<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Information-Disclosure — PoC Archive</title><link>https://poc.intelseclab.com/tags/information-disclosure/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 09 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/information-disclosure/index.xml" rel="self" type="application/rss+xml"/><item><title>Apache Polaris — Cross-Tenant Credential Vending Before Location Validation in Iceberg REST Register (CVE-2026-64640)</title><link>https://poc.intelseclab.com/pocs/cloud/2026-08-09_cve-2026-64640-apache-polaris-cross-tenant-credential-vending/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/cloud/2026-08-09_cve-2026-64640-apache-polaris-cross-tenant-credential-vending/</guid><description>High severity (CVSS 8.1) — cloud · CVE-2026-64640. Status: Patched. Affects: Apache Polaris (Apache Iceberg REST catalog), registerTable and registerView endpoints. Tags: apache-polaris, iceberg, apache-iceberg, credential-vending, confused-deputy, authorization-bypass, cross-tenant, s3, storage, allowed-locations, CWE-441, CWE-639, CWE-918, ssrf, server-side-read, information-disclosure, register-table, register-view.</description><category>cloud</category><category>High</category><category>apache-polaris</category><category>iceberg</category><category>apache-iceberg</category><category>credential-vending</category><category>confused-deputy</category><category>authorization-bypass</category><category>cross-tenant</category><category>s3</category><category>storage</category><category>allowed-locations</category><category>CWE-441</category><category>CWE-639</category><category>CWE-918</category><category>ssrf</category><category>server-side-read</category><category>information-disclosure</category><category>register-table</category><category>register-view</category></item><item><title>Xiongmai XM530 IP Camera ONVIF Authentication Bypass (CVE-2025-65856)</title><link>https://poc.intelseclab.com/pocs/hardware/2026-07-06_cve-2025-65856-onvif-camera-auth-bypass/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/hardware/2026-07-06_cve-2025-65856-onvif-camera-auth-bypass/</guid><description>Critical severity (CVSS 9.8) — hardware · CVE-2025-65856. Status: Weaponized. Affects: Xiongmai XM530-based IP camera ONVIF service (tested on model XM530_50X50-WG_8M). Tags: xiongmai, xm530, onvif, ip-camera, iot, auth-bypass, access-control, information-disclosure, rtsp, cwe-306, cwe-287, python, bash, curl.</description><category>hardware</category><category>Critical</category><category>xiongmai</category><category>xm530</category><category>onvif</category><category>ip-camera</category><category>iot</category><category>auth-bypass</category><category>access-control</category><category>information-disclosure</category><category>rtsp</category><category>cwe-306</category><category>cwe-287</category><category>python</category><category>bash</category><category>curl</category></item><item><title>Twonky Server 8.5.2 Unauthenticated `/nmc/rpc/` Auth Bypass &amp; Admin Credential Log Leak (CVE-2025-13315)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-13315-twonky-server-auth-bypass/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-13315-twonky-server-auth-bypass/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2025-13315. Status: PoC. Affects: Twonky Server (Lynx Technology), a DLNA/UPnP media server. Tags: twonky-server, dlna, upnp, media-server, auth-bypass, access-control, information-disclosure, credential-leak, cwe-284, unauthenticated, nuclei.</description><category>network</category><category>Critical</category><category>twonky-server</category><category>dlna</category><category>upnp</category><category>media-server</category><category>auth-bypass</category><category>access-control</category><category>information-disclosure</category><category>credential-leak</category><category>cwe-284</category><category>unauthenticated</category><category>nuclei</category></item><item><title>Squid Proxy Sensitive Header Leak via Error Page `mailto:` Diagnostic Block (CVE-2025-62168)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-62168-squid-error-page-header-reflection-token-leak/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-62168-squid-error-page-header-reflection-token-leak/</guid><description>Critical severity (CVSS 10) — network · CVE-2025-62168. Status: PoC. Affects: Squid Proxy. Tags: squid, proxy, information-disclosure, header-reflection, jwt, token-leak, error-page, cwe-209, cwe-550.</description><category>network</category><category>Critical</category><category>squid</category><category>proxy</category><category>information-disclosure</category><category>header-reflection</category><category>jwt</category><category>token-leak</category><category>error-page</category><category>cwe-209</category><category>cwe-550</category></item><item><title>RustFS Hardcoded gRPC Authentication Token Leading to Full Node Compromise (CVE-2025-68926)</title><link>https://poc.intelseclab.com/pocs/cloud/2026-07-06_cve-2025-68926-rustfs-grpc-token-bypass/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/cloud/2026-07-06_cve-2025-68926-rustfs-grpc-token-bypass/</guid><description>Critical severity (CVSS 9.8) — cloud · CVE-2025-68926. Status: Weaponized. Affects: RustFS (Rust-based S3-compatible distributed object storage) — internal node-to-node gRPC service. Tags: rustfs, grpc, hardcoded-credentials, authentication-bypass, object-storage, s3-compatible, information-disclosure, credential-theft, data-destruction, cwe-798, cwe-306.