Skip to content
KitploitKITPLOIT
उपकरणएक्सप्लॉइटब्लॉग
Log in
जमा करें
उपकरणएक्सप्लॉइटब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

··फ़ीड·संपर्क·गोपनीयता·© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
CVE-2026-74239 — Proof of concept and technical write-up for CVE-2026-74239, a path traversal vulnerability in XenForo style archive imports on Windows, allowing file write via crafted ZIP. | Kitploit
उपकरण/GitHubGitHub/bombobombone/cve-2026-74239
Vulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration Testing
GitHubbombobombone/cve-2026-74239

CVE-2026-74239

Proof of concept and technical write-up for CVE-2026-74239, a path traversal vulnerability in XenForo style archive imports on Windows, allowing file write via crafted ZIP.

रिपॉजिटरी देखें
820 दिन पहलेअभी तक समीक्षित नहीं

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें
अनुरोधित भाषा में सामग्री उपलब्ध नहीं है। अंग्रेज़ी संस्करण दिखाया जा रहा है।

CVE-2026-74239: Windows path traversal in style archive import

XenForo before 2.3.13 is vulnerable to path traversal in style archive imports on Windows.

What happens

The importer accepts ZIP members under upload/ and rejects names containing the forward-slash form /../. It does not normalize or reject backslashes. XenForo then appends the retained member name to its temporary extraction directory. Windows interprets ..\ as parent-directory traversal.

A non-super ACP administrator with the style permission can escape the temporary directory and write bytes to another web-server-writable path. On XenForo 2.3.12 (build 2031270), a crafted member wrote a new PHP marker file into the public web root; requesting it executed the constant marker as the web-server account.

The prerequisites are a Windows deployment with PHP ZIP support, a delegated style administrator, and a writable destination. XenForo 2.3.13 contains the fix.

Proof of concept

root@kitploit:~
python poc.py https://xenforo.example LIMITED_STYLE_ADMIN --confirm-write

The password is read from a prompt. The script creates style-archive-sentinel.php and prints its path after the run.

References

  • CVE record
  • VulnCheck advisory
  • XenForo 2.3.13 release

Discovered by Marco Paciaroni (BomboBombone).

टूल डाउनलोड करें