Exploits
Collection of Exploits developed by Ron Jost
For Exploit-development requests, please reach out to me: [email protected]
Table of Contents:
- Wordpress Plugin XCloner 4.2.12 - Remote Code Execution (Authenticated): CVE-2020-35948
- Wordpress Plugin Modern Events Calendar Lite < 5.16.5 - RCE (Authenticated): CVE-2021-24145
- Wordpress Plugin Modern Events Calendar Lite < 5.16.5 - Export Event Data (Unauthenticated): CVE-2021-24146
- Wordpress Plugin Backup Guard < 1.6.0 - Remote Code Execution(Authenticated): CVE-2021-24155
- Wordpress Plugin Responsive Menu < 4.0.3 - Remote Code Execution (Authenticated): CVE-2021-24160
- Wordpress Plugin SP Project & Document Manager 4.21 - Remote Code Execution (Authenticated): CVE-2021-24347
- Wordpress Plugin BulletProof Security V 5.1 - Sensitive information disclosure CVE-2021-39327
- Wordpress Plugin Secure File Manager V <= 2.9.3 - Remtoe Code Execution (Authenticated): SFM-0day
- Wordpress Plugin Duplcate Post V <= 1.1.9 - SQL Injection: CVE-2021-43408
- Wordpress Plugin Catch Themes Demo Import V 1.6.1 - Remote Code Execution (Authenticated): CVE-2021-39352
- Wordpress Plugin WP Visitor Statistics V <= 4.7 - SQL Injection (Authenticated): CVE-2021-24750
- Wordpress Plugin RegistrationMagic V <= 5.0.1.5 - SQL Injection (Authenticated): CVE-2021-24862
- Wordpress Plugin Modern Events Calendar V < 6.1.5 - SQL Injection (Unauthenticated) CVE-2021-24946
- Wordpress Plugin Download Monitor WordPress V < 4.4.5 - SQL Injection (Authenticated) CVE-2021-24786
- Wordpress Plugin 404 to 301 <= 2.0.2 - SQL-Injection (Authenticated) CVE-2015-9323
- Wordpress Plugin Secure Copy Content Protection and Content Locking < 2.8.2 - SQL-Injection (Unauthenticated) CVE-2021-24931
- Wordpress Plugin Perfect Survey < 1.5.2 - SQL Injection (Unauthenticated) CVE-2021-24762
- Wordpress Plugin WP User Frontend < 3.5.26 - SQL-Injection (Authenticated)
- GetSimple CMS 3.3.4 - Information Disclosure: CVE-2014-8722
- OpenEMR 5.0.0 - Remote Code Execution (Authenticated): CVE-2017-9380
- OpenEMR < 5.0.1.4 - Remote Code Execution (Authenticated): CVE-2018-15139
- OpenEMR < 5.0.1.4 - /portal/account/register.php Authentication bypass: CVE-2018-15152
- OpenEMR < 5.0.2 - Path Traversal (Authenticated): CVE-2019-14530
- Trixbox 2.8.0.4 - 'lang' Remote Code Execution (Unauthenticated): CVE-2017-14535
- Trixbox 2.8.0.4 - 'lang' Path Traversal: CVE-2017-14537
- Monstra CMS <= 3.0.4 - Remote Code Execution (Authenticated): CVE-2018-6383
- Codiad 2.8.4 - Remote Code Execution (Authenticated): CVE-2018-19423
- Codiad 2.8.4 - Remote Code Execution (Authenticated) (2): CVE-2019-19208
- Pluck CMS 4.7.13 - File Upload Remote Code Execution (Authenticated): CVE-2020-29607
CVE-2020-35948-Exploit
Exploit Title: Wordpress Plugin XCloner < 5.1.13 - Remote Code Execution (Authenticated)
CVE description:
An issue was discovered in the XCloner Backup and Restore plugin before 4.2.13 for WordPress. It gave authenticated attackers the ability to modify arbitrary files, including PHP files. Doing so would allow an attacker to achieve remote code execution. The xcloner_restore.php write_file_action could overwrite wp-config.php, for example. Alternatively, an attacker could create an exploit chain to obtain a database dump.
ExploitDB:
Exploit Description:
Usage:

Usage Example:

CVE-2021-24145-Exploit
Exploit Title: Wordpress Plugin Modern Events Calendar Lite < 5.16.5 - Remote Code Execution (Authenticated)
CVE description:
Arbitrary file upload in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly check the imported file, allowing PHP ones to be uploaded by administrator by using the 'text/csv' content-type in the request.
ExploitDB:
Exploit Description:
Usage:

Usage Example:

CVE-2021-24146-Exploit
Exploit Title: Wordpress Plugin Modern Events Calendar Lite < 5.16.5 - Export Event Data (Unauthenticated)
CVE description:
Lack of authorisation checks in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly restrict access to the export files, allowing unauthenticated users to exports all events data in CSV or XML format for example.
ExploitDB:
Exploit Description:
Usage:

Usage Example:

CVE-2021-24155-Exploit
Wordpress Plugin Backup Guard < 1.6.0 - Remote Code Execution (Authenticated)
CVE description:
The WordPress Backup and Migrate Plugin – Backup Guard WordPress plugin before 1.6.0 did not ensure that the imported files are of the SGBP format and extension, allowing high privilege users (admin+) to upload arbitrary files, including PHP ones, leading to RCE.
ExploitDB:
Exploit Description:
Usage:
