Subscribe via feed.
Archive for January, 2018

FiberHome MIFI LM53Q1 Information Disclosure / Password Change

Posted by deepcore under exploit (No Respond)

FiberHome MIFI LM53Q1 suffers from credential disclosure and password change vulnerabilities.

WordPress Social Media Widget By Acurax 3.2.5 Cross Site Request Forgery

Posted by deepcore under exploit (No Respond)

WordPress Social Media Widget by Acurax plugin version 3.2.5 suffers from a cross site request forgery vulnerability.

Synology DiskStation Manager (DSM) User Enumeration

Posted by deepcore under exploit (No Respond)

Synology DiskStation Manager (DMS) versions prior to 6.1.3-15152 suffer from a forget_passwd.cgi user enumeration vulnerability.

WordPress LearnDash 2.5.3 File Upload

Posted by deepcore under exploit (No Respond)

WordPress LearnDash plugin version 2.5.3 suffers from an arbitrary file upload vulnerability.

WordPress CMS Tree Page View 1.4 CSRF / Privilege Escalation

Posted by deepcore under exploit (No Respond)

WordPress CMS Tree Page View plugin version 1.4 suffers from cross site request forgery and privilege escalation vulnerabilities.

WordPress Admin Menu Tree Page View 2.6.9 CSRF / Privilege Escalation

Posted by deepcore under exploit (No Respond)

WordPress Admin Menu Tree Page View plugin version 2.6.9 suffers from cross site request forgery and privilege escalation vulnerabilities.

Rx Tera 2.0 Cross Site Request Forgery

Posted by deepcore under exploit (No Respond)

Rx Tera version 2.0 suffers from a cross site request forgery vulnerability.

Office Tracker 11.2.5 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Office Tracker version 11.2.5 suffers from a cross site scripting vulnerability.

AvantFAX 3.3.3 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

AvantFAX version 3.3.3 suffers from a cross site scripting vulnerability.

Vanilla Forums Cross Site Request Forgery

Posted by deepcore under exploit (No Respond)

Vanilla Forums versions prior to 2.1.5 suffer from a cross site request forgery vulnerability.