SQLi bug exposes 1Panel users to remote hijacking
by Loki - Wednesday July 31, 2024 at 02:14 AM
#1
1Panel is a web-based linux server management control panel. There are many sql injections in the project, and some of them are not well filtered, leading to arbitrary file writes, and ultimately leading to RCEs.
Hidden Content
You must register or login to view this content.



Omnicer
[Image: e47c91a87cc521d1efbd20183b42ee4259c9c593.gifv]
PGP
Reply
#2
highkey doubt ts
Reply
#3
Nice interesting loki lets to see
Reply
#4
Looks interesting thanks i check this one out...but seems kinda similar
Reply
#5
(08-08-2024, 06:22 AM)Banuk Wrote: Looks interesting thanks i check this one out...but seems kinda similar

Similar to what?
[Image: e47c91a87cc521d1efbd20183b42ee4259c9c593.gifv]
PGP
Reply
#6
yeah this one CVE-2024-39907 which is the case...
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  CVE-2025-47812 - Wing FTP Server Remote Code Execution (RCE) thermos 7 370 08-03-2025, 08:21 PM
Last Post: handsomexxxxxy
  Palo-Alto-Expedition-Remote-Code result 16 1,907 04-12-2025, 03:10 AM
Last Post: kry
  Craft CMS 4.4.14 - Unauthenticated Remote Code Execution Loki 13 1,074 04-06-2025, 10:05 PM
Last Post: cobrinha
  D-Link DIR-823X AX3000 Dual-Band Gigabit Wireless Router Remote Command Execution POC Loki 11 1,156 03-19-2025, 01:58 PM
Last Post: bbq9527
  Liferay TunnelServlet Deserialization Remote Code Execution darkspeed 4 387 03-14-2025, 08:18 AM
Last Post: darkspeed

Forum Jump:


 Users browsing this thread: 1 Guest(s)