Subscribe via feed.
Archive for August, 2020

Curfew e-Pass Management System 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Curfew e-Pass Management System version 1.0 suffers from multiple remote SQL injection vulnerabilities. Original discovery of SQL injection in this version is attributed to gh1mau.

Daily Expenses Management System 1.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Daily Expenses Management System version 1.0 suffers from multiple persistent cross site scripting vulnerabilities.

Daily Expenses Management System 1.0 Cross SIte Request Forgery

Posted by deepcore under exploit (No Respond)

Daily Expenses Management System version 1.0 suffers from a cross site request forgery vulnerability.

Daily Expenses Management System 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Daily Expenses Management System version 1.0 suffers from multiple remote SQL injection vulnerabilities. Original discovery of SQL injection in this version is attributed to Daniel Ortiz.

Online Shopping Alphaware 1.0 Cross Site Request Forgery

Posted by deepcore under exploit (No Respond)

Online Shopping Alphaware version 1.0 suffers from a cross site request forgery vulnerability.

Online Shopping Alphaware 1.0 Arbitrary File Upload

Posted by deepcore under exploit (No Respond)

Online Shopping Alphaware version 1.0 suffers from an arbitrary file upload vulnerability.

Online Shopping Alphaware 1.0 Unauthorized Administrative Access

Posted by deepcore under exploit (No Respond)

Online Shopping Alphaware version 1.0 suffers from an unauthorized administrative functionality access vulnerability.

Victor CMS 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Victor CMS version 1.0 suffers from a search remote SQL injection vulnerability. Original discovery of SQL injection in this version is attributed to BKpatron.

Docker Privileged Container Escape

Posted by deepcore under exploit (No Respond)

This Metasploit module escapes from a privileged Docker container and obtains root on the host machine by abusing the Linux cgroup notification on release feature. This exploit should work against any container started with the following flags: –cap-add=SYS_ADMIN, –privileged.

[webapps] Daily Expenses Management System 1.0 – 'item' SQL Injection

Posted by deepcore under Security (No Respond)

Daily Expenses Management System 1.0 – ‘item’ SQL Injection

Tags: ,