Subscribe via feed.
Archive for August, 2021

Moodle 3.9 Remote Code Execution

Posted by deepcore under exploit (No Respond)

Moodle version 3.9 authenticated remote code execution exploit.

GFI Mail Archiver 15.1 Arbitrary File Upload

Posted by deepcore under exploit (No Respond)

GFI Mail Archiver versions 15.1 and below Telerik UI component unauthenticated arbitrary file upload exploit.

GFI Mail Archiver 15.1 Arbitrary File Upload

Posted by deepcore under exploit (No Respond)

GFI Mail Archiver versions 15.1 and below Telerik UI component unauthenticated arbitrary file upload exploit.

Apache OfBiz 17.12.01 Remote Command Execution

Posted by deepcore under exploit (No Respond)

Apache OfBiz version 17.12.01 exploit that achieves remote command execution via unsafe deserialization of XMLRPC arguments.

WordPress WP Customize Login 1.1 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

WordPress WP Customize Login plugin version 1.1 suffers from a persistent cross site scripting vulnerability.

Riak Insecure Default Configuration / Remote Command Execution

Posted by deepcore under exploit (No Respond)

Riak runs as an Erlang service configured with a default cookie of riak that allows for remote command execution if not modified before use.

Client Management System 1.1 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Client Management System version 1.1 suffers from a persistent cross site scripting vulnerability. This is a variant from the discovery of persistent cross site scripting in this version originally found by Bhavesh Kaul in June of 2021.

qdPM 9.2 Information Disclosure

Posted by deepcore under exploit (No Respond)

qdPM version 9.2 discloses the password and connection string for the database in an internet-accessible file.

[webapps] GFI Mail Archiver 15.1 – Telerik UI Component Arbitrary File Upload (Unauthenticated)

Posted by deepcore under Security (No Respond)

GFI Mail Archiver 15.1 – Telerik UI Component Arbitrary File Upload (Unauthenticated)

Tags: ,

[webapps] CMSuno 1.7 – 'tgo' Stored Cross-Site Scripting (XSS) (Authenticated)

Posted by deepcore under Security (No Respond)

CMSuno 1.7 – ‘tgo’ Stored Cross-Site Scripting (XSS) (Authenticated)

Tags: ,