Subscribe via feed.
Archive for July, 2021

[webapps] Church Management System 1.0 – Unrestricted File Upload to Remote Code Execution (Authenticated)

Posted by deepcore under Security (No Respond)

Church Management System 1.0 – Unrestricted File Upload to Remote Code Execution (Authenticated)

Tags: ,

[webapps] Church Management System 1.0 – 'Multiple' Stored Cross-Site Scripting (XSS)

Posted by deepcore under Security (No Respond)

Church Management System 1.0 – ‘Multiple’ Stored Cross-Site Scripting (XSS)

Tags: ,

AKCP sensorProbe SPX476 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

AKCP sensorProbe SPX476 suffers from multiple cross site scripting vulnerabilities.

b2evolution 7.2.2 Cross Site Request Forgery

Posted by deepcore under exploit (No Respond)

b2evolution version 7.2.2 suffers from a cross site request forgery vulnerability.

WordPress Modern Events Calendar 5.16.2 Information Disclosure

Posted by deepcore under exploit (No Respond)

WordPress Modern Events Calendar plugin version 5.16.2 suffers from an issue where unauthenticated parties can export all event data.

WordPress Modern Events Calendar 5.16.2 Shell Upload

Posted by deepcore under exploit (No Respond)

WordPress Modern Events Calendar plugin version 5.16.2 suffers from a remote shell upload vulnerability.

Scratch Desktop 3.17 Code Execution / Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Scratch Desktop version 3.17 suffers from code execution and cross site scripting vulnerabilities.

Microsoft PrintNightmare Proof Of Concept

Posted by deepcore under exploit (No Respond)

This is the Impacket implementation of the PrintNightmare proof of concept originally created by Zhiniang Peng and Xuefeng Li that leverages a privilege escalation vulnerability in the Windows Print Spooler.

Garbage Collection Management System 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Garbage Collection Management System version 1.0 suffers from a remote SQL injection vulnerability.

PrintNightmare Windows Spooler Service Remote Code Execution

Posted by deepcore under exploit (No Respond)

PrintNightmare remote code execution proof of concept exploit for the Windows Spooler Service.