</description><category>cloud</category><category>Critical</category><category>rustfs</category><category>grpc</category><category>hardcoded-credentials</category><category>authentication-bypass</category><category>object-storage</category><category>s3-compatible</category><category>information-disclosure</category><category>credential-theft</category><category>data-destruction</category><category>cwe-798</category><category>cwe-306</category></item><item><title>Pterodactyl Panel Unauthenticated Path Traversal via locale.json Leaking Database Credentials (CVE-2025-49132)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-49132-pterodactyl-locale-path-traversal/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-49132-pterodactyl-locale-path-traversal/</guid><description>Critical severity (CVSS 10) — web · CVE-2025-49132. Status: Weaponized. Affects: Pterodactyl Panel (game server management panel). Tags: pterodactyl, path-traversal, unauthenticated, information-disclosure, credential-leak, database, php, config-exposure, cwe-22.</description><category>web</category><category>Critical</category><category>pterodactyl</category><category>path-traversal</category><category>unauthenticated</category><category>information-disclosure</category><category>credential-leak</category><category>database</category><category>php</category><category>config-exposure</category><category>cwe-22</category></item><item><title>AI Engine WordPress Plugin Unauthenticated MCP Token Disclosure to Admin Account Creation (CVE-2025-11749)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-11749-ai-engine-admin-account-creation/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-11749-ai-engine-admin-account-creation/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-11749. Status: Weaponized. Affects: AI Engine plugin for WordPress (mwai). Tags: wordpress, ai-engine, mwai, mcp, rest-api, information-disclosure, privilege-escalation, admin-account-creation, python, mass-scanner.</description><category>web</category><category>Critical</category><category>wordpress</category><category>ai-engine</category><category>mwai</category><category>mcp</category><category>rest-api</category><category>information-disclosure</category><category>privilege-escalation</category><category>admin-account-creation</category><category>python</category><category>mass-scanner</category></item><item><title>ZTE ZXHN H298A / H108N Router Unauthenticated Credential Disclosure (CVE-2026-34474)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-34474-zte-router-sensitive-data-exposure/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-34474-zte-router-sensitive-data-exposure/</guid><description>High severity — network · CVE-2026-34474. Status: PoC. Affects: ZTE ZXHN H298A (hardware 1.1) and ZXHN H108N (hardware 2.6) home routers. Tags: information-disclosure, router, firmware, unauthenticated, credential-leak, iot, zte, wifi.</description><category>network</category><category>High</category><category>information-disclosure</category><category>router</category><category>firmware</category><category>unauthenticated</category><category>credential-leak</category><category>iot</category><category>zte</category><category>wifi</category></item><item><title>Xboard / V2Board — Magic Link Token Leak Unauth Account Takeover (CVE-2026-39912)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-39912-xboard-v2board-account-takeover/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-39912-xboard-v2board-account-takeover/</guid><description>Critical severity (CVSS 9.1) — web · CVE-2026-39912. Status: Weaponized. Affects: V2Board / Xboard (VPN/proxy subscription management panels). Tags: xboard, v2board, php, laravel, account-takeover, magic-link, unauthenticated, information-disclosure, proxy-panel.</description><category>web</category><category>Critical</category><category>xboard</category><category>v2board</category><category>php</category><category>laravel</category><category>account-takeover</category><category>magic-link</category><category>unauthenticated</category><category>information-disclosure</category><category>proxy-panel</category></item><item><title>WebKit WebGPU `importExternalTexture` Cross-Origin Video Frame Leak (CVE-2026-43700)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-43700-webgpu-importexternaltexture-cross-origin-leak/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-43700-webgpu-importexternaltexture-cross-origin-leak/</guid><description>High severity — web · CVE-2026-43700. Status: PoC. Affects: WebKit / Safari (GPUDevice.importExternalTexture WebGPU API). Tags: webkit, safari, webgpu, cross-origin, information-disclosure, same-origin-policy-bypass, external-texture, video.</description><category>web</category><category>High</category><category>webkit</category><category>safari</category><category>webgpu</category><category>cross-origin</category><category>information-disclosure</category><category>same-origin-policy-bypass</category><category>external-texture</category><category>video</category></item><item><title>WebKit Navigation API `NavigateEvent.sourceElement` Cross-Origin DOM Leak (CVE-2026-43735)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-43735-webkit-navigateevent-sourceelement-leak/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-43735-webkit-navigateevent-sourceelement-leak/</guid><description>High severity — web · CVE-2026-43735. Status: PoC. Affects: WebKit / Safari (Navigation API — NavigateEvent.sourceElement). Tags: webkit, safari, navigation-api, navigateevent, cross-origin, information-disclosure, dom-access, same-origin-policy-bypass, iframe.