MEDIUM
GitLab 8.6-15.9.5, 15.10-15.10.4, 15.11 - File Integrity Compromise via Tag or Release Reference
An issue has been discovered in GitLab CE/EE affecting all versions from 8.6 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. File integrity may be compromised when source code or installation packages are pulled from a tag or from a release containing a ref to another commit.
CVSS 5.7
CVE-2023-1204 WRITEUP MEDIUM
GitLab 10.1-15.10.7, 15.11-15.11.6, 16.0-16.0.1 - Cryptographic Signature Verification Bypass
An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.1 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A user could use an unverified email as a public email and commit email by sending a specifically crafted request on user update settings.
CVSS 4.3
CVE-2023-1265 WRITEUP MEDIUM
GitLab <15.9.6-15.11.1 - Info Disclosure
An issue has been discovered in GitLab affecting all versions starting from 11.9 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. The condition allows for a privileged attacker, under certain conditions, to obtain session tokens from all users of a GitLab instance.
CVSS 5.4
CVE-2023-1494 WRITEUP MEDIUM
IBOS 4.5.5 - SQL Injection via Emailids Parameter in ApiController.php
A vulnerability classified as critical has been found in IBOS 4.5.5. Affected is an unknown function of the file ApiController.php. The manipulation of the argument emailids leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-223380.
CVSS 6.3
CVE-2023-1501 WRITEUP MEDIUM
RockOA 2.3.2 - Unrestricted Upload of File with Dangerous Type via fileid Argument
A vulnerability, which was classified as critical, was found in RockOA 2.3.2. This affects the function runAction of the file acloudCosAction.php.SQL. The manipulation of the argument fileid leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-223401 was assigned to this vulnerability.
CVSS 6.3
CVE-2023-1684 WRITEUP MEDIUM
HadSky 7.7.16 - Unrestricted Upload
A vulnerability was found in HadSky 7.7.16. It has been classified as problematic. This affects an unknown part of the file upload/index.php?c=app&a=superadmin:index. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-224241 was assigned to this vulnerability.
CVSS 4.7
CVE-2023-1685 WRITEUP MEDIUM
HadSky < 7.11.8 - Remote Command Injection via Installation Interface
A vulnerability was found in HadSky up to 7.11.8. It has been declared as critical. This vulnerability affects unknown code of the file /install/index.php of the component Installation Interface. The manipulation leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-224242 is the identifier assigned to this vulnerability.
CVSS 6.3
CVE-2023-1685 WRITEUP MEDIUM
HadSky < 7.11.8 - Remote Command Injection via Installation Interface
A vulnerability was found in HadSky up to 7.11.8. It has been declared as critical. This vulnerability affects unknown code of the file /install/index.php of the component Installation Interface. The manipulation leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-224242 is the identifier assigned to this vulnerability.
CVSS 6.3
CVE-2023-1739 WRITEUP MEDIUM
SourceCodester Simple and Beautiful Shopping Cart System 1.0 - Unre...
A vulnerability was found in SourceCodester Simple and Beautiful Shopping Cart System 1.0 and classified as critical. This issue affects some unknown processing of the file upload.php. The manipulation leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-224627.
CVSS 6.3
CVE-2023-1742 WRITEUP MEDIUM
IBOS < 4.5.5 - SQL Injection via Report Search API
A vulnerability was found in IBOS 4.5.5. It has been rated as critical. Affected by this issue is some unknown functionality of the file /?r=report/api/getlist of the component Report Search. The manipulation leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-224630 is the identifier assigned to this vulnerability.
CVSS 6.3
CVE-2023-1744 WRITEUP MEDIUM
ibos < 4.5.5 - Unrestricted File Upload via htaccess Handler
A vulnerability classified as critical was found in IBOS 4.5.5. This vulnerability affects unknown code of the component htaccess Handler. The manipulation leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-224632.
CVSS 6.3
CVE-2023-1747 WRITEUP MEDIUM
IBOS < 4.5.4 - SQL Injection via emailids Parameter in Email API
A vulnerability has been found in IBOS up to 4.5.4 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /?r=email/api/mark&op=delFromSend. The manipulation of the argument emailids leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 4.5.5 is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-224635.
CVSS 6.3
CVE-2023-1797 WRITEUP MEDIUM
OTCMS 6.0.1 - Unrestricted Upload of File with Dangerous Type via sysCheckFile.php
A vulnerability classified as critical was found in OTCMS 6.0.1. Affected by this vulnerability is an unknown functionality of the file sysCheckFile.php?mudi=sql. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-224749 was assigned to this vulnerability.
