PoC Archive PoC Archive

tag

Options-Method

  • CVE-2024-51378 web CRITICAL 10 KEV Ransomware EPSS 95%

    CyberPanel Pre-Auth Remote Code Execution via getresetstatus Command Injection (CVE-2024-51378)

    CyberPanel exposes two DNS/FTP reset-status endpoints, /dns/getresetstatus and /ftp/getresetstatus, whose handlers read a JSON statusfile property straight out of the request body and concatenate it into a shell command executed with sudo. Neither handler…

    Patched 2026-08-09