Subscribe via feed.
Archive for September, 2021

OpenCats 0.9.4 XML Injection

Posted by deepcore under exploit (No Respond)

OpenCats version 0.9.4 suffers from an XML external entity injection vulnerability.

ManageEngine OpManager SumPDU Java Deserialization

Posted by deepcore under exploit (No Respond)

An HTTP endpoint used by the Manage Engine OpManager Smart Update Manager component can be leveraged to deserialize an arbitrary Java object. This can be abused by an unauthenticated remote attacker to execute OS commands in the context of the OpManager application. This vulnerability is also present in other products that are built on top […]

[webapps] Filerun 2021.03.26 – Remote Code Execution (RCE) (Authenticated)

Posted by deepcore under Security (No Respond)

Filerun 2021.03.26 – Remote Code Execution (RCE) (Authenticated)

Tags: ,

[webapps] Simple Attendance System 1.0 – Unauthenticated Blind SQLi

Posted by deepcore under Security (No Respond)

Simple Attendance System 1.0 – Unauthenticated Blind SQLi

Tags: ,

ManageEngine OpManager SumPDU Java Deserialization

Posted by deepcore under exploit (No Respond)

An HTTP endpoint used by the Manage Engine OpManager Smart Update Manager component can be leveraged to deserialize an arbitrary Java object. This can be abused by an unauthenticated remote attacker to execute OS commands in the context of the OpManager application. This vulnerability is also present in other products that are built on top […]

Maxpatrol 8 / Xspider Denial Of Service

Posted by deepcore under exploit (No Respond)

Positive Technologies Maxpatrol 8 and Xspider appears to suffer from a denial of service vulnerability.

WordPress 5.7 Media Library XML Injection

Posted by deepcore under exploit (No Respond)

WordPress version 5.7 suffers from a Media Library XML external entity injection vulnerability.

Church Management System 1.0 Shell Upload

Posted by deepcore under exploit (No Respond)

Church Management System version 1.0 remote shell upload exploit.

Online Food Ordering System 2.0 Shell Upload

Posted by deepcore under exploit (No Respond)

Online Food Ordering System version 2.0 remote shell upload exploit.

Budget And Expense Tracker System 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Budget and Expense Tracker System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.