<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Arbitrary-File-Write — PoC Archive</title><link>https://poc.intelseclab.com/tags/arbitrary-file-write/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sat, 15 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/arbitrary-file-write/index.xml" rel="self" type="application/rss+xml"/><item><title>Microsoft SCCM — AdminService CAB Extraction Path-Traversal to SYSTEM RCE (CVE-2026-47301)</title><link>https://poc.intelseclab.com/pocs/network/2026-08-15_cve-2026-47301-sccm-adminservice-cab-rce/</link><pubDate>Sat, 15 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-08-15_cve-2026-47301-sccm-adminservice-cab-rce/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2026-47301. Status: Patched. Affects: Microsoft Configuration Manager (SCCM / ConfigMgr), AdminService REST API. Tags: windows, sccm, configmgr, rce, cab, path-traversal, dll-hijacking, dll-proxy, arbitrary-file-write, system, microsoft, CVE-2026-47301.</description><category>network</category><category>Critical</category><category>windows</category><category>sccm</category><category>configmgr</category><category>rce</category><category>cab</category><category>path-traversal</category><category>dll-hijacking</category><category>dll-proxy</category><category>arbitrary-file-write</category><category>system</category><category>microsoft</category><category>CVE-2026-47301</category></item><item><title>Crawl4AI Docker API Server Arbitrary File Write via `output_path` (CVE-2026-56260)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-12_cve-2026-56260-crawl4ai-output-path-arbitrary-write/</link><pubDate>Sun, 12 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-12_cve-2026-56260-crawl4ai-output-path-arbitrary-write/</guid><description>Critical severity (CVSS 9.1) — web · CVE-2026-56260 (GHSA-365w-hqf6-vxfg). Status: PoC — lab (vulnerable-app/) demonstrates genuine unrestricted arbitrary file write; the bundled poc.py scanner is deliberately conservative (writes only to a randomized safe /tmp marker) so it is safe to run against real/production targets. See Notes.. Affects: Crawl4AI — open-source LLM-friendly web crawler/scraper (unclecode/crawl4ai), Docker API server mode. Tags: crawl4ai, ai-web-crawler, docker-api, path-traversal, arbitrary-file-write, cwe-22, unauthenticated, remote, denial-of-service.</description><category>web</category><category>Critical</category><category>crawl4ai</category><category>ai-web-crawler</category><category>docker-api</category><category>path-traversal</category><category>arbitrary-file-write</category><category>cwe-22</category><category>unauthenticated</category><category>remote</category><category>denial-of-service</category></item><item><title>ZimaOS Arbitrary File Write via Unvalidated File API Path — CVE-2026-28286</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-28286-zimaos-arbitrary-file-write/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-28286-zimaos-arbitrary-file-write/</guid><description>Critical severity — web · CVE-2026-28286. Status: PoC. Affects: ZimaOS (NAS / home-server operating system), file API endpoint /v2_1/files/file. Tags: zimaos, nas, arbitrary-file-write, path-traversal, api-misconfiguration, rce, home-server.</description><category>web</category><category>Critical</category><category>zimaos</category><category>nas</category><category>arbitrary-file-write</category><category>path-traversal</category><category>api-misconfiguration</category><category>rce</category><category>home-server</category></item><item><title>Veno File Manager Arbitrary PHP File Overwrite (CVE-2026-37068)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-37068-veno-file-manager-arbitrary-file-write/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-37068-veno-file-manager-arbitrary-file-write/</guid><description>Critical severity — web · CVE-2026-37068. Status: Weaponized. Affects: Veno File Manager Project. Tags: veno-file-manager, arbitrary-file-write, rce, authenticated, superadmin, cwe-434.</description><category>web</category><category>Critical</category><category>veno-file-manager</category><category>arbitrary-file-write</category><category>rce</category><category>authenticated</category><category>superadmin</category><category>cwe-434</category></item><item><title>Responsive Filemanager 9.14.0 — Unauthenticated RCE via Duplicate File (CVE-2026-39023)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-39023-responsive-filemanager-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-39023-responsive-filemanager-rce/</guid><description>Critical severity — web · CVE-2026-39023. Status: Weaponized. Affects: Responsive Filemanager. Tags: responsive-filemanager, php, unauthenticated, rce, duplicate-file, arbitrary-file-write.