<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Credential-Theft — PoC Archive</title><link>https://poc.intelseclab.com/tags/credential-theft/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sat, 11 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/credential-theft/index.xml" rel="self" type="application/rss+xml"/><item><title>LiteLLM Proxy Pre-Authentication SQL Injection via Error-Handling Callback (CVE-2026-42208)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2026-42208-litellm-sqli-proxy-authbypass/</link><pubDate>Sat, 11 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2026-42208-litellm-sqli-proxy-authbypass/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-42208 (GHSA-r75f-5x8p-qvmc). Status: Weaponized (public working PoC + Docker lab, actively exploited in the wild within 36 hours of disclosure). Affects: LiteLLM Proxy — open-source LLM/AI gateway (22,000+ GitHub stars) fronting OpenAI, Anthropic, and other model provider APIs. Tags: litellm, ai-gateway, llm-proxy, sql-injection, cwe-89, unauthenticated, remote, blind-sqli, kev-adjacent, credential-theft.</description><category>web</category><category>Critical</category><category>litellm</category><category>ai-gateway</category><category>llm-proxy</category><category>sql-injection</category><category>cwe-89</category><category>unauthenticated</category><category>remote</category><category>blind-sqli</category><category>kev-adjacent</category><category>credential-theft</category></item><item><title>TNC Toolbox: Web Performance Unauthenticated cPanel Credential Exposure (CVE-2025-12539)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-12539-tnc-toolbox-cpanel-creds-exposure/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-12539-tnc-toolbox-cpanel-creds-exposure/</guid><description>Critical severity (CVSS 10) — web · CVE-2025-12539. Status: Weaponized. Affects: TNC Toolbox: Web Performance (WordPress plugin). Tags: wordpress, tnc-toolbox, sensitive-information-exposure, unauthenticated, cpanel, credential-theft, privilege-escalation, python.</description><category>web</category><category>Critical</category><category>wordpress</category><category>tnc-toolbox</category><category>sensitive-information-exposure</category><category>unauthenticated</category><category>cpanel</category><category>credential-theft</category><category>privilege-escalation</category><category>python</category></item><item><title>RustFS Hardcoded gRPC Authentication Token Leading to Full Node Compromise (CVE-2025-68926)</title><link>https://poc.intelseclab.com/pocs/cloud/2026-07-06_cve-2025-68926-rustfs-grpc-token-bypass/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/cloud/2026-07-06_cve-2025-68926-rustfs-grpc-token-bypass/</guid><description>Critical severity (CVSS 9.8) — cloud · CVE-2025-68926. Status: Weaponized. Affects: RustFS (Rust-based S3-compatible distributed object storage) — internal node-to-node gRPC service. Tags: rustfs, grpc, hardcoded-credentials, authentication-bypass, object-storage, s3-compatible, information-disclosure, credential-theft, data-destruction, cwe-798, cwe-306.</description><category>cloud</category><category>Critical</category><category>rustfs</category><category>grpc</category><category>hardcoded-credentials</category><category>authentication-bypass</category><category>object-storage</category><category>s3-compatible</category><category>information-disclosure</category><category>credential-theft</category><category>data-destruction</category><category>cwe-798</category><category>cwe-306</category></item><item><title>pdfmake Server-Side Request Forgery via Unvalidated Document URLs (CVE-2026-26801)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-26801-pdfmake-ssrf/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-26801-pdfmake-ssrf/</guid><description>High severity — web · CVE-2026-26801. Status: Weaponized. Affects: pdfmake (Node.js PDF generation library), src/URLResolver.js. Tags: ssrf, pdfmake, node-js, cloud-metadata, aws-imds, cwe-918, credential-theft, data-exfiltration.</description><category>web</category><category>High</category><category>ssrf</category><category>pdfmake</category><category>node-js</category><category>cloud-metadata</category><category>aws-imds</category><category>cwe-918</category><category>credential-theft</category><category>data-exfiltration</category></item><item><title>OpenSTAManager Scadenzario Bulk Operations Error-Based SQL Injection — CVE-2026-24418</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-24418-openstamanager-sqli-scadenzario/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-24418-openstamanager-sqli-scadenzario/</guid><description>High severity (CVSS 8.8) — web · CVE-2026-24418. Status: Weaponized. Affects: OpenSTAManager (devcode-it/openstamanager). Tags: sql-injection, error-based, openstamanager, php, extractvalue, rce, credential-theft, authenticated.</description><category>web</category><category>High</category><category>sql-injection</category><category>error-based</category><category>openstamanager</category><category>php</category><category>extractvalue</category><category>rce</category><category>credential-theft</category><category>authenticated</category></item><item><title>OpenSTAManager Prima Nota Error-Based SQL Injection — CVE-2026-24419</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-24419-openstamanager-sqli-prima-nota/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-24419-openstamanager-sqli-prima-nota/</guid><description>High severity — web · CVE-2026-24419. Status: PoC. Affects: OpenSTAManager (devcode-it/openstamanager). Tags: sql-injection, error-based, openstamanager, php, extractvalue, credential-theft, authenticated.