Subscribe via feed.
Archive for June, 2016

SugarCRM 6.5.18 PHP Code Injection

Posted by deepcore under exploit (No Respond)

SugarCRM versions 6.5.18 and below suffer from two PHP code injection vulnerabilities.

SugarCRM 6.5.18 fopen() Command Injection / XSS / SSRF

Posted by deepcore under exploit (No Respond)

SugarCRM versions 6.5.18 and below suffer from a MySugar::addDashlet insecure fopen() usage that can lead to command injection, cross site scripting, and server-side request forgery exploitation.

Wolf CMS 0.8.2 Arbitrary PHP File Upload

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a file upload vulnerability in Wolf CMS version 0.8.2. This application has an upload feature that allows an authenticated user with administrator roles to upload arbitrary files to the ‘/public’ directory.

PCMAN FTP Server 2.0.7 ls Buffer Overflow

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a buffer overflow vulnerability found in the ls command of the PCMAN FTP version 2.0.7 Server.

WordPress Contus Video Comments 1.0 File Upload

Posted by deepcore under exploit (No Respond)

WordPress Contus Video Comments plugin version 1.0 suffers from a remote file upload vulnerability.

Open-Xchange App Suite 7.8.1 Information Disclosure

Posted by deepcore under exploit (No Respond)

Open-Xchange App Suite versions 7.8.1 and below suffer from an information disclosure vulnerability.

Tiki-Wiki CMS Calendar Command Execution

Posted by deepcore under exploit (No Respond)

Tiki-Wiki CMS’s calendar module contains a remote code execution vulnerability within the viewmode GET parameter. The calendar module is NOT enabled by default. If enabled, the default permissions are set to NOT allow anonymous users to access.

Quick.Cart.Ext 6.7 Cross Site Request Forgery

Posted by deepcore under exploit (No Respond)

Quick.Cart.Ext versions 6.7 and below remote admin add cross site request forgery exploit.

Dolibarr CRM Command Injection

Posted by deepcore under exploit (No Respond)

Dolibarr CRM versions prior to 3.9.1 suffer from a command injection vulnerability.

Getsimple CMS 3.3.10 Shell Upload

Posted by deepcore under exploit (No Respond)

Getsimple CMS versions 3.3.10 and below suffer from a remote shell upload vulnerability.