</description><category>web</category><category>Critical</category><category>responsive-filemanager</category><category>php</category><category>unauthenticated</category><category>rce</category><category>duplicate-file</category><category>arbitrary-file-write</category></item><item><title>OpenPLC_v3 glue_generator Path Traversal — CVE-2026-31156</title><link>https://poc.intelseclab.com/pocs/hardware/2026-07-05_cve-2026-31156-openplc-glue-generator-traversal/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/hardware/2026-07-05_cve-2026-31156-openplc-glue-generator-traversal/</guid><description>High severity — hardware · CVE-2026-31156. Status: PoC. Affects: OpenPLC_v3 — utils/glue_generator_src/glue_generator.cpp build/code-generation utility. Tags: openplc, ics, path-traversal, arbitrary-file-write, glue-generator, cpp, plc, industrial-control.</description><category>hardware</category><category>High</category><category>openplc</category><category>ics</category><category>path-traversal</category><category>arbitrary-file-write</category><category>glue-generator</category><category>cpp</category><category>plc</category><category>industrial-control</category></item><item><title>Node.js `tar` Package Symlink Path Traversal — CVE-2026-29786</title><link>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-29786-node-tar-symlink-traversal/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-29786-node-tar-symlink-traversal/</guid><description>High severity — misc · CVE-2026-29786. Status: PoC. Affects: tar npm package (Node.js). Tags: node-tar, path-traversal, symlink, archive-extraction, arbitrary-file-write, nodejs, supply-chain.</description><category>misc</category><category>High</category><category>node-tar</category><category>path-traversal</category><category>symlink</category><category>archive-extraction</category><category>arbitrary-file-write</category><category>nodejs</category><category>supply-chain</category></item><item><title>FUXA SCADA/HMI — Unauthenticated Path Traversal to Remote Code Execution (CVE-2026-25895)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-25895-fuxa-path-traversal-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-25895-fuxa-path-traversal-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-25895. Status: Weaponized. Affects: FUXA (Node.js-based SCADA/HMI platform), frangoteam. Tags: fuxa, scada, ics, path-traversal, arbitrary-file-write, rce, unauthenticated, cwe-22, cron-persistence, webshell.</description><category>web</category><category>Critical</category><category>fuxa</category><category>scada</category><category>ics</category><category>path-traversal</category><category>arbitrary-file-write</category><category>rce</category><category>unauthenticated</category><category>cwe-22</category><category>cron-persistence</category><category>webshell</category></item><item><title>Fireshare Unauthenticated Arbitrary File Write/Overwrite — CVE-2026-54337</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-54337-fireshare-file-overwrite/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-54337-fireshare-file-overwrite/</guid><description>Info severity — web · CVE-2026-54337 (see [GHSA-hmh2-6g84-q8jx](https://github.com/ShaneIsrael/fireshare/security/advisories/GHSA-hmh2-6g84-q8jx)). Status: PoC. Affects: Fireshare (self-hosted video sharing app), &lt;= 1.16.3. Tags: fireshare, unauthenticated, arbitrary-file-write, argument-injection, ffmpeg, file-upload, cwe-73, docker.</description><category>web</category><category>Info</category><category>fireshare</category><category>unauthenticated</category><category>arbitrary-file-write</category><category>argument-injection</category><category>ffmpeg</category><category>file-upload</category><category>cwe-73</category><category>docker</category></item><item><title>exiftool-vendored.js Argument Injection via Newline-Delimited Tag Names (CVE-2026-43893)</title><link>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-43893-exiftool-vendored-arg-injection-file-write/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-43893-exiftool-vendored-arg-injection-file-write/</guid><description>High severity (CVSS 8.2) — misc · CVE-2026-43893 / GHSA-cw26-7653-2rp5. Status: PoC. Affects: exiftool-vendored (npm package, Node.js wrapper around Phil Harvey's ExifTool). Tags: exiftool, exiftool-vendored, argument-injection, arbitrary-file-write, arbitrary-file-read, nodejs, cli-wrapper, newline-injection.</description><category>misc</category><category>High</category><category>exiftool</category><category>exiftool-vendored</category><category>argument-injection</category><category>arbitrary-file-write</category><category>arbitrary-file-read</category><category>nodejs</category><category>cli-wrapper</category><category>newline-injection</category></item><item><title>Casdoor Authenticated Path Traversal to Arbitrary File Write (CVE-2026-6815)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-6815-casdoor-path-traversal-file-write/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-6815-casdoor-path-traversal-file-write/</guid><description>High severity — web · CVE-2026-6815. Status: Weaponized. Affects: Casdoor (open-source identity/access management platform). Tags: casdoor, path-traversal, arbitrary-file-write, rce, dos, authenticated, cwe-22.</description><category>web</category><category>High</category><category>casdoor</category><category>path-traversal</category><category>arbitrary-file-write</category><category>rce</category><category>dos</category><category>authenticated</category><category>cwe-22</category></item><item><title>ApostropheCMS Import — Malicious Tar Archive Path Traversal (CVE-2026-32731)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-32731-apostrophecms-tar-path-traversal/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-32731-apostrophecms-tar-path-traversal/</guid><description>High severity — web · CVE-2026-32731. Status: PoC. Affects: ApostropheCMS (site export/import feature). Tags: apostrophecms, cms, path-traversal, tar-slip, arbitrary-file-write, import, node-js.</description><category>web</category><category>High</category><category>apostrophecms</category><category>cms</category><category>path-traversal</category><category>tar-slip</category><category>arbitrary-file-write</category><category>import</category><category>node-js</category></item><item><title>Apktool Resource Table Path Traversal — Malicious APK Builder (CVE-2026-39973)</title><link>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-39973-apktool-path-traversal/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-39973-apktool-path-traversal/</guid><description>High severity — misc · CVE-2026-39973. Status: PoC. Affects: iBotPeaches/Apktool (Android APK decompiler/rebuilder). Tags: apktool, path-traversal, resources-arsc, apk, decompilation, arbitrary-file-write, android-tooling.</description><category>misc</category><category>High</category><category>apktool</category><category>path-traversal</category><category>resources-arsc</category><category>apk</category><category>decompilation</category><category>arbitrary-file-write</category><category>android-tooling</category></item><item><title>Amazon WorkSpaces Skylight Workspace Config Service Local Privilege Escalation (CVE-2026-7791)</title><link>https://poc.intelseclab.com/pocs/cloud/2026-07-05_cve-2026-7791-aws-workspaces-skylight-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/cloud/2026-07-05_cve-2026-7791-aws-workspaces-skylight-lpe/</guid><description>High severity — cloud · CVE-2026-7791. Status: PoC. Affects: Amazon WorkSpaces — Skylight Workspace Config Service. Tags: aws, amazon-workspaces, skylight, toctou, privilege-escalation, arbitrary-file-write, windows, directory-junction.</description><category>cloud</category><category>High</category><category>aws</category><category>amazon-workspaces</category><category>skylight</category><category>toctou</category><category>privilege-escalation</category><category>arbitrary-file-write</category><category>windows</category><category>directory-junction</category></item><item><title>AdonisJS bodyparser Path Traversal to Arbitrary File Write (CVE-2026-21440)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-21440-adonisjs-bodyparser-path-traversal/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-21440-adonisjs-bodyparser-path-traversal/</guid><description>Critical severity (CVSS 9.2) — web · CVE-2026-21440 (GHSA-gvq6-hvvp-h34h). Status: Weaponized. Affects: @adonisjs/bodyparser (AdonisJS multipart file-upload handling). Tags: adonisjs, nodejs, path-traversal, arbitrary-file-write, cwe-22, file-upload, rce, bodyparser.</description><category>web</category><category>Critical</category><category>adonisjs</category><category>nodejs</category><category>path-traversal</category><category>arbitrary-file-write</category><category>cwe-22</category><category>file-upload</category><category>rce</category><category>bodyparser</category></item><item><title>WinRAR Archive Extraction Path Traversal (CVE-2025-6218)</title><link>https://poc.intelseclab.com/pocs/misc/2026-05-15_winrar-path-traversal-cve-2025-6218/</link><pubDate>Fri, 15 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-05-15_winrar-path-traversal-cve-2025-6218/</guid><description>High severity — misc · CVE-2025-6218. Status: Weaponized. Affects: WinRAR archive extraction workflow. Tags: path-traversal, arbitrary-file-write, startup-folder, WinRAR, Windows, user-interaction.</description><category>misc</category><category>High</category><category>path-traversal</category><category>arbitrary-file-write</category><category>startup-folder</category><category>WinRAR</category><category>Windows</category><category>user-interaction</category></item></channel></rss>