</description><category>web</category><category>High</category><category>sql-injection</category><category>error-based</category><category>openstamanager</category><category>php</category><category>extractvalue</category><category>credential-theft</category><category>authenticated</category></item><item><title>OpenSTAManager Article Pricing Time-Based Blind SQL Injection — CVE-2026-24416</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-24416-openstamanager-sqli-article-pricing/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-24416-openstamanager-sqli-article-pricing/</guid><description>High severity — web · CVE-2026-24416. Status: PoC. Affects: OpenSTAManager (devcode-it/openstamanager). Tags: sql-injection, time-based-blind, openstamanager, php, ajax, credential-theft, authenticated.</description><category>web</category><category>High</category><category>sql-injection</category><category>time-based-blind</category><category>openstamanager</category><category>php</category><category>ajax</category><category>credential-theft</category><category>authenticated</category></item><item><title>Nhost Local MCP Server Unauthenticated CORS Bypass Leading to Full Project Takeover (CVE-2026-34200)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-34200-nhost-mcp-cors-takeover/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-34200-nhost-mcp-cors-takeover/</guid><description>Critical severity (CVSS 9.6) — web · CVE-2026-34200 (GHSA-6c5x-3h35-vvw2). Status: PoC. Affects: Nhost CLI local MCP server (nhost mcp start). Tags: mcp, cors, csrf, drive-by, cors-bypass, credential-theft, hasura, dns-rebinding.</description><category>web</category><category>Critical</category><category>mcp</category><category>cors</category><category>csrf</category><category>drive-by</category><category>cors-bypass</category><category>credential-theft</category><category>hasura</category><category>dns-rebinding</category></item><item><title>Fortinet FortiClient EMS Pre-Auth Bypass — "FortiBleed" (CVE-2026-35616)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-03_cve-2026-35616-forticlient-ems-auth-bypass/</link><pubDate>Fri, 03 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-03_cve-2026-35616-forticlient-ems-auth-bypass/</guid><description>Critical severity (CVSS 9.1) — network · CVE-2026-35616. Status: Weaponized. Affects: Fortinet FortiClient Endpoint Management Server (EMS). Tags: authentication-bypass, header-spoofing, Fortinet, FortiClient-EMS, FortiBleed, credential-theft, CISA-KEV, active-exploitation, ransomware.</description><category>network</category><category>Critical</category><category>authentication-bypass</category><category>header-spoofing</category><category>Fortinet</category><category>FortiClient-EMS</category><category>FortiBleed</category><category>credential-theft</category><category>CISA-KEV</category><category>active-exploitation</category><category>ransomware</category></item><item><title>Squidbleed — Squid Proxy FTP Gateway Out-of-Bounds Heap Read (CVE-2026-47729)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-01_cve-2026-47729-squidbleed-squid-ftp-oob-read/</link><pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-01_cve-2026-47729-squidbleed-squid-ftp-oob-read/</guid><description>Medium severity — network · CVE-2026-47729. Status: PoC. Affects: Squid Proxy — FTP gateway / directory-listing parser. Tags: memory-disclosure, information-disclosure, Squid, proxy, FTP, heap-overflow, oob-read, credential-theft, legacy.</description><category>network</category><category>Medium</category><category>memory-disclosure</category><category>information-disclosure</category><category>Squid</category><category>proxy</category><category>FTP</category><category>heap-overflow</category><category>oob-read</category><category>credential-theft</category><category>legacy</category></item><item><title>Windows NTLM Hash Disclosure via File Explorer - CVE-2025-24054</title><link>https://poc.intelseclab.com/pocs/binary/2026-05-17_windows-ntlm-hash-disclosure-cve-2025-24054/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-05-17_windows-ntlm-hash-disclosure-cve-2025-24054/</guid><description>Medium severity (CVSS 6.5) — binary · CVE-2025-24054. Status: Patched. Affects: Windows File Explorer (Windows Shell). Tags: NTLM, NTLMv2, hash-disclosure, zero-click, Windows, File-Explorer, UNC, SMB, credential-theft, in-the-wild, state-sponsored.</description><category>binary</category><category>Medium</category><category>NTLM</category><category>NTLMv2</category><category>hash-disclosure</category><category>zero-click</category><category>Windows</category><category>File-Explorer</category><category>UNC</category><category>SMB</category><category>credential-theft</category><category>in-the-wild</category><category>state-sponsored</category></item><item><title>Jenkins CLI Arbitrary File Read to RCE (CVE-2024-23897)</title><link>https://poc.intelseclab.com/pocs/web/2026-05-17_jenkins-cli-arbitrary-file-read-rce/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-05-17_jenkins-cli-arbitrary-file-read-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2024-23897. Status: Weaponized. Affects: Jenkins controller (CLI endpoint). Tags: arbitrary-file-read, Jenkins, CLI, credential-theft, RCE, unauthenticated, KEV.</description><category>web</category><category>Critical</category><category>arbitrary-file-read</category><category>Jenkins</category><category>CLI</category><category>credential-theft</category><category>RCE</category><category>unauthenticated</category><category>KEV</category></item></channel></rss>