Subscribe via feed.
Archive for September, 2021

[webapps] Library Management System 1.0 – Blind Time-Based SQL Injection (Unauthenticated)

Posted by deepcore under Security (No Respond)

Library Management System 1.0 – Blind Time-Based SQL Injection (Unauthenticated)

Tags: ,

[webapps] WordPress Plugin WooCommerce Booster Plugin 5.4.3 – Authentication Bypass

Posted by deepcore under Security (No Respond)

WordPress Plugin WooCommerce Booster Plugin 5.4.3 – Authentication Bypass

Tags: ,

Git git-lfs Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit modules exploits a critical vulnerability in Git Large File Storage (Git LFS), an open source Git extension for versioning large files, which allows attackers to achieve remote code execution if the Windows-using victim is tricked into cloning the attacker’s malicious repository using a vulnerable Git version control tool.

Zenitel AlphaCom XE Audio Server 11.2.3.10 Shell Upload

Posted by deepcore under exploit (No Respond)

Remote command execution exploit for Zenitel AlphaCom XE Audio Server versions up to 11.2.3.10 which have a web interface called AlphaWeb XE that allows for a remote shell upload.

Evolution CMS 3.1.6 Remote Code Execution

Posted by deepcore under exploit (No Respond)

Evolution CMS version 3.1.6 authenticated remote code execution exploit.

AHSS-PHP 1.0 Cross Site Scripting / SQL Injection

Posted by deepcore under exploit (No Respond)

AHSS-PHP version 1.0 suffers from cross site scripting and remote SQL injection vulnerabilities.

Support Board 3.3.3 SQL Injection

Posted by deepcore under exploit (No Respond)

Support Board version 3.3.3 suffers from a remote SQL injection vulnerability.

elFinder Archive Command Injection

Posted by deepcore under exploit (No Respond)

elFinder versions below 2.1.59 are vulnerable to a command injection vulnerability via its archive functionality. When creating a new zip archive, the name parameter is sanitized with the escapeshellarg() php function and then passed to the zip utility. Despite the sanitization, supplying the -TmTT argument as part of the name parameter is still permitted and […]

[webapps] ImpressCMS 1.4.2 – Remote Code Execution (RCE) (Authenticated)

Posted by deepcore under Security (No Respond)

ImpressCMS 1.4.2 – Remote Code Execution (RCE) (Authenticated)

Tags: ,

elFinder Archive Command Injection

Posted by deepcore under exploit (No Respond)

elFinder versions below 2.1.59 are vulnerable to a command injection vulnerability via its archive functionality. When creating a new zip archive, the name parameter is sanitized with the escapeshellarg() php function and then passed to the zip utility. Despite the sanitization, supplying the -TmTT argument as part of the name parameter is still permitted and […]