Subscribe via feed.
Archive for July, 2021

[webapps] WordPress Plugin Modern Events Calendar 5.16.2 – Remote Code Execution (Authenticated)

Posted by deepcore under Security (No Respond)

WordPress Plugin Modern Events Calendar 5.16.2 – Remote Code Execution (Authenticated)

Tags: ,

[webapps] Scratch Desktop 3.17 – Cross-Site Scripting/Remote Code Execution (XSS/RCE)

Posted by deepcore under Security (No Respond)

Scratch Desktop 3.17 – Cross-Site Scripting/Remote Code Execution (XSS/RCE)

Tags: ,

phpAbook 0.9i SQL Injection

Posted by deepcore under exploit (No Respond)

phpAbook version 0.9i suffers from a remote SQL injection vulnerability.

Doctors Patients Management System 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Doctors Patients Management System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

Securepoint SSL VPN Client 2.0.30 Local Privilege Escalation

Posted by deepcore under exploit (No Respond)

Securepoint SSL VPN Client version 2.0.30 suffers from a local privilege escalation vulnerability.

Apache Superset 1.1.0 Account Enumeration

Posted by deepcore under exploit (No Respond)

Apache Superset version 1.1.0 suffers from a time-based account enumeration vulnerability.

KVM nested_svm_vmrun Double Fetch

Posted by deepcore under exploit (No Respond)

A KVM guest on AMD can launch a L2 guest without the Intercept VMRUN control bit by exploiting a TOCTOU vulnerability in nested_svm_vmrun. Executing vmrun from the L2 guest, will then trigger a second call to nested_svm_vmrun and corrupt svm->nested.hsave with data copied out of the L2 vmcb. For kernel versions that include the commit […]

[webapps] Vianeos OctoPUS 5 – 'login_user' SQLi

Posted by deepcore under Security (No Respond)

Vianeos OctoPUS 5 – ‘login_user’ SQLi

Tags: ,

[webapps] Online Voting System 1.0 – Remote Code Execution (Authenticated)

Posted by deepcore under Security (No Respond)

Online Voting System 1.0 – Remote Code Execution (Authenticated)

Tags: ,

[webapps] Online Voting System 1.0 – Authentication Bypass (SQLi)

Posted by deepcore under Security (No Respond)

Online Voting System 1.0 – Authentication Bypass (SQLi)

Tags: ,