Subscribe via feed.
Archive for August, 2020

October CMS Build 465 XSS / File Read / File Deletion / CSV Injection

Posted by deepcore under exploit (No Respond)

October CMS builds 465 and below suffer from arbitrary file read, arbitrary file deletion, file uploading to arbitrary locations, persistent and reflective cross site scripting, and CSV injection vulnerabilities.

[webapps] Daily Expenses Management System 1.0 – 'username' SQL Injection

Posted by deepcore under Security (No Respond)

Daily Expenses Management System 1.0 – ‘username’ SQL Injection

Tags: ,

[dos] RTSP for iOS 1.0 – 'IP Address' Denial of Service (PoC)

Posted by deepcore under Security (No Respond)

RTSP for iOS 1.0 – ‘IP Address’ Denial of Service (PoC)

Tags: ,

[dos] Mocha Telnet Lite for iOS 4.2 – 'User' Denial of Service (PoC)

Posted by deepcore under Security (No Respond)

Mocha Telnet Lite for iOS 4.2 – ‘User’ Denial of Service (PoC)

Tags: ,

[webapps] Pi-hole 4.3.2 – Remote Code Execution (Authenticated)

Posted by deepcore under Security (No Respond)

Pi-hole 4.3.2 – Remote Code Execution (Authenticated)

Tags: ,

Setup UGEEK UPS3 HAT on Raspberry

Posted by deepquest under Raspberry (No Respond)

Setup UGEEK UPS3 HAT on Raspberry.

Tags: , , ,

Daily Tracker System 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Daily Tracker System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

Daily Tracker System 1.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Daily Tracker System version 1.0 suffers from a cross site scripting vulnerability.

Online Bike Rental 1.0 Shell Upload

Posted by deepcore under exploit (No Respond)

Online Bike Rental version 1.0 suffers from a remote shell upload vulnerability.

Online Shopping Alphaware 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Online Shopping Alphaware version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.