Subscribe via feed.
Archive for January, 2021

CSZ CMS 1.2.9 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

CSZ CMS version 1.2.9 suffers from multiple cross site scripting vulnerabilities.

Fluentd TD-agent 4.0.1 Insecure Folder Permission

Posted by deepcore under exploit (No Respond)

Fluentd TD-agent plugin version 4.0.1 suffers from an insecure folder permission vulnerability.

Responsive FileManager 9.13.4 Path Traversal

Posted by deepcore under exploit (No Respond)

Responsive FileManager version 9.13.4 path traversal exploit. Original discovery of this finding is attributed to farisv in December of 2018.

Baby Care System 1.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Baby Care System version 1.0 suffers from a persistent cross site scripting vulnerability.

Responsive ELearning System 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Responsive ELearning System version 1.0 suffers from a remote SQL injection vulnerability.

Resumes Management And Job Application Website 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Resumes Management and Job Application Website version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

Klog Server 2.4.1 Command Injection

Posted by deepcore under exploit (No Respond)

Klog Server version 2.4.1 suffers from a remote command injection vulnerability.

WordPress Stripe Payments 2.0.39 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

WordPress Stripe Payments plugin version 2.0.39 suffers from a persistent cross site scripting vulnerability.

WordPress WP-Paginate 2.1.3 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

WordPress WP-Paginate plugin version 2.1.3 suffers from a persistent cross site scripting vulnerability.

Online Learning Management System 1.0 Remote Command Execution

Posted by deepcore under exploit (No Respond)

Online Learning Management System 1.0 remote command execution exploit. Remote shell upload was already discovered in this version in October of 2020 by Jyotsna Adhana.