A Cross-Site Scripting (XSS) vulnerability exists in OURPHP versions up to and including 7.2.0, specifically in the /client/manage/ourphp_out.php endpoint. The vulnerability allows attackers to inject arbitrary JavaScript or HTML code into the web page, which is then executed in the context of the user's browser.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a Proof-of-Concept (PoC) environment for CVE-2023-30212, demonstrating a Local File Inclusion (LFI) vulnerability in a custom PHP web application. The environment is set up using Docker, running Apache with PHP 7.4 on port 8088. The main files are: - vulnerable.php: Contains an LFI vulnerability by including a file specified via the 'file' GET parameter without sanitization. - malicious.php: Contains a payload that executes a system command to create /tmp/pwned. - README.md: Provides detailed instructions and PoC steps, including how to leak the source of malicious.php using php://filter and how to trigger the payload for code execution. - Dockerfile and docker-compose.yaml: Used to build and run the vulnerable environment. The exploit demonstrates how an attacker can use LFI to read the contents of malicious.php, then directly access it to execute arbitrary commands, resulting in the creation of a file on the server. The attack vector is network-based, targeting the web server via HTTP requests. The endpoints of interest are the vulnerable and malicious PHP scripts, as well as the file created as a result of successful exploitation.
This repository provides a proof-of-concept (POC) exploit and vulnerable environment for CVE-2023-30212, a Cross-Site Scripting (XSS) vulnerability in OURPHP <= 7.2.0. The repository includes a Dockerfile to set up a vulnerable instance of OURPHP with MySQL, and PHP files that represent the core of the CMS. The README.md gives detailed instructions for building and running the Docker environment, configuring the database, and executing the exploit. The main exploit is a crafted URL targeting '/client/manage/ourphp_out.php' that injects a JavaScript payload, resulting in an alert box when visited. The repository is structured for educational and testing purposes, allowing users to reproduce and observe the XSS vulnerability in a controlled environment. No advanced or weaponized payloads are included; the exploit demonstrates the vulnerability via a simple alert.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.