Subscribe via feed.
Archive for October, 2020

Hotel Management System 1.0 Remote Code Execution

Posted by deepcore under exploit (No Respond)

Hotel Management System version 1.0 authenticated remote code execution exploit.

Company Visitor Management System (CVMS) 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Company Visitor Management System (CVMS) version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

Zoo Management System 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Zoo Management System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

Simple Grocery Store Sales And Inventory System 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Simple Grocery Store Sales and Inventory System 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

Microsoft Windows Uninitialized Variable Local Privilege Escalation

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits CVE-2019-1458, an arbitrary pointer dereference vulnerability within win32k which occurs due to an uninitialized variable, which allows user mode attackers to write a limited amount of controlled data to an attacker controlled address in kernel memory. By utilizing this vulnerability to execute controlled writes to kernel memory, an attacker can gain […]

[webapps] aaPanel 6.6.6 – Privilege Escalation & Remote Code Execution (Authenticated)

Posted by deepcore under Security (No Respond)

aaPanel 6.6.6 – Privilege Escalation & Remote Code Execution (Authenticated)

Tags: ,

[webapps] Restaurant Reservation System 1.0 – 'date' SQL Injection (Authenticated)

Posted by deepcore under Security (No Respond)

Restaurant Reservation System 1.0 – ‘date’ SQL Injection (Authenticated)

Tags: ,

[webapps] Company Visitor Management System (CVMS) 1.0 – Authentication Bypass

Posted by deepcore under Security (No Respond)

Company Visitor Management System (CVMS) 1.0 – Authentication Bypass

Tags: ,

[webapps] Employee Management System 1.0 – Cross Site Scripting (Stored)

Posted by deepcore under Security (No Respond)

Employee Management System 1.0 – Cross Site Scripting (Stored)

Tags: ,

[webapps] Alumni Management System 1.0 – Authentication Bypass

Posted by deepcore under Security (No Respond)

Alumni Management System 1.0 – Authentication Bypass

Tags: ,