Subscribe via feed.
Archive for October, 2021

Student Quarterly Grading System 1.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Student Quarterly Grading System version 1.0 suffers from a persistent cross site scripting vulnerability.

Lifestyle Store 1.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Lifestyle Store version 1.0 suffers from a cross site scripting vulnerability.

Logitech Media Server 8.2.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Logitech Media Server version 8.2.0 suffers from a cross site scripting vulnerability.

Simple Payroll System 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Simple Payroll System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

Alchemy CMS 6.0.0 Arbitrary File Upload

Posted by deepcore under exploit (No Respond)

Alchemy CMS versions 2.x through 6.0.0 suffers from an arbitrary file upload vulnerability.

Keycloak 12.0.1 Server-Side Request Forgery

Posted by deepcore under exploit (No Respond)

Keycloak version 12.0.1 suffers from a blind server-side request forgery vulnerability.

Apache HTTP Server 2.4.50 Path Traversal / Code Execution

Posted by deepcore under exploit (No Respond)

Apache HTTP Server version 2.4.50 suffers from path traversal and code execution vulnerabilities.

Sonicwall SonicOS 7.0 Host Header Injection

Posted by deepcore under exploit (No Respond)

Sonicwall SonicOS version 7.0 suffers from a host header injection vulnerability.

myfactory.FMS 7.1-911 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

myfactory.FMS versions 7.1-911 and below suffer from a cross site scripting vulnerability.

[local] SolarWinds Kiwi CatTools 3.11.8 – Unquoted Service Path

Posted by deepcore under Security (No Respond)

SolarWinds Kiwi CatTools 3.11.8 – Unquoted Service Path

Tags: ,