Subscribe via feed.
Archive for August, 2020

Online Shopping System SQL Injection

Posted by deepcore under exploit (No Respond)

Online Shopping System from projectworlds.in suffers from a remote SQL injection vulnerability. Versions are not provided with this software currently.

Online Book Store SQL Injection

Posted by deepcore under exploit (No Respond)

Online Book Store from projectworlds.in suffers from a remote SQL injection vulnerability. Versions are not provided with this software currently.

Online Book Store Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Online Book Store from projectworlds.in suffers from a cross site scripting vulnerability. Versions are not provided with this software currently.

Car Rental Script SQL Injection

Posted by deepcore under exploit (No Respond)

Car Rental Script from projectworlds.in suffers from a remote SQL injection vulnerability. Versions are not provided with this software currently.

Car Rental Script Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Car Rental Script from projectworlds.in suffers from a cross site scripting vulnerability. Versions are not provided with this software currently.

QiHang Media Web Digital Signage 3.0.9 Password Disclosure

Posted by deepcore under exploit (No Respond)

QiHang Media Web Digital Signage version 3.0.9 suffers from a cleartext transmission/storage of sensitive information in a cookie. This allows a remote attacker to intercept the HTTP Cookie authentication credentials via a man-in-the-middle attack.

QiHang Media Web Digital Signage 3.0.9 Credential Disclosure

Posted by deepcore under exploit (No Respond)

QiHang Media Web Digital Signage version 3.0.9 suffers from a clear-text credential disclosure vulnerability that allows an unauthenticated attacker to issue a request to an unprotected directory that hosts an XML file /xml/User/User.xml and obtain administrative login information that allows for a successful authentication bypass attack.

QiHang Media Web Digital Signage 3.0.9 Arbitrary File Deletion

Posted by deepcore under exploit (No Respond)

QiHang Media Web Digital Signage version 3.0.9 suffers from an unauthenticated arbitrary file deletion vulnerability.

QiHang Media Web Digital Signage 3.0.9 Arbitrary File Disclosure

Posted by deepcore under exploit (No Respond)

QiHang Media Web Digital Signage version 3.0.9 suffers from an arbitrary file disclosure vulnerability.

QiHang Media Web Digital Signage 3.0.9 Remote Code Execution

Posted by deepcore under exploit (No Respond)

QiHang Media Web Digital Signage version 3.0.9 suffers from a pre-authentication remote code execution vulnerability.