Camaleon CMS v2.7.0 – Server-Side Template Injection (SSTI)
Exploit Title: Camaleon CMS v2.7.0 - Server-Side Template Injection (SSTI)
ruby 相关平台内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
Exploit Title: Camaleon CMS v2.7.0 - Server-Side Template Injection (SSTI)
# Exploit Title: Authenticated Persistent XSS in Cameleon CMS 2.7.4
#!/usr/bin/env python3
# Exploit Title: GitLab v15.3 - Remote Code Execution (RCE) (Authenticated)
# Exploit Title: Gitlab 14.9 - Authentication Bypass
# Exploit Title: Gitlab Stored XSS
# Exploit Title: GitLab 13.10.2 - Remote Code Execution (RCE) (Unauthenticated)
# Exploit Title: Gitlab 13.10.2 - Remote Code Execution (Authenticated)
# Exploit Title: Gitlab 13.9.3 - Remote Code Execution (Authenticated)
# Exploit Title: GitLab Community Edition (CE) 13.10.3 - User Enumeration
# Exploit Title: GitLab Community Edition (CE) 13.10.3 - 'Sign_Up' User Enumeration
# Exploit Title: STVS ProVision 5.9.10 - File Disclosure (Authenticated)
# Exploit Title: STVS ProVision 5.9.10 - Cross-Site Request Forgery (Add Admin)
# Exploit Title: GitLab 11.4.7 RCE (POC)
# Exploit Title: Gitlab 11.4.7 - Remote Code Execution
# Exploit Title: Gitlab 12.9.0 - Arbitrary File Read (Authenticated)
# Exploit Title: Rails 5.0.1 - Remote Code Execution
# Exploit Title: GitLab 12.9.0 - Arbitrary File Read
# Exploit Title: Fat Free CRM v0.19.0 - HTML Injection
# Exploit Title: AlchemyCMS 4.1 - Cross-Site Scripting
# Exploit Title: CAMALEON CMS 2.4 - Cross-Site Scripting
While using NET::Ftp I realised you could get command execution through "malicious" file names.
# Exploit Title: CSRF
#!/usr/bin/ruby
# Exploit Title: GitLab privilege escalation via "impersonate" feature
# Exploit Title: Radiant CMS 1.1.3 - Mutiple Persistant XSS Vulnerabilities
#1 Stored XSS in 'signup[note]' POST parameter