Subscribe via feed.
Archive for February, 2016

BlackBerry Enterprise Service 12 (BES12) Self-Service XSS / SQL Injection

Posted by deepcore under exploit (No Respond)

BlackBerry Enterprise Service 12 (BES12) Self-Service suffers from cross site scripting and remote SQL injection vulnerabilities.

Thru Managed File Transfer Portal 9.0.2 Insecure Direct Object Reference

Posted by deepcore under exploit (No Respond)

Thru Managed File Transfer Portal version 9.0.2 suffers from an insecure direct object reference vulnerability that references log data.

Thru Managed File Transfer Portal 9.0.2 Insecure Direct Object Reference

Posted by deepcore under exploit (No Respond)

Thru Managed File Transfer Portal version 9.0.2 suffers from an insecure direct object reference vulnerability in the upload functionality.

Thru Managed File Transfer Portal 9.0.2 Insecure Direct Object Reference

Posted by deepcore under exploit (No Respond)

Thru Managed File Transfer Portal version 9.0.2 suffers from an insecure direct object reference vulnerability in the contacts list functionality.

E-Cidade Directory Traversal

Posted by deepcore under exploit (No Respond)

E-Cidade suffers from a path traversal vulnerability.

SamenBlog Weblog Service Cross Site Request Forgery / Cross Site Scripting

Posted by deepcore under exploit (No Respond)

SamenBlog Weblog Service suffers from cross site request forgery and cross site scripting vulnerabilities.

SOLIDserver 5.0.4 Local File Inclusion

Posted by deepcore under exploit (No Respond)

SOLIDserver versions 5.0.4 and below suffer from a local file inclusion vulnerability.

PLANET IP ICA-5350V LFI / XSS / CSRF / Bypass

Posted by deepcore under exploit (No Respond)

PLANET IP surveillance camera model ICA-5350V suffers from authentication bypass, cross site request forgery, cross site scripting, arbitrary file read, hardcoded credential, and local file inclusion vulnerabilities.

ManageEngine Firewall Analyzer 8.5 SQL Injection

Posted by deepcore under exploit (No Respond)

ManageEngine Firewall Analyzer version 8.5 suffers from a remote SQL injection vulnerability.

Fiyo CMS 2.0.2.1 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Fiyo CMS version 2.0.2.1 suffers from multiple persistent cross site scripting vulnerabilities.