<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Data-Exfiltration — PoC Archive</title><link>https://poc.intelseclab.com/tags/data-exfiltration/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 05 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/data-exfiltration/index.xml" rel="self" type="application/rss+xml"/><item><title>WordPress "Form Maker" Plugin Unauthenticated SQL Injection — CVE-2026-3359</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-3359-formmaker-wordpress-sqli/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-3359-formmaker-wordpress-sqli/</guid><description>Critical severity — web · CVE-2026-3359. Status: PoC. Affects: WordPress "Form Maker" plugin by Web10. Tags: wordpress, sql-injection, form-maker, unauthenticated, admin-ajax, wp-plugin, data-exfiltration.</description><category>web</category><category>Critical</category><category>wordpress</category><category>sql-injection</category><category>form-maker</category><category>unauthenticated</category><category>admin-ajax</category><category>wp-plugin</category><category>data-exfiltration</category></item><item><title>Sliver C2 MCP Server Unauthenticated CORS/Preflight Bypass (CVE-2026-34227)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-34227-sliver-mcp-cors-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-34227-sliver-mcp-cors-bypass/</guid><description>High severity — web · CVE-2026-34227 (GHSA-6fpf-248c-m7wm). Status: PoC. Affects: Sliver C2 framework — MCP (Model Context Protocol) server interface. Tags: sliver, c2, mcp, cors, csrf, sse, cross-origin, data-exfiltration.</description><category>web</category><category>High</category><category>sliver</category><category>c2</category><category>mcp</category><category>cors</category><category>csrf</category><category>sse</category><category>cross-origin</category><category>data-exfiltration</category></item><item><title>pdfmake Server-Side Request Forgery via Unvalidated Document URLs (CVE-2026-26801)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-26801-pdfmake-ssrf/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-26801-pdfmake-ssrf/</guid><description>High severity — web · CVE-2026-26801. Status: Weaponized. Affects: pdfmake (Node.js PDF generation library), src/URLResolver.js. Tags: ssrf, pdfmake, node-js, cloud-metadata, aws-imds, cwe-918, credential-theft, data-exfiltration.</description><category>web</category><category>High</category><category>ssrf</category><category>pdfmake</category><category>node-js</category><category>cloud-metadata</category><category>aws-imds</category><category>cwe-918</category><category>credential-theft</category><category>data-exfiltration</category></item><item><title>adx-mcp-server KQL Injection via table_name Parameter (CVE-2026-33980)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33980-adx-mcp-server-kql-injection/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33980-adx-mcp-server-kql-injection/</guid><description>High severity (CVSS 8.8) — web · CVE-2026-33980. Status: PoC. Affects: adx-mcp-server (pab1it0/adx-mcp-server). Tags: mcp, kql-injection, azure-data-explorer, ai-agent, prompt-injection, cwe-943, data-exfiltration.</description><category>web</category><category>High</category><category>mcp</category><category>kql-injection</category><category>azure-data-explorer</category><category>ai-agent</category><category>prompt-injection</category><category>cwe-943</category><category>data-exfiltration</category></item><item><title>Drupal Core PostgreSQL SQL Injection (CVE-2026-9082)</title><link>https://poc.intelseclab.com/pocs/web/2026-05-30_drupal-core-postgresql-sql-injection/</link><pubDate>Sat, 30 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-05-30_drupal-core-postgresql-sql-injection/</guid><description>Critical severity — web · CVE-2026-9082 / SA-CORE-2026-004. Status: Patched. Affects: Drupal Core. Tags: SQLi, Drupal, PostgreSQL, JSON:API, unauthenticated, data-exfiltration.</description><category>web</category><category>Critical</category><category>SQLi</category><category>Drupal</category><category>PostgreSQL</category><category>JSON:API</category><category>unauthenticated</category><category>data-exfiltration</category></item></channel></rss>