Feed/CVE-2023-3840
CVE-2023-3840LOWCVSS 3.5

CVE-2023-3840

Published Jul 22, 2023·Updated Jun 17, 2026

NVD Description

A vulnerability, which was classified as problematic, was found in NxFilter 4.3.2.5. This affects an unknown part of the file /report,daily.jsp?stime=2023%2F07%2F12&timeOption=yesterday&. The manipulation of the argument user leads to cross site scripting. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-235191. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

Public Exploits & PoCs9 found

[POC] CVE-2023-38408 — CVE-2023-38408

CVE-2023-38408 Remote Code Execution in OpenSSH's forwarded ssh-agent

3

[POC] CVE-2023-38408 — cve-2023-38408

An in-depth analysis of CVE 2023 38408, a critical OpenSSH vulnerability, including technical background, exploitation in controlled environments, and mitigation strategies.

2

[POC] CVE-2023-38408 — cve_2023_38408_scanner

Vulnerability Overview CVE-2023-38408 affects OpenSSH versions < 9.3p2 and stems from improper validation of data when SSH agent forwarding is enabled. When users connect to a remote server with ssh -A, they allow the agent on their local machine to be used for authentication to further systems

[POC] CVE-2023-38408 — nmap-scan-results

Found 200+ vulnerabilities on scanme.nmap.org including CVE-2023-38408 (9.8 critical)

[POC] CVE-2023-38408 — CVE-2023-38408

CVE-2023-38408 Remote Code Execution in OpenSSH's forwarded ssh-agent

[POC] CVE-2023-38408 — CVE-2023-38408

Takeover Account OpenSSH

[POC] CVE-2023-38408 — CVE-2023-38408

PoC for the recent critical vuln affecting OpenSSH versions < 9.3p2

[POC] CVE-2023-38408 — CVE-2023-38408

Script para eliminar vulnerabilidad de openssh de ubuntu 22.04 LTS

[POC] CVE-2023-38408 — CVE-2023-38408

CVE-2023-38408 SSH Vulnerability Scanner & PoC

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free