PoC Archive PoC Archive

tag

Session-Poisoning

  • CVE-2025-32432 web CRITICAL 10 KEV EPSS 100%

    Craft CMS Pre-Auth Remote Code Execution via Session Poisoning + Yii2 PhpManager Gadget (CVE-2025-32432)

    Craft CMS shipped an incomplete patch for the earlier CVE-2023-41892 deserialization RCE, leaving a critical, pre-auth code-injection chain exploitable through the assets/generate-transform action. An unauthenticated attacker first poisons the server-side PHP…

    Patched 2026-07-31
  • CVE-2026-44403 web HIGH

    Wing FTP Server Admin Session Poisoning via Lua loadfile() RCE (CVE-2026-44403)

    Wing FTP Server's WebAdmin session mechanism serializes session values as executable Lua source using [[...]] long-string literals. Because bracket-sanitization code that would strip [/] characters from session values was commented out, a value containing ]]…

    Patched 2026-07-05
  • CVE-2026-41940 web CRITICAL 10 KEV Ransomware EPSS 98%

    cPanel & WHM Authentication Bypass via Session-File CRLF Injection (CVE-2026-41940)

    CVE-2026-41940 is a critical unauthenticated authentication bypass in cPanel & WHM. The vulnerable session handling flow writes attacker-controlled Authorization: Basic data to the session file before sanitization, allowing CRLF injection of trusted session…

    Patched 2026-05-16