<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Soap — PoC Archive</title><link>https://poc.intelseclab.com/tags/soap/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 09 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/soap/index.xml" rel="self" type="application/rss+xml"/><item><title>Check Point Security Management / Multi-Domain Server SmartConsole Authentication Bypass via Forged Application Certificate Bind (CVE-2026-16232)</title><link>https://poc.intelseclab.com/pocs/network/2026-08-09_cve-2026-16232-checkpoint-smartconsole-auth-bypass/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-08-09_cve-2026-16232-checkpoint-smartconsole-auth-bypass/</guid><description>Critical severity (CVSS 9.1) — network · CVE-2026-16232. Status: Patched. Affects: Check Point Security Management Server and Multi-Domain Security Management Server (MDS) — the legacy FWM/CPMI SIC service on TCP 18190 and the CPM SOAP web services on TCP 19009. Tags: check-point, smartconsole, security-management-server, multi-domain-server, cpmi, sic, fwm, authentication-bypass, CWE-287, improper-authentication, privilege-escalation, sso-token-forgery, soap, dle, cisa-kev, bod-26-04, python, firewall-management.</description><category>network</category><category>Critical</category><category>check-point</category><category>smartconsole</category><category>security-management-server</category><category>multi-domain-server</category><category>cpmi</category><category>sic</category><category>fwm</category><category>authentication-bypass</category><category>CWE-287</category><category>improper-authentication</category><category>privilege-escalation</category><category>sso-token-forgery</category><category>soap</category><category>dle</category><category>cisa-kev</category><category>bod-26-04</category><category>python</category><category>firewall-management</category></item><item><title>D-Link AX1500 SetDeviceSettings `DeviceName` OS Command Injection (CVE-2025-60854)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-60854-dlink-ax1500-devicename-command-injection/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-60854-dlink-ax1500-devicename-command-injection/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2025-60854. Status: Weaponized. Affects: D-Link AX1500 router firmware (HNAP/DHMAPI web management SOAP interface). Tags: d-link, ax1500, router, command-injection, os-command-injection, hnap, soap, telnetd, cwe-78, iot.</description><category>network</category><category>Critical</category><category>d-link</category><category>ax1500</category><category>router</category><category>command-injection</category><category>os-command-injection</category><category>hnap</category><category>soap</category><category>telnetd</category><category>cwe-78</category><category>iot</category></item><item><title>Microsoft Exchange Authenticated Arbitrary File Read via EWS Reference Attachment (CVE-2026-45504)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-45504-exchange-file-read/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-45504-exchange-file-read/</guid><description>High severity — web · CVE-2026-45504. Status: PoC. Affects: Microsoft Exchange Server (OWA / EWS). Tags: exchange, owa, ews, file-read, ssrf, ntlm, soap, lfi.</description><category>web</category><category>High</category><category>exchange</category><category>owa</category><category>ews</category><category>file-read</category><category>ssrf</category><category>ntlm</category><category>soap</category><category>lfi</category></item><item><title>MantisBT SOAP `mc_issue_add` Authentication Bypass (Type Juggling) — CVE-2026-30849</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-30849-mantisbt-soap-auth-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-30849-mantisbt-soap-auth-bypass/</guid><description>High severity — web · CVE-2026-30849. Status: Weaponized. Affects: MantisBT (SOAP API). Tags: mantisbt, soap, auth-bypass, type-juggling, php, bug-tracker, typescript.</description><category>web</category><category>High</category><category>mantisbt</category><category>soap</category><category>auth-bypass</category><category>type-juggling</category><category>php</category><category>bug-tracker</category><category>typescript</category></item><item><title>PHP 8.5.7 StreamBucket-to-SOAP Numeric Cookie Remote Code Execution</title><link>https://poc.intelseclab.com/pocs/web/2026-07-03_php-857-streambucket-soap-rce/</link><pubDate>Fri, 03 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-03_php-857-streambucket-soap-rce/</guid><description>Critical severity — web · None assigned as of 2026-07-03. Status: PoC. Affects: PHP CLI (Zend Engine) — ArrayIterator, StreamBucket, SoapClient internals. Tags: php, type-confusion, streambucket, soap, hashtable-overwrite, memory-corruption, rce, zend-engine.</description><category>web</category><category>Critical</category><category>php</category><category>type-confusion</category><category>streambucket</category><category>soap</category><category>hashtable-overwrite</category><category>memory-corruption</category><category>rce</category><category>zend-engine</category></item></channel></rss>