Subscribe via feed.
Archive for November, 2021

[webapps] WordPress Plugin WPSchoolPress 2.1.16 – 'Multiple' Cross Site Scripting (XSS)

Posted by deepcore under Security (No Respond)

WordPress Plugin WPSchoolPress 2.1.16 – ‘Multiple’ Cross Site Scripting (XSS)

Tags: ,

Mumara Classic 2.93 SQL Injection

Posted by deepcore under exploit (No Respond)

Mumara Classic versions 2.93 and below suffer from a remote SQL injection vulnerability.

Microsoft Windows MultiPoint Server 2011 SP1 Local Privilege Escalation

Posted by deepcore under exploit (No Respond)

Microsoft MultiPoint Server 2011 version 6.1 Compilation 7601 Service Pack 1 suffers from an RpcEptMapper and Dnschade local privilege escalation vulnerability.

WordPress WP Symposium