Subscribe via feed.
Archive for November, 2020

[webapps] PESCMS TEAM 2.3.2 – Multiple Reflected XSS

Posted by deepcore under Security (No Respond)

PESCMS TEAM 2.3.2 – Multiple Reflected XSS

Tags: ,

Huawei LCD_Service 1.0.1.0 Unquoted Service Path

Posted by deepcore under exploit (No Respond)

Huawei LCD_Service version 1.0.1.0 suffers from an unquoted service path vulnerability.

Online Doctor Appointment Booking System PHP And MySQL 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Online Doctor Appointment Booking System PHP and MySQL version 1.0 suffers from a remote SQL injection vulnerability.

AIX 5.3L libc Buffer Overflow

Posted by deepcore under exploit (No Respond)

AIX version 5.3L libc local environment handling local root exploit. The AIX 5.3L (and possibly others) libc is vulnerable to multiple buffer overflow issues in the handling of locale environment variables. This allows for exploitation of any setuid root binary that makes use of functions such as setlocale() which do not perform bounds checking when […]

Online News Portal Local File Inclusion

Posted by deepcore under exploit (No Respond)

Online News Portal versions released prior to November 16, 2020 have been identified as being susceptible to a local file inclusion vulnerability.

Medical Center Portal Management System SQL Injection

Posted by deepcore under exploit (No Respond)

Medical Center Portal Management System released prior to November 16, 2020 have been identified as being susceptible to a local file inclusion vulnerability.

Social Networking Site SQL Injection

Posted by deepcore under exploit (No Respond)

Social Networking Site versions released prior to November 17, 2020 have been found susceptible to a remote SQL injection vulnerability that allows for authentication bypass.

EgavilanMedia User Registration And Login System With Admin Panel SQL Injection

Posted by deepcore under exploit (No Respond)

EgavilanMedia User Registration and Login System with Admin Panel versions released prior to November 17, 2020 appear susceptible to a remote SQL injection vulnerability that allows for authentication bypass.

Aerospike Database 5.1.0.3 Remote Command Execution

Posted by deepcore under exploit (No Respond)

Aerospike Database version 5.1.0.3 suffers from a remote command execution vulnerability.

Grocy Household Management Solution 2.7.1 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Grocy Household Management Solution version 2.7.1 suffers from a persistent cross site scripting vulnerability.