Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2020-20210: Bludit v3.9.2 Code Execution Vulnerability in "Images Upload" · Issue #1079 · bludit/bludit

Bludit 3.9.2 is vulnerable to Remote Code Execution (RCE) via /admin/ajax/upload-images.

CVE
#vulnerability#php#rce

A Code Execution Vulnerability in Bludit v3.9.2****There is a Code Execution Vulnerability which allow to get server permissions,the url is /admin/ajax/upload-images****1, login with any account which allows you to edit content

2, click the button of Images to upload a picture

3 change the name and content of the file and then upload

and also upload a.htaccess file

The file will now be under the TMP folder

4 visit evil php http://127.0.0.1/bludit-3-9-2/bl-content/tmp/shell.php

PHP version

PHP 7.3.2

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907