Subscribe via feed.
Archive for June, 2021

Remote Mouse GUI 3.008 Privilege Escalation

Posted by deepcore under exploit (No Respond)

Remote Mouse GUI version 3.008 suffers from a local privilege escalation vulnerability.

WordPress Admin Columns Cross Site Scripting

Posted by deepcore under exploit (No Respond)

WordPress Admin Columns plugin versions below 5.5.2 Pro and 4.3.2 Pro suffers from a cross site scripting vulnerability.

Online Library Management System 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Online Library Management System version 1.0 suffers from a remote SQL injection vulnerability.

Online Library Management System 1.0 Shell Upload

Posted by deepcore under exploit (No Respond)

Online Library Management System version 1.0 suffers from a remote shell upload vulnerability. This is a formal exploit for the vulnerability priorly discovered by Jyotsna Adhana in October of 2020.

Simple CRM 3.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Simple CRM version 3.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

Microsoft Windows Filtering Platform Token Access Check Privilege Escalation

Posted by deepcore under exploit (No Respond)

The Windows Filtering Platform does not verify the token impersonation level when checking filters allowing the bypass of firewall rules leading to elevation of privilege.

WordPress Poll, Survey, Questionnaire And Voting System 1.5.2 SQL Injection

Posted by deepcore under exploit (No Respond)

WordPress Poll, Survey, Questionnaire and Voting System plugin version 1.5.2 suffers from a blind remote SQL injection vulnerability.

WordPress WP Google Maps 8.1.11 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

WordPress WP Google Maps plugin version 8.1.11 suffers from a persistent cross site scripting vulnerability.

Monitorr 1.7.6m Bypass / Information Disclosure / Shell Upload

Posted by deepcore under exploit (No Respond)

This ruby script is a 4-in-1 exploit that leverages shell upload, bypass, and information disclosure vulnerabilities in Monitorr version 1.7.6m.

F5 BIG-IQ VE 8.0.0-2923215 Remote Root

Posted by deepcore under exploit (No Respond)

F5 BIG-IQ VE version 8.0.0-2923215 post-authentication remote root code execution exploit.