Subscribe via feed.
Archive for December, 2020

[webapps] Flexmonster Pivot Table & Charts 2.7.17 – 'To remote CSV' Reflected XSS

Posted by deepcore under Security (No Respond)

Flexmonster Pivot Table & Charts 2.7.17 – ‘To remote CSV’ Reflected XSS

Tags: ,

[webapps] Flexmonster Pivot Table & Charts 2.7.17 – 'Remote Report' Reflected XSS

Posted by deepcore under Security (No Respond)

Flexmonster Pivot Table & Charts 2.7.17 – ‘Remote Report’ Reflected XSS

Tags: ,

[webapps] Flexmonster Pivot Table & Charts 2.7.17 – 'To OLAP' Reflected XSS

Posted by deepcore under Security (No Respond)

Flexmonster Pivot Table & Charts 2.7.17 – ‘To OLAP’ Reflected XSS

Tags: ,

[webapps] Spiceworks 7.5 – HTTP Header Injection

Posted by deepcore under Security (No Respond)

Spiceworks 7.5 – HTTP Header Injection

Tags: ,

[webapps] Academy-LMS 4.3 – Stored XSS

Posted by deepcore under Security (No Respond)

Academy-LMS 4.3 – Stored XSS

Tags: ,

[webapps] Spotweb 1.4.9 – 'search' SQL Injection

Posted by deepcore under Security (No Respond)

Spotweb 1.4.9 – ‘search’ SQL Injection

Tags: ,

[webapps] Queue Management System 4.0.0 – "Add User" Stored XSS

Posted by deepcore under Security (No Respond)

Queue Management System 4.0.0 – “Add User” Stored XSS

Tags: ,

[webapps] WordPress Plugin Contact Form 7 5.3.1 – Unrestricted File Upload

Posted by deepcore under Security (No Respond)

WordPress Plugin Contact Form 7 5.3.1 – Unrestricted File Upload

Tags: ,

Alumni Management System 1.0 Shell Upload

Posted by deepcore under exploit (No Respond)

Alumni Management System version 1.0 suffers from a remote shell upload vulnerability. Original discovery for this vulnerability in this version is attributed to Valerio Alessandroni.

Point Of Sale System 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Point of Sale System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.