http://therapy.huahinhospital.go.th
http://therapy.huahinhospital.go.th notified by Al Catraz
Tags: defacementhttp://therapy.huahinhospital.go.th notified by Al Catraz
Tags: defacementWater Billing System 1.0 – ‘username’ and ‘password’ parameters SQL Injection
Tags: 0day, remote exploitCar Rental Management System version 1.0 remote SQL injection and shell upload exploit.
ShoreTel Conferencing version 19.46.1802.0 suffers from a cross site scripting vulnerability.
Anuko Time Tracker version 1.19.23.5325 suffers from a CSV formula injection vulnerability.
The WordPress File Manager (wp-file-manager) plugin versions 6.0 through 6.8 allows remote attackers to upload and execute arbitrary PHP code because it renames an unsafe example elFinder connector file to have the .php extension. This, for example, allows attackers to run the elFinder upload (or mkfile and put) command to write PHP code into the […]
This Metasploit module exploits a command injection vulnerability in Metasploit Framework’s msfvenom payload generator when using a crafted APK file as an Android payload template. Affected includes Metasploit Framework versions 6.0.11 and below and Metasploit Pro versions 4.18.0 and below.