Skip to content

Instantly share code, notes, and snippets.

View Chiaki2333's full-sized avatar

Chiaki2333 Chiaki2333

  • China
  • 03:43 (UTC +08:00)
View GitHub Profile
@Chiaki2333
Chiaki2333 / CVE-2023-49030
Last active November 26, 2023 15:09
CVE-2023-49030
[CVE ID]
CVE-2023-49030
[PRODUCT]
https://github.com/32ns/KLive
[VERSION]
32ns/KLive - <=2019-1-19
[PROBLEM TYPE]
SQL Injection
[DESCRIPTION]
SQL Injection vulnerability in 32ns KLive v.2019-1-19 and before allows a remote attacker to obtain sensitive information via a crafted script to the web/user.php component.
@Chiaki2333
Chiaki2333 / CVE-2023-49029
Last active November 26, 2023 14:27
CVE-2023-49029
[CVE ID]
CVE-2023-49029
[PRODUCT]
https://github.com/smpn1smg/absis
[VERSION]
smpn1smg/absis - <=2017-10-19
[PROBLEM TYPE]
Cross Site Scripting (XSS)
[DESCRIPTION]
Cross Site Scripting vulnerability in smpn1smg absis v.2017-10-19 and before allows a remote attacker to execute arbitrary code via the nama parameter in the lock/lock.php file.
@Chiaki2333
Chiaki2333 / CVE-2023-49028
Created November 26, 2023 14:08
CVE-2023-49028
[CVE ID]
CVE-2023-49028
[PRODUCT]
https://github.com/smpn1smg/absis
[VERSION]
smpn1smg/absis - <=2017-10-19
[PROBLEM TYPE]
Cross Site Scripting (XSS)
[DESCRIPTION]
Cross Site Scripting vulnerability in smpn1smg absis v.2017-10-19 and before allows a remote attacker to execute arbitrary code via the user parameter in the lock/lock.php file.
@Chiaki2333
Chiaki2333 / CVE-2023-43381
Created September 26, 2023 08:26
CVE-2023-43381
[CVE ID]
CVE-2023-43381
[PRODUCT]
https://github.com/tianchoy/blog
[VERSION]
v1.8.8
[PROBLEM TYPE]
SQL Injection
[DESCRIPTION]
SQL Injection exists in tianchoy/blog through 2018-06-19 via the user parameter to login.php.