Skip to content

Instantly share code, notes, and snippets.

> [Suggested description]
> GDidees CMS v3.9.1 was discovered to contain a source code disclosure
> vulnerability by the backup feature which is accessible via
> /_admin/backup.php.
>
> ------------------------------------------
>
> [Vulnerability Type]
> Incorrect Access Control
>
> [Suggested description]
> GDidees CMS v3.9.1 and lower was discovered to contain an arbitrary
> file download vulnerability via the filename parameter at
> /_admin/imgdownload.php.
>
> ------------------------------------------
>
> [Vulnerability Type]
> Incorrect Access Control
>
> [description]
> An arbitrary file upload vulnerability in the upload function of
> GDidees CMS 3.9.1 allows attackers to execute arbitrary code via a
> crafted file.
>
> ------------------------------------------
>
> [Vulnerability Type]
> Incorrect Access Control
>
@Hadi999
Hadi999 / Reference.txt
Created October 24, 2022 22:08
CVE-2022-40797
> [Suggested description]
> Roxy Fileman 1.4.6 suffers from a Remote Code Execution (RCE)
> vulnerability caused by a weak upload control.
>
> ------------------------------------------
>
> [Additional Information]
> The Vendor website is down, in order to download the application we must use Internet Archive.
>
> ------------------------------------------