Subscribe via feed.
Archive for October, 2021

IFSC Code Finder Project 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

IFSC Code Finder Project version 1.0 suffers from a remote SQL injection vulnerability.

Yellowfin Cross Site Scripting / Insecure Direct Object Reference

Posted by deepcore under exploit (No Respond)

Yellowfin versions prior to 9.6.1 suffer from persistent cross site scripting and insecure direct object reference vulnerabilities.

WebKit PointerCaptureController::processPendingPointerCapture Heap Use-After-Free

Posted by deepcore under exploit (No Respond)

WebKit suffers from a heap use-after-free vulnerability in PointerCaptureController::processPendingPointerCapture.

WebKit EventHandler::keyEvent Heap Use-After-Free

Posted by deepcore under exploit (No Respond)

WebKit suffers from a heap use-after-free vulnerability in EventHandler::keyEvent.

WebKit DOMWindow::open Heap Use-After-Free

Posted by deepcore under exploit (No Respond)

WebKit suffers from a heap use-after-free vulnerability in DOMWindow::open.

[webapps] i-Panel Administration System 2.0 – Reflected Cross-site Scripting (XSS)

Posted by deepcore under Security (No Respond)

i-Panel Administration System 2.0 – Reflected Cross-site Scripting (XSS)

Tags: ,

[webapps] i-Panel Administration System 2.0 – Reflected Cross-site Scripting (XSS)

Posted by deepcore under Security (No Respond)

i-Panel Administration System 2.0 – Reflected Cross-site Scripting (XSS)

Tags: ,

WebKit DOMWindow::open Heap Use-After-Free

Posted by deepcore under exploit (No Respond)

WebKit suffers from a heap use-after-free vulnerability in DOMWindow::open.

Pharmacy Point Of Sale System 1.0 Cross Site Request Forgery

Posted by deepcore under exploit (No Respond)

Pharmacy Point of Sale System version 1.0 suffers from a cross site request forgery vulnerability.

Simple Issue Tracker System 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Simple Issue Tracker System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.