Subscribe via feed.
Archive for August, 2020

[webapps] ManageEngine ADSelfService Build prior to 6003 – Remote Code Execution (Unauthenticated)

Posted by deepcore under Security (No Respond)

ManageEngine ADSelfService Build prior to 6003 – Remote Code Execution (Unauthenticated)

Tags: ,

[webapps] Warehouse Inventory System 1.0 – Cross-Site Request Forgery (Change Admin Password)

Posted by deepcore under Security (No Respond)

Warehouse Inventory System 1.0 – Cross-Site Request Forgery (Change Admin Password)

Tags: ,

CodeMeter 6.60 Unquoted Service Path

Posted by deepcore under exploit (No Respond)

CodeMeter version 6.60 suffers from an unquoted service path vulnerability.

Tailor Management System 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Tailor Management System version 1.0 suffers from multiple remote SQL injection vulnerabilities.

Car Rental Management System 1.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Car Rental Management System version 1.0 unauthenticated persistent cross site scripting session harvester exploit.

Online Shopping Alphaware 1.0 Insecure Direct Object Reference

Posted by deepcore under exploit (No Respond)

Online Shopping Alphaware version 1.0 suffers from an insecure direct object reference vulnerability.

Online Shopping Alphaware 1.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Online Shopping Alphaware version 1.0 suffers from multiple persistent cross site scripting vulnerabilities.

Online Shopping Alphaware 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Online Shopping Alphaware version 1.0 suffers from multiple remote SQL injection vulnerabilities. Original discovery of SQL injection in this version attributed to Ahmed Abbas.

ACTi NVR3 Standard / Professional Server 3.0.12.42 Denial Of Service

Posted by deepcore under exploit (No Respond)

ACTi NVR3 Standard or Professional Server version 3.0.12.42 denial of service proof of concept exploit.

QlikView 12.50.20000.0 Denial Of Service

Posted by deepcore under exploit (No Respond)

QlikView version 12.50.20000.0 denial of service proof of concept exploit.