https://www.doa.go.th/th/luv.htm
https://www.doa.go.th/th/luv.htm notified by Alf404
Tags: defacementCommScope Ruckus IoT Controller 1.7.1.0 Undocumented Account
An upgrade account is included in the IoT Controller OVA that provides the vendor undocumented access via Secure Copy (SCP).
RarmaRadio 2.72.8 Denial Of Service
RarmaRadio version 2.72.8 denial of service proof of concept exploit.
Codiad 2.8.4 Shell Upload
Codiad version 2.8.4 suffers from a remote shell upload vulnerability.
ProFTPd 1.3.5 Remote Command Execution
ProFTPd version 1.3.5 remote command execution exploit. This is a variant of the original vulnerability discovered in 2015 with credit going to R-73eN.
Nagios XI / Fusion Privilege Escalation / Cross Site Scripting / Code Execution
Skylight Cyber has identified a total of 13 vulnerabilities in Nagios XI and Nagios Fusion servers. These include remote code execution, cross site scripting, privilege escalation, and more.
Pluck CMS 4.7.13 Remote Shell Upload
Pluck CMS version 4.7.13 suffers from a remote shell upload vulnerability.
i-doit 1.15.2 Cross Site Scripting
i-doit version 1.15.2 suffers from a cross site scripting vulnerability.
nginx 1.20.0 DNS Resolver Off-By-One Heap Write
An off-by-one error in ngx_resolver_copy() while processing DNS responses allows a network attacker to write a dot character (‘.’, 0x2E) out of bounds in a heap allocated buffer. The vulnerability can be triggered by a DNS response in reply to a DNS request from nginx when the resolver primitive is configured. A specially crafted packet […]