[webapps] Moodle 3.4.1 – Remote Code Execution
Posted by deepcore under Security (No Respond)
CMS Made Simple Showtime2 Module 3.6.2 – Authenticated Arbitrary File Upload
Tags: 0day, remote exploitThe Microsoft Windows MSHTML Engine is prone to a vulnerability that allows attackers to execute arbitrary code on vulnerable systems because of improper validation of specially crafted web documents (html, xhtml, etc).
WordPress GraceMedia Media Player plugin version 1.0 suffers from a local file inclusion vulnerability.
pfSense version 2.4.4-p1 with HAProxy Package version 0.59_14 suffers from a cross site scripting vulnerability.