<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Curl — PoC Archive</title><link>https://poc.intelseclab.com/tags/curl/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 16 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/curl/index.xml" rel="self" type="application/rss+xml"/><item><title>Cisco IMC Argument Injection to Root RCE (CVE-2026-20200)</title><link>https://poc.intelseclab.com/pocs/network/2026-08-16_cve-2026-20200-cisco-imc-argument-injection-rce/</link><pubDate>Sun, 16 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-08-16_cve-2026-20200-cisco-imc-argument-injection-rce/</guid><description>Critical severity (CVSS 9.9) — network · CVE-2026-20200 / NSIDE-SA-2026-003. Status: Patched. Affects: Cisco Integrated Management Controller (CIMC). Tags: cisco, imc, cimc, argument-injection, rce, redfish, curl, reverse-shell, arm, file-read, file-write, CVE-2026-20200.</description><category>network</category><category>Critical</category><category>cisco</category><category>imc</category><category>cimc</category><category>argument-injection</category><category>rce</category><category>redfish</category><category>curl</category><category>reverse-shell</category><category>arm</category><category>file-read</category><category>file-write</category><category>CVE-2026-20200</category></item><item><title>Xiongmai XM530 IP Camera ONVIF Authentication Bypass (CVE-2025-65856)</title><link>https://poc.intelseclab.com/pocs/hardware/2026-07-06_cve-2025-65856-onvif-camera-auth-bypass/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/hardware/2026-07-06_cve-2025-65856-onvif-camera-auth-bypass/</guid><description>Critical severity (CVSS 9.8) — hardware · CVE-2025-65856. Status: Weaponized. Affects: Xiongmai XM530-based IP camera ONVIF service (tested on model XM530_50X50-WG_8M). Tags: xiongmai, xm530, onvif, ip-camera, iot, auth-bypass, access-control, information-disclosure, rtsp, cwe-306, cwe-287, python, bash, curl.</description><category>hardware</category><category>Critical</category><category>xiongmai</category><category>xm530</category><category>onvif</category><category>ip-camera</category><category>iot</category><category>auth-bypass</category><category>access-control</category><category>information-disclosure</category><category>rtsp</category><category>cwe-306</category><category>cwe-287</category><category>python</category><category>bash</category><category>curl</category></item><item><title>MCPJam Inspector Unauthenticated Command Injection RCE (CVE-2026-23744)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-23744-mcpjam-inspector-htb-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-23744-mcpjam-inspector-htb-rce/</guid><description>Critical severity — web · CVE-2026-23744. Status: PoC. Affects: MCPJam Inspector v1.4.2. Tags: mcpjam-inspector, mcp, command-injection, rce, curl, hack-the-box, reverse-shell, chained-privesc.</description><category>web</category><category>Critical</category><category>mcpjam-inspector</category><category>mcp</category><category>command-injection</category><category>rce</category><category>curl</category><category>hack-the-box</category><category>reverse-shell</category><category>chained-privesc</category></item><item><title>Langflow Custom Component Remote Code Execution — CVE-2026-33017</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33017-langflow-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33017-langflow-rce/</guid><description>Critical severity — web · CVE-2026-33017. Status: PoC. Affects: Langflow (flow-building / LLM pipeline platform). Tags: langflow, rce, custom-component, code-execution, flow-builder, reverse-shell, curl.</description><category>web</category><category>Critical</category><category>langflow</category><category>rce</category><category>custom-component</category><category>code-execution</category><category>flow-builder</category><category>reverse-shell</category><category>curl</category></item><item><title>curl SMB Connection-Reuse Use-After-Free (CVE-2026-3805)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-3805-curl-smb-use-after-free/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-3805-curl-smb-use-after-free/</guid><description>High severity — network · CVE-2026-3805. Status: PoC. Affects: curl / libcurl. Tags: curl, libcurl, use-after-free, smb, cwe-416, memory-corruption, asan.</description><category>network</category><category>High</category><category>curl</category><category>libcurl</category><category>use-after-free</category><category>smb</category><category>cwe-416</category><category>memory-corruption</category><category>asan</category></item><item><title>curl SMTP EXPN Recipient CRLF Command Injection</title><link>https://poc.intelseclab.com/pocs/network/2026-07-03_curl-smtp-expn-crlf-injection/</link><pubDate>Fri, 03 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-03_curl-smtp-expn-crlf-injection/</guid><description>Medium severity — network · None assigned as of 2026-07-03. Status: PoC. Affects: curl / libcurl (SMTP support). Tags: curl, smtp, crlf-injection, command-injection, expn, vrfy, protocol-injection, libcurl.</description><category>network</category><category>Medium</category><category>curl</category><category>smtp</category><category>crlf-injection</category><category>command-injection</category><category>expn</category><category>vrfy</category><category>protocol-injection</category><category>libcurl</category></item></channel></rss>