mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-24 15:54:10 +02:00
1.2 KiB
1.2 KiB
CVE-2019-13358
Description
lib/DocumentToText.php in OpenCats before 0.9.4-3 has XXE that allows remote users to read files on the underlying operating system. The attacker must upload a file in the docx or odt format.
POC
Reference
Github
- https://github.com/0xaniketB/TryHackMe-Empline
- https://github.com/20142995/Goby
- https://github.com/20142995/nuclei-templates
- https://github.com/ARPSyndicate/cvemon
- https://github.com/HimmelAward/Goby_POC
- https://github.com/Jake-Ruston/Proof-Of-Concepts
- https://github.com/Jake-yee/Proof-Of-Concepts
- https://github.com/MariaShaikh7857/try-hack-me-Empline
- https://github.com/NyxAzrael/Goby_POC
- https://github.com/Z0fhack/Goby_POC
- https://github.com/cyb3r-w0lf/nuclei-template-collection
- https://github.com/elouatih/securite_devoirs