Sploitus

CVE-2018-1000006

32 known exploits for CVE-2018-1000006

GitHub Electron versions 1.8.2-beta.3 and earlier, 1.7.10 and earlier, 1.6.15 and earlier has a vulnerability in the protocol handler, specifically Electron apps running on Windows 10, 7 or 2008 that register custom protocol handlers can be tricked in arbitrary command execution if the user clicks on a specially crafted URL. This has been fixed in versions 1.8.2-beta.4, 1.7.11, and 1.6.16.

Atom Electron
= 1.8.2
Fix
Available
CVSS 2.0
9.3 HIGH
CVSS 3.1
8.8 HIGH
EPSS
76.0% (100th percentile)
Weakness
CWE-78
NVD status
Modified
Published
2018-01-24
CVE-2018-1000006 at NVD
Authoritative description, scoring and affected products

32 known exploits for CVE-2018-1000006

Proof-of-concept code and exploit modules indexed by Sploitus

CVE-2018-1000006-DEMO
2026-08-26 KitPloitKITPLOIT
Exploit for Improper Encoding or Escaping of Output in F5 Nginx
2023-05-01 hundanGITEE
Exploit for SQL Injection in Zabbix
2022-01-19 天艺GITEE
Exploit for Improper Encoding or Escaping of Output in F5 Nginx
2021-12-15 iceCreamGITEE
Exploit for Improper Encoding or Escaping of Output in F5 Nginx
2021-11-24 MOBGITEE
Exploit for SQL Injection in Zabbix
2021-11-13 三度的雪GITEE
Exploit for Improper Encoding or Escaping of Output in F5 Nginx
2021-09-26 阿雷GITEE
Exploit for Improper Encoding or Escaping of Output in F5 Nginx
2021-09-19 W3lk1nGITEE
Exploit for Improper Encoding or Escaping of Output in F5 Nginx
2021-08-15 d0ng1uGITEE
Exploit for Improper Encoding or Escaping of Output in F5 Nginx
2021-06-11 owlGITEE
Exploit for SQL Injection in Zabbix
2021-05-16 nullGITEE
Exploit for Improper Encoding or Escaping of Output in F5 Nginx
2021-03-29 wangnfcGITEE
Exploit for Exposure of Sensitive Information to an Unauthorized Actor in Gitlab
2021-01-18 sadfasdfGITEE
Exploit for Improper Encoding or Escaping of Output in F5 Nginx
2020-07-30 orcnirnavaGITEE
Exploit for Exposure of Sensitive Information to an Unauthorized Actor in Gitlab
2020-07-28 小义的爸爸GITEE
Exploit for Exposure of Sensitive Information to an Unauthorized Actor in Gitlab
2020-07-17 ZcocGITEE
Exploit for Improper Encoding or Escaping of Output in F5 Nginx
2020-07-12 AndyGITEE
Exploit for Improper Encoding or Escaping of Output in F5 Nginx
2020-07-10 aryaGITEE
Exploit for Improper Encoding or Escaping of Output in F5 Nginx
2020-06-18 Dawson_JonesGITEE
Exploit for OS Command Injection in Atom Electron
2020-05-15 4meGITEE
Exploit for Improper Encoding or Escaping of Output in F5 Nginx
2020-05-07 一个卿呀GITEE
Exploit for Exposure of Sensitive Information to an Unauthorized Actor in Gitlab
2020-04-08 fahawifiGITEE
Exploit for Exposure of Sensitive Information to an Unauthorized Actor in Gitlab
2020-04-02 hhGITEE
Exploit for Exposure of Sensitive Information to an Unauthorized Actor in Gitlab
2019-10-11 HFOUGITEE
Exploit for Exposure of Sensitive Information to an Unauthorized Actor in Gitlab
2018-08-21 老野战猪GITEE
Exodus Wallet (ElectronJS Framework) - Remote Code Execution (Metasploit)
2018-03-29 MetasploitEXPLOITDBRuby
Exodus Wallet (ElectronJS Framework) Remote Code Execution
2018-03-29 Daniel TeixeiraPACKETSTORMRuby
Exodus Wallet (ElectronJS Framework) - Remote Code Execution Exploit
2018-03-29 metasploitZDTRuby
Exodus Wallet (ElectronJS Framework) Remote Code Execution
2018-01-26 WflkiPACKETSTORM
Exodus Wallet (ElectronJS Framework) remote Code Execution
2018-01-25 Wflki, Daniel TeixeiraMETASPLOITRuby
Exodus Wallet (ElectronJS Framework) - Remote Code Execution
2018-01-25 WflkiEXPLOITDB
Exploit for OS Command Injection in Atom Electron
2018-01-25 CHYbetaGITHUB