Subscribe via feed.
Archive for May, 2021

GravCMS 1.10.7 Remote Command Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits an arbitrary config write/update vulnerability to achieve remote code execution. Unauthenticated users can execute a terminal command under the context of the web server user. Grav Admin Plugin is an HTML user interface that provides a way to configure Grav and create and modify pages. In versions 1.10.7 and earlier, an […]

[webapps] WordPress Plugin WP Super Edit 2.5.4 – Remote File Upload

Posted by deepcore under Security (No Respond)

WordPress Plugin WP Super Edit 2.5.4 – Remote File Upload

Tags: ,

[webapps] Schlix CMS 2.2.6-6 – Remote Code Execution (Authenticated)

Posted by deepcore under Security (No Respond)

Schlix CMS 2.2.6-6 – Remote Code Execution (Authenticated)

Tags: ,

[webapps] Schlix CMS 2.2.6-6 – 'title' Persistent Cross-Site Scripting (Authenticated)

Posted by deepcore under Security (No Respond)

Schlix CMS 2.2.6-6 – ‘title’ Persistent Cross-Site Scripting (Authenticated)

Tags: ,

Apple Security Advisory 2021-05-03-2

Posted by deepcore under Apple (No Respond)

Apple Security Advisory 2021-05-03-2 – iOS 12.5.3 addresses buffer overflow, code execution, integer overflow, and use-after-free vulnerabilities.

Tags: , ,

Apple Security Advisory 2021-05-03-1

Posted by deepcore under Apple (No Respond)

Apple Security Advisory 2021-05-03-1 – iOS 14.5.1 and iPadOS 14.5.1 addresses code execution and integer overflow vulnerabilities.

Tags: , ,

Apple Security Advisory 2021-05-03-4

Posted by deepcore under Apple (No Respond)

Apple Security Advisory 2021-05-03-4 – macOS Big Sur 11.3.1 addresses code execution and integer overflow vulnerabilities.

Tags: , ,

Apple Security Advisory 2021-05-03-3

Posted by deepcore under Apple (No Respond)

Apple Security Advisory 2021-05-03-3 – watchOS 7.4.1 addresses a code execution vulnerability.

Tags: , ,

Packet Storm New Exploits For April, 2021

Posted by deepcore under exploit (No Respond)

This archive contains all of the 162 exploits added to Packet Storm in April, 2021.

GetSimple CMS Custom JS 0.1 CSRF / XSS / Code Execution

Posted by deepcore under exploit (No Respond)

The Custom JS plugin version 0.1 for GetSimple CMS suffers from a cross site request forgery vulnerability that allows remote unauthenticated attackers to inject arbitrary client-side code into authenticated administrators browsers, which results in remote code execution on the hosting server, when an authenticated administrator visits a malicious third party website.