CVSS 6.3
CVE-2023-1798 WRITEUP LOW
EyouCMS < 1.5.4 - Cross-Site Scripting via login.php typename Parameter
A vulnerability, which was classified as problematic, has been found in EyouCMS up to 1.5.4. Affected by this issue is some unknown functionality of the file login.php. The manipulation of the argument typename leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-224750 is the identifier assigned to this vulnerability.
CVSS 3.5
CVE-2023-1799 WRITEUP LOW
EyouCMS < 1.5.4 - Cross-Site Scripting via tag_tag Parameter in login.php
A vulnerability, which was classified as problematic, was found in EyouCMS up to 1.5.4. This affects an unknown part of the file login.php. The manipulation of the argument tag_tag leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-224751.
CVSS 3.5
CVE-2023-1836 WRITEUP MEDIUM
GitLab <15.9.6-15.10.5-15.11.1 - XSS
A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 5.1 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. When viewing an XML file in a repository in "raw" mode, it can be made to render as HTML if viewed under specific circumstances
CVSS 4.4
CVE-2023-1947 WRITEUP MEDIUM
taoCMS 3.0.2 - Remote Code Injection in /admin/admin.php
A vulnerability was found in taoCMS 3.0.2. It has been classified as critical. Affected is an unknown function of the file /admin/admin.php. The manipulation leads to code injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-225330 is the identifier assigned to this vulnerability.
CVSS 6.3
CVE-2023-1965 WRITEUP MEDIUM
GitLab EE <15.9.6, <15.10.5, <15.11.1 - Open Redirect
An issue has been discovered in GitLab EE affecting all versions starting from 14.2 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. Lack of verification on RelayState parameter allowed a maliciously crafted URL to obtain access tokens granted for 3rd party Group SAML SSO logins. This feature isn't enabled by default.
CVSS 6.8
CVE-2023-1992 WRITEUP MEDIUM
Wireshark 3.6.0-3.6.12 and 4.0.0-4.0.4 - Denial of Service via RPCoRDMA Dissector
RPCoRDMA dissector crash in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service via packet injection or crafted capture file
CVSS 6.3
CVE-2023-1993 WRITEUP MEDIUM
Wireshark 3.6.0-3.6.12 and 4.0.0-4.0.4 - Denial of Service via LISP Dissector Large Loop
LISP dissector large loop in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service via packet injection or crafted capture file
CVSS 6.3
CVE-2023-1994 WRITEUP MEDIUM
Wireshark 3.6.0-3.6.12 and 4.0.0-4.0.4 - Denial of Service via GQUIC Dissector Crash
GQUIC dissector crash in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service via packet injection or crafted capture file
CVSS 6.3
CVE-2023-2056 WRITEUP MEDIUM
dedecms < 5.7.87 - Remote Code Execution via GetSystemFile Function
A vulnerability was found in DedeCMS up to 5.7.87 and classified as critical. This issue affects the function GetSystemFile of the file module_main.php. The manipulation leads to code injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-225941 was assigned to this vulnerability.
CVSS 6.3
CVE-2023-2069 WRITEUP MEDIUM
GitLab 10.0-12.9.7, 12.10-12.10.6, 13.0 - Authenticated CI/CD Variable Exposure via Project Import
An issue has been discovered in GitLab affecting all versions starting from 10.0 before 12.9.8, all versions starting from 12.10 before 12.10.7, all versions starting from 13.0 before 13.0.1. A user with the role of developer could use the import project feature to leak CI/CD variables.
CVSS 6.4
CVE-2023-2181 WRITEUP MEDIUM
GitLab <15.9.8-15.10.7-15.11.3 - Info Disclosure
An issue has been discovered in GitLab affecting all versions before 15.9.8, 15.10.0 before 15.10.7, and 15.11.0 before 15.11.3. A malicious developer could use a git feature called refs/replace to smuggle content into a merge request which would not be visible during review in the UI.
CVSS 6.3
CVE-2023-2424 WRITEUP MEDIUM
DedeCMS 5.7.106 - Unrestricted File Upload via UpDateMemberModCache Function
A vulnerability was found in DedeCMS 5.7.106 and classified as critical. Affected by this issue is the function UpDateMemberModCache of the file uploads/dede/config.php. The manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-227750 is the identifier assigned to this vulnerability.
CVSS 6.3