Subscribe via feed.
Archive for August, 2021

[webapps] Simple Water Refilling Station Management System 1.0 – Authentication Bypass

Posted by deepcore under Security (No Respond)

Simple Water Refilling Station Management System 1.0 – Authentication Bypass

Tags: ,

[webapps] Simple Water Refilling Station Management System 1.0 – Remote Code Execution (RCE) through File Upload

Posted by deepcore under Security (No Respond)

Simple Water Refilling Station Management System 1.0 – Remote Code Execution (RCE) through File Upload

Tags: ,

[webapps] CentOS Web Panel 0.9.8.1081 – Stored Cross-Site Scripting (XSS)

Posted by deepcore under Security (No Respond)

CentOS Web Panel 0.9.8.1081 – Stored Cross-Site Scripting (XSS)

Tags: ,

[webapps] COMMAX Smart Home Ruvie CCTV Bridge DVR Service – Config Write / DoS (Unauthenticated)

Posted by deepcore under Security (No Respond)

COMMAX Smart Home Ruvie CCTV Bridge DVR Service – Config Write / DoS (Unauthenticated)

Tags: ,

[webapps] NetGear D1500 V1.0.0.21_1.0.1PE – 'Wireless Repeater' Stored Cross-Site Scripting (XSS)

Posted by deepcore under Security (No Respond)

NetGear D1500 V1.0.0.21_1.0.1PE – ‘Wireless Repeater’ Stored Cross-Site Scripting (XSS)

Tags: ,

RATES SYSTEM 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

RATES SYSTEM version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass. Original discovery of SQL injection in this version is attributed to Halit Akaydin in August of 2021.

Police Crime Record Management System 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Police Crime Record Management System version 1.0 suffers from a remote SQL injection vulnerability.

Police Crime Record Management System 1.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Police Crime Record Management System version 1.0 suffers from a persistent cross site scripting vulnerability.

Easy-Mock 1.6.0 Remote Code Execution

Posted by deepcore under exploit (No Respond)

Easy-Mock version 1.6.0 authenticated remote code execution exploit.

Chikitsa 2.0.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Chikitsa version 2.0.0 suffers from a cross site scripting vulnerability.