Subscribe via feed.
Archive for September, 2021

http://kpp.nfe.go.th/kurd.html

Posted by deepcore under defacement (No Respond)

http://kpp.nfe.go.th/kurd.html notified by 0x1998

Tags:

Men Salon Management System 1.0 Cross Site Scripting / SQL Injection

Posted by deepcore under exploit (No Respond)

Men Salon Management System version 1.0 suffers from cross site scripting and remote SQL injection vulnerabilities.

WordPress Download From Files 1.48 Shell Upload

Posted by deepcore under exploit (No Respond)

WordPress Download From Files plugin version 1.48 suffers from a remote shell upload vulnerability.

Apartment Visitor Management System 1.0 Shell Upload / SQL Injection

Posted by deepcore under exploit (No Respond)

Apartment Visitor Management System version 1.0 suffers from a remote SQL injection vulnerability that allows for a shell upload.

Active WebCam 11.5 Unquoted Service Path

Posted by deepcore under exploit (No Respond)

Active WebCam version 11.5 suffers from an unquoted service path vulnerability.

Purchase Order Management System 1.0 Shell Upload

Posted by deepcore under exploit (No Respond)

Purchase Order Management System version 1.0 suffers from a remote shell upload vulnerability.

Facebook ParlAI 1.0.0 Code Execution / Deserialization

Posted by deepcore under exploit (No Respond)

Facebook ParlAI version 1.0.0 suffers from a deserialization vulnerability that can allow for code execution.

Zenitel AlphaCom XE Audio Server 11.2.3.10 Shell Upload

Posted by deepcore under exploit (No Respond)

Zenitel AlphaCom XE Audio Server versions up to 11.2.3.10 have a web interface called AlphaWeb XE that allows for a remote shell upload.

Ulfius Web Framework Remote Memory Corruption

Posted by deepcore under exploit (No Respond)

Ulfius Web Framework suffers from a remote memory corruption vulnerability. When parsing malformed HTTP requests, a heap-related initialization bug is triggered resulting in a crash in the server or potentially remote code execution with privileges of the running process.

DMA Softlab Radius Manager 4.4.0 Session Management / Cross Site Scripting

Posted by deepcore under exploit (No Respond)

DMA Softlab Radius Manager version 4.4.0 chained exploit written in go that exploits session management and cross site scripting vulnerabilities.