CVE-2023-26360.zip
4.9 KB
CVE-2023-26360
Author: RyanRodrigues880
Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction.
GitHub Link:
https://github.com/RyanRodrigues880/CVE-2023-26360
Author: RyanRodrigues880
Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction.
GitHub Link:
https://github.com/RyanRodrigues880/CVE-2023-26360
CVE-2018-10933.zip
1010 B
CVE-2018-10933
Author: opsifiz
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without first performing authentication, resulting in unauthorized access.
GitHub Link:
https://github.com/opsifiz/CVE-2018-10933
Author: opsifiz
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without first performing authentication, resulting in unauthorized access.
GitHub Link:
https://github.com/opsifiz/CVE-2018-10933
CVE-2018-17254.zip
2.5 KB
CVE-2018-17254
Author: 7amzahard
The JCK Editor component 6.4.4 for Joomla! allows SQL Injection via the jtreelink/dialogs/links.php parent parameter.
GitHub Link:
https://github.com/7amzahard/script-python-to-detect-CVE-2018-17254
Author: 7amzahard
The JCK Editor component 6.4.4 for Joomla! allows SQL Injection via the jtreelink/dialogs/links.php parent parameter.
GitHub Link:
https://github.com/7amzahard/script-python-to-detect-CVE-2018-17254
CVE-2021-23394
Author: 0xnemian
The package studio-42/elfinder before 2.1.58 are vulnerable to Remote Code Execution (RCE) via execution of PHP code in a .phar file. NOTE: This only applies if the server parses .phar files as PHP.
GitHub Link:
https://github.com/0xnemian/CVE-2021-23394
Author: 0xnemian
The package studio-42/elfinder before 2.1.58 are vulnerable to Remote Code Execution (RCE) via execution of PHP code in a .phar file. NOTE: This only applies if the server parses .phar files as PHP.
GitHub Link:
https://github.com/0xnemian/CVE-2021-23394