The Forminator plugin for WordPress is vulnerable to arbitrary file uploads due to file type validation occurring after a file has been uploaded to the server in the upload_post_image() function in versions up to, and including, 1.24.6. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
PoC: CVE-2023-4596-OpenSSH-Multi-Checker
CVE-2024-6387-checker is a tool or script designed to detect the security vulnerability known as CVE-2024-6387 OpenSSH. CVE-2024-6387 OpenSSH is an entry in the Common Vulnerabilities and Exposures (CVE) that documents security weaknesses discovered in certain software or systems.
PoC: CVE-2023-4596-Vulnerable-Exploit-and-Checker-Version
CVE-2023-4596 Vulnerable Exploit and Checker Version
PoC: caldera_sandcat-usecase
special thanks to E1A for the POC of the CVE Exploit found here: https://github.com/E1A/CVE-2023-4596
PoC: CVE-2023-4596
PoC Script for CVE-2023-4596, unauthenticated Remote Command Execution through arbitrary file uploads.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free