</description><category>web</category><category>High</category><category>webkit</category><category>safari</category><category>navigation-api</category><category>navigateevent</category><category>cross-origin</category><category>information-disclosure</category><category>dom-access</category><category>same-origin-policy-bypass</category><category>iframe</category></item><item><title>Veno File Manager Absolute Path Disclosure (CVE-2026-37069)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-37069-veno-file-manager-path-disclosure/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-37069-veno-file-manager-path-disclosure/</guid><description>Low severity — web · CVE-2026-37069. Status: PoC. Affects: Veno File Manager Project. Tags: veno-file-manager, path-disclosure, unauthenticated, information-disclosure, cwe-200.</description><category>web</category><category>Low</category><category>veno-file-manager</category><category>path-disclosure</category><category>unauthenticated</category><category>information-disclosure</category><category>cwe-200</category></item><item><title>phpSysInfo IP Allowlist Bypass via X-Forwarded-For Spoofing — CVE-2026-55584</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-55584-phpsysinfo-xff-allowlist-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-55584-phpsysinfo-xff-allowlist-bypass/</guid><description>High severity (CVSS 7.5) — web · CVE-2026-55584 / GHSA-786w-p5pm-cvgh. Status: PoC. Affects: phpSysInfo. Tags: phpsysinfo, ip-spoofing, x-forwarded-for, access-control-bypass, cwe-290, information-disclosure.</description><category>web</category><category>High</category><category>phpsysinfo</category><category>ip-spoofing</category><category>x-forwarded-for</category><category>access-control-bypass</category><category>cwe-290</category><category>information-disclosure</category></item><item><title>Notepad++ nativeLang.xml Format String Crash / Info Disclosure — CVE-2026-3008</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-3008-notepadpp-formatstring/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-3008-notepadpp-formatstring/</guid><description>Medium severity — binary · CVE-2026-3008. Status: PoC. Affects: Notepad++ 8.9.3. Tags: notepad++, format-string, wsprintfw, dos, information-disclosure, localization, windows.</description><category>binary</category><category>Medium</category><category>notepad++</category><category>format-string</category><category>wsprintfw</category><category>dos</category><category>information-disclosure</category><category>localization</category><category>windows</category></item><item><title>InvoicePlane Unauthenticated Path Traversal in Guest Controller (CVE-2026-23491)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-23491-invoiceplane-path-traversal/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-23491-invoiceplane-path-traversal/</guid><description>Critical severity — web · CVE-2026-23491. Status: PoC. Affects: InvoicePlane. Tags: invoiceplane, path-traversal, directory-traversal, unauthenticated, information-disclosure, php, arbitrary-file-read.</description><category>web</category><category>Critical</category><category>invoiceplane</category><category>path-traversal</category><category>directory-traversal</category><category>unauthenticated</category><category>information-disclosure</category><category>php</category><category>arbitrary-file-read</category></item><item><title>GitLab WebSocket GraphqlChannel Unauthorized Method Enumeration — CVE-2026-5173</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-5173-gitlab-websocket-graphql-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-5173-gitlab-websocket-graphql-bypass/</guid><description>High severity — web · CVE-2026-5173. Status: PoC. Affects: GitLab CE/EE, ActionCable WebSocket endpoint (/-/cable), GraphqlChannel. Tags: gitlab, websocket, graphql, actioncable, graphqlchannel, information-disclosure, broken-access-control.</description><category>web</category><category>High</category><category>gitlab</category><category>websocket</category><category>graphql</category><category>actioncable</category><category>graphqlchannel</category><category>information-disclosure</category><category>broken-access-control</category></item><item><title>Gitea Container Registry Anonymous Auth Bypass (CVE-2026-27771)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-27771-gitea-registry-auth-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-27771-gitea-registry-auth-bypass/</guid><description>Critical severity — web · CVE-2026-27771. Status: Weaponized. Affects: Gitea (self-hosted Git service with OCI container registry). Tags: gitea, forgejo, oci-registry, auth-bypass, container-registry, unauthenticated, information-disclosure.</description><category>web</category><category>Critical</category><category>gitea</category><category>forgejo</category><category>oci-registry</category><category>auth-bypass</category><category>container-registry</category><category>unauthenticated</category><category>information-disclosure</category></item><item><title>Apache HTTP Server mod_rewrite/mod_setenvif/mod_proxy_fcgi ap_expr Local File Read — CVE-2026-24072</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-24072-apache-httpd-ap-expr-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-24072-apache-httpd-ap-expr-lpe/</guid><description>Medium severity — web · CVE-2026-24072. Status: PoC. Affects: Apache HTTP Server (httpd). Tags: apache-httpd, mod_rewrite, ap_expr, htaccess, local-privilege-escalation, arbitrary-file-read, information-disclosure, cwe-668.</description><category>web</category><category>Medium</category><category>apache-httpd</category><category>mod_rewrite</category><category>ap_expr</category><category>htaccess</category><category>local-privilege-escalation</category><category>arbitrary-file-read</category><category>information-disclosure</category><category>cwe-668</category></item><item><title>Android ActivityManagerService dumpBitmapsProto() Missing Permission Check (CVE-2026-0047)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-0047-activitymanager-bitmap-leak/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-0047-activitymanager-bitmap-leak/</guid><description>Critical severity (CVSS 8.4) — binary · CVE-2026-0047. Status: Weaponized. Affects: Android system_server ActivityManagerService.dumpBitmapsProto(). Tags: android, activitymanagerservice, binder, missing-permission-check, information-disclosure, zero-permission, baklava, bitmap-theft.</description><category>binary</category><category>Critical</category><category>android</category><category>activitymanagerservice</category><category>binder</category><category>missing-permission-check</category><category>information-disclosure</category><category>zero-permission</category><category>baklava</category><category>bitmap-theft</category></item><item><title>Next.js unstable_cache Object-Argument Cache-Key Collision</title><link>https://poc.intelseclab.com/pocs/web/2026-07-03_nextjs-unstable-cache-key-collision/</link><pubDate>Fri, 03 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-03_nextjs-unstable-cache-key-collision/</guid><description>High severity — web · None assigned as of 2026-07-03. Status: PoC. Affects: Next.js (App Router, Data Cache). Tags: nextjs, unstable_cache, cache-poisoning, cache-key-collision, data-cache, information-disclosure, server-side-caching, javascript.</description><category>web</category><category>High</category><category>nextjs</category><category>unstable_cache</category><category>cache-poisoning</category><category>cache-key-collision</category><category>data-cache</category><category>information-disclosure</category><category>server-side-caching</category><category>javascript</category></item><item><title>Firefox Smart Window Private URL Exfiltration</title><link>https://poc.intelseclab.com/pocs/web/2026-07-03_firefox-smartwindow-private-url-exfil/</link><pubDate>Fri, 03 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-03_firefox-smartwindow-private-url-exfil/</guid><description>High severity — web · None assigned as of 2026-07-03. Status: PoC. Affects: Firefox Smart Window (AI browsing assistant feature). Tags: firefox, smart-window, ai-assistant, privacy-leak, information-disclosure, url-token-exfiltration, browser, prompt-injection.</description><category>web</category><category>High</category><category>firefox</category><category>smart-window</category><category>ai-assistant</category><category>privacy-leak</category><category>information-disclosure</category><category>url-token-exfiltration</category><category>browser</category><category>prompt-injection</category></item><item><title>Squidbleed — Squid Proxy FTP Gateway Out-of-Bounds Heap Read (CVE-2026-47729)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-01_cve-2026-47729-squidbleed-squid-ftp-oob-read/</link><pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-01_cve-2026-47729-squidbleed-squid-ftp-oob-read/</guid><description>Medium severity — network · CVE-2026-47729. Status: PoC. Affects: Squid Proxy — FTP gateway / directory-listing parser. Tags: memory-disclosure, information-disclosure, Squid, proxy, FTP, heap-overflow, oob-read, credential-theft, legacy.</description><category>network</category><category>Medium</category><category>memory-disclosure</category><category>information-disclosure</category><category>Squid</category><category>proxy</category><category>FTP</category><category>heap-overflow</category><category>oob-read</category><category>credential-theft</category><category>legacy</category></item><item><title>Next.js i18n Middleware Bypass (CVE-2026-44573)</title><link>https://poc.intelseclab.com/pocs/web/2026-05-17_nextjs-i18n-middleware-bypass/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-05-17_nextjs-i18n-middleware-bypass/</guid><description>High severity (CVSS 7.5) — web · CVE-2026-44573. Status: Weaponized. Affects: Next.js Pages Router with i18n configuration. Tags: middleware-bypass, i18n, _next/data, Pages-Router, authorization-bypass, information-disclosure, Next.js, unauthenticated.</description><category>web</category><category>High</category><category>middleware-bypass</category><category>i18n</category><category>_next/data</category><category>Pages-Router</category><category>authorization-bypass</category><category>information-disclosure</category><category>Next.js</category><category>unauthenticated</category></item></channel></rss>