[webapps] Budget and Expense Tracker System 1.0 – Remote Code Execution (RCE) (Unauthenticated)
Budget and Expense Tracker System 1.0 – Remote Code Execution (RCE) (Unauthenticated)
Tags: 0day, remote exploitBudget and Expense Tracker System 1.0 – Remote Code Execution (RCE) (Unauthenticated)
Tags: 0day, remote exploitThis article discusses the CVE-2021-40444 vulnerability and an alternative path that reduces the lines of JS code to trigger the issue and does not require CAB archives.
http://chaleang.go.th/er.php notified by LahBodoAmat
Tags: defacementChurch Management System 1.0 – Remote Code Execution (RCE) (Unauthenticated)
Tags: 0day, remote exploitOnline Food Ordering System 2.0 – Remote Code Execution (RCE) (Unauthenticated)
Tags: 0day, remote exploitWordPress 5.7 – ‘Media Library’ XML External Entity Injection (XXE) (Authenticated)
Tags: 0day, remote exploitT-Soft E-Commerce 4 – change ‘admin credentials’ Cross-Site Request Forgery (CSRF)
Tags: 0day, remote exploitSimple Attendance System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.