<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Backdoor — PoC Archive</title><link>https://poc.intelseclab.com/tags/backdoor/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 05 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/backdoor/index.xml" rel="self" type="application/rss+xml"/><item><title>ProFTPD mod_sql Pre-Auth SQL Injection Leading to RCE (CVE-2026-42167)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-42167-proftpd-sqli-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-42167-proftpd-sqli-rce/</guid><description>High severity (CVSS 8.1) — network · CVE-2026-42167. Status: PoC. Affects: ProFTPD (with mod_sql and SQL-backed logging configured). Tags: sqli, unauthenticated, proftpd, mod_sql, ftp, rce, backdoor, go.</description><category>network</category><category>High</category><category>sqli</category><category>unauthenticated</category><category>proftpd</category><category>mod_sql</category><category>ftp</category><category>rce</category><category>backdoor</category><category>go</category></item><item><title>Kanboard — Missing Access Control on Plugin Installation Leads to Administrative RCE via Webshell Plugin (CVE-2026-25924)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-25924-kanboard-plugin-webshell/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-25924-kanboard-plugin-webshell/</guid><description>High severity (CVSS 8.4) — web · CVE-2026-25924 / GHSA-grch-p7vf-vc4f. Status: Weaponized. Affects: Kanboard (project management application). Tags: kanboard, rce, webshell, plugin-installation, incorrect-authorization, cwe-863, cwe-94, admin-bypass, backdoor.</description><category>web</category><category>High</category><category>kanboard</category><category>rce</category><category>webshell</category><category>plugin-installation</category><category>incorrect-authorization</category><category>cwe-863</category><category>cwe-94</category><category>admin-bypass</category><category>backdoor</category></item><item><title>SP Page Builder (Joomla) Unauthenticated File Upload RCE (CVE-2026-48908)</title><link>https://poc.intelseclab.com/pocs/web/2026-06-30_cve-2026-48908-sp-page-builder-joomla-rce/</link><pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-06-30_cve-2026-48908-sp-page-builder-joomla-rce/</guid><description>Critical severity (CVSS 10) — web · CVE-2026-48908 (GHSA-8fwr-8fxr-8v2p). Status: Weaponized — public PoC with mass-scan support, added to CISA KEV 2026-07-07, confirmed active in-the-wild exploitation. Affects: SP Page Builder extension for Joomla (joomshaper.net). Tags: RCE, unauthenticated, file-upload, PHP-webshell, Joomla, CMS, access-control, Python, CVSS-10, kev, backdoor, cwe-434.</description><category>web</category><category>Critical</category><category>RCE</category><category>unauthenticated</category><category>file-upload</category><category>PHP-webshell</category><category>Joomla</category><category>CMS</category><category>access-control</category><category>Python</category><category>CVSS-10</category><category>kev</category><category>backdoor</category><category>cwe-434</category></item></channel></rss>