
もらったCVE、2件目!!!!!!!! ‐ CVE-2022-24435 - [New] CVE-2026-56124
Post summary
The post simply lists two CVE identifiers without providing any further context or details.
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
phpUploader before 2.0.2 contains an unauthenticated information disclosure vulnerability that allows remote attackers to access the full contents of the uploaded-files database table by visiting any page of the application. The index model executes an unbounded SELECT query and embeds the complete JSON-encoded result set in an inline script block, exposing uploader IP addresses, Argon2ID key hashes, internal filenames, and SHA-256 fingerprints.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
AVAILABLE
Momentum
STABLE
| Date | Total | Labels |
|---|
| 2026-06-29 | 4 | Disclosure2General1Patch1 |
| 2026-06-30 | 1 | Patch1 |

もらったCVE、2件目!!!!!!!! ‐ CVE-2022-24435 - [New] CVE-2026-56124
Post summary
The post simply lists two CVE identifiers without providing any further context or details.

phpUploader v2.0.2を公開しました。 今回の更新で認証なしでのデータベース全体の情報漏洩に関する脆弱性(CVE-2026-56124)が対応されています。 v2.0.1 以前のすべてのバージョンが影響を受けます。ご利用されてる方はアップデートをお願いいたします。 https://github.com/shimosyan/phpUploader/releases/tag/v2.0.2
Post summary
The post announces the release of phpUploader v2.0.2, which contains a hot‑fix for CVE-2026-56124, an unauthenticated database disclosure vulnerability, and urges users to update.

CVE-2026-56124 phpUploader before 2.0.2 contains an unauthenticated information disclosure vulnerability that allows remote attackers to access the full contents of the uploaded-fil… https://www.cve.org/CVERecord?id=CVE-2026-56124
Post summary
The text announces a CVE for phpUploader (pre‑2.0.2) that permits unauthenticated attackers to read the full contents of uploaded files.

🚨 HIGH: CVE-2026-56124 (CVSS 7.5) - phpUploader <2.0.2 exposes unauthenticated info disclosure. Attackers can access uploaded-files database including IP addresses, Argon2ID hashes, filenames & SHA-256 fingerprints. Patch immediately. #CVE #Vulnerability https://t.co/u0Xn1T1uLg
Post summary
The tweet announces a high‑severity information‑disclosure vulnerability in phpUploader and urges users to patch immediately.

🚨*CVE* CVE-2026-56124 phpUploader before 2.0.2 contains an unauthenticated information disclosure vulnerability that allows remote attackers to access the full contents of the uploaded-fil… https://www.cve.org/CVERecord?id=CVE-2026-56124 ----- Traducción: CVE-2026-56124 php… http://infoflow.cloud`
Post summary
The post announces CVE‑2026‑56124, an unauthenticated information‑disclosure flaw in phpUploader before 2.0.2, and links to the CVE record without detailing any PoC, exploit tools, or patches.