Subscribe via feed.
Archive for August, 2021

WordPress Picture Gallery 1.4.2 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

WordPress Picture Gallery plugin version 1.4.2 suffers from a persistent cross site scripting vulnerability.

Simple Library Management System 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Simple Library Management System version 1.0 suffers from a remote SQL injection vulnerability.

MobileTogether Server 7.3 XML Injection

Posted by deepcore under exploit (No Respond)

RedTeam Pentesting discovered a vulnerability in the MobileTogether server which allows users with access to at least one application to read arbitrary, non-binary files from the file system and perform server-side requests. The vulnerability can also be used to deny availability of the system. As an example, this advisory shows the compromise of the server’s […]

MobileTogether Server 7.3 XML Injection

Posted by deepcore under exploit (No Respond)

RedTeam Pentesting discovered a vulnerability in the MobileTogether server which allows users with access to at least one application to read arbitrary, non-binary files from the file system and perform server-side requests. The vulnerability can also be used to deny availability of the system. As an example, this advisory shows the compromise of the server’s […]

OneNav Beta 0.9.12 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

OneNav Beta version 0.9.12 suffers from a persistent cross site scripting vulnerability.

Microsoft Windows Malicious Software Removal Tool Privilege Escalation

Posted by deepcore under exploit (No Respond)

Microsoft Windows suffers from unsafe temporary directory use with the Malicious Software Removal Tool that can lead to elevation of privilege.

[webapps] Cockpit CMS 0.11.1 – 'Username Enumeration & Password Reset' NoSQL Injection

Posted by deepcore under Security (No Respond)

Cockpit CMS 0.11.1 – ‘Username Enumeration & Password Reset’ NoSQL Injection

Tags: ,

[local] Amica Prodigy 1.7 – Privilege Escalation

Posted by deepcore under Security (No Respond)

Amica Prodigy 1.7 – Privilege Escalation

Tags: ,

[webapps] IPCop 2.1.9 – Remote Code Execution (RCE) (Authenticated)

Posted by deepcore under Security (No Respond)

IPCop 2.1.9 – Remote Code Execution (RCE) (Authenticated)

Tags: ,

Microsoft Windows Malicious Software Removal Tool Privilege Escalation

Posted by deepcore under exploit (No Respond)

Microsoft Windows suffers from unsafe temporary directory use with the Malicious Software Removal Tool that can lead to elevation of privilege.