Subscribe via feed.
Archive for February, 2021

WordPress Under Construction, Coming Soon, And Maintenance Mode 1.1.1 SSRF / XSS

Posted by deepcore under exploit (No Respond)

WordPress Under Construction, Coming Soon, and Maintenance Mode plugin version 1.1.1 suffers from cross site scripting and server-side request forgery vulnerabilities.

Simple Employee Records System 1.0 Shell Upload

Posted by deepcore under exploit (No Respond)

Simple Employee Records System version 1.0 suffers from an unauthenticated remote shell upload vulnerability.

Yeastar TG400 GSM Gateway 91.3.0.3 Path Traversal

Posted by deepcore under exploit (No Respond)

Yeastar TG400 GSM Gateway version 91.3.0.3 suffers from a path traversal vulnerability.

Nagios XI 5.7.5 Remote Code Execution

Posted by deepcore under exploit (No Respond)

Nagios XI version 5.7.5 suffers from a cross site scripting and multiple remote code execution vulnerabilities.

LightCMS 1.3.4 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

LightCMS version 1.3.4 suffers from a persistent cross site scripting vulnerability.

Squid 4.14 / 5.0.5 Code Execution / Double Free

Posted by deepcore under exploit (No Respond)

Squid versions 4.14 and 5.0.5 suffer from a double free vulnerability that can result in code execution.

Trojan-Dropper.Win32.Daws.etlm Unauthenticated Reboot

Posted by deepcore under exploit (No Respond)

Trojan-Dropper.Win32.Daws.etlm malware suffers from a remote unauthenticated system reboot vulnerability.

Trojan-Spy.Win32.SpyEyes.elr Insecure Permissions

Posted by deepcore under exploit (No Respond)

Trojan-Spy.Win32.SpyEyes.elr malware suffers from an insecure permissions vulnerability.

Backdoor.Win32.Azbreg.amw Insecure Permissions

Posted by deepcore under exploit (No Respond)

Backdoor.Win32.Azbreg.amw malware suffers from an insecure permissions vulnerability.

Trojan.Win32.Hotkeychick.am Insecure Permissions

Posted by deepcore under exploit (No Respond)

Trojan.Win32.Hotkeychick.am malware suffers from an insecure permissions vulnerability.