-
Notifications
You must be signed in to change notification settings - Fork 860
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
- Loading branch information
1 parent
aed98e0
commit f38b831
Showing
9 changed files
with
130 additions
and
0 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,18 @@ | ||
### [CVE-2024-51376](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-51376) | ||
 | ||
 | ||
 | ||
|
||
### Description | ||
|
||
Directory Traversal vulnerability in yeqifu carRental v.1.0 allows a remote attacker to obtain sensitive information via the file/downloadFile.action?path= component. | ||
|
||
### POC | ||
|
||
#### Reference | ||
- https://github.com/echo0d/vulnerability/blob/main/yeqifu_carRental/DirectoryTraversal.md | ||
- https://github.com/yeqifu/carRental/issues/43 | ||
|
||
#### Github | ||
No PoCs found on GitHub currently. | ||
|
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,17 @@ | ||
### [CVE-2024-57601](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-57601) | ||
 | ||
 | ||
 | ||
|
||
### Description | ||
|
||
Cross Site Scripting vulnerability in Alex Tselegidis EasyAppointments v.1.5.0 allows a remote attacker to execute arbitrary code via the legal_settings parameter. | ||
|
||
### POC | ||
|
||
#### Reference | ||
- https://hkohi.ca/vulnerability/13 | ||
|
||
#### Github | ||
No PoCs found on GitHub currently. | ||
|
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,17 @@ | ||
### [CVE-2024-57602](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-57602) | ||
 | ||
 | ||
 | ||
|
||
### Description | ||
|
||
An issue in Alex Tselegidis EasyAppointments v.1.5.0 allows a remote attacker to escalate privileges via the index.php file. | ||
|
||
### POC | ||
|
||
#### Reference | ||
- https://hkohi.ca/vulnerability/12 | ||
|
||
#### Github | ||
No PoCs found on GitHub currently. | ||
|
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,17 @@ | ||
### [CVE-2024-57603](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-57603) | ||
 | ||
 | ||
 | ||
|
||
### Description | ||
|
||
An issue in MaysWind ezBookkeeping 0.7.0 allows a remote attacker to escalate privileges via the lack of rate limiting. | ||
|
||
### POC | ||
|
||
#### Reference | ||
- https://hkohi.ca/vulnerability/1 | ||
|
||
#### Github | ||
No PoCs found on GitHub currently. | ||
|
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,17 @@ | ||
### [CVE-2024-57604](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-57604) | ||
 | ||
 | ||
 | ||
|
||
### Description | ||
|
||
An issue in MaysWind ezBookkeeping 0.7.0 allows a remote attacker to escalate privileges via the token component. | ||
|
||
### POC | ||
|
||
#### Reference | ||
- https://hkohi.ca/vulnerability/2 | ||
|
||
#### Github | ||
No PoCs found on GitHub currently. | ||
|
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,17 @@ | ||
### [CVE-2024-57605](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-57605) | ||
 | ||
 | ||
 | ||
|
||
### Description | ||
|
||
Cross Site Scripting vulnerability in Daylight Studio Fuel CMS v.1.5.2 allows an attacker to escalate privileges via the /fuel/blocks/ and /fuel/pages components. | ||
|
||
### POC | ||
|
||
#### Reference | ||
- https://hkohi.ca/vulnerability/3 | ||
|
||
#### Github | ||
No PoCs found on GitHub currently. | ||
|
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,17 @@ | ||
### [CVE-2024-8266](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8266) | ||
 | ||
 | ||
 | ||
|
||
### Description | ||
|
||
An issue was discovered in GitLab CE/EE affecting all versions starting from 17.1 prior to 17.6.0, which allows an attacker with maintainer role to trigger a pipeline as project owner under certain circumstances. | ||
|
||
### POC | ||
|
||
#### Reference | ||
- https://gitlab.com/gitlab-org/gitlab/-/issues/481531 | ||
|
||
#### Github | ||
No PoCs found on GitHub currently. | ||
|
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters