Subscribe via feed.
Archive for June, 2021

KnFTP Server 1.0.0 Denial Of Service

Posted by deepcore under exploit (No Respond)

KnFTP Server version 1.0.0 LIST denial of service proof of concept exploit.

OpenEMR 5.0.1.3 Shell Upload

Posted by deepcore under exploit (No Respond)

OpenEMR version 5.0.1.3 authenticated remote shell upload exploit.

COVID-19 Testing Management System 1.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

COVID-19 Testing Management System version 1.0 suffers from a persistent cross site scripting vulnerability. This is a variant of the original discovery of cross site scripting in this version made by Rohit Burke in May of 2021.

Backdoor.Win32.Pazus.18 Authentication Bypass / Code Execution

Posted by deepcore under exploit (No Respond)

Backdoor.Win32.Pazus.18 malware suffers from bypass and code execution vulnerabilities.

Accela Civic Platform 21.1 Cross Site Scripting / Open Redirection

Posted by deepcore under exploit (No Respond)

Accela Civic Platform version 21.1 suffers from cross site scripting and open redirection vulnerabilities.

Accela Civic Platform 21.1 Insecure Direct Object Reference

Posted by deepcore under exploit (No Respond)

Accela Civic Platform version 21.1 suffers from an insecure direct object reference vulnerability.

GLPI 9.4.5 Remote Code Execution

Posted by deepcore under exploit (No Respond)

GLPI version 9.4.5 remote code execution exploit.

Backdoor.Win32.Zombam.gen Information Disclosure

Posted by deepcore under exploit (No Respond)

Backdoor.Win32.Zombam.gen malware suffers from an information leakage vulnerability.

Stock Management System 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Stock Management System version 1.0 suffers from a remote blind SQL injection vulnerability. This is a variant to the original discovery of SQL injection in this version discovered in August of 2020 by hyd3sec.

Small CRM 3.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Small CRM version 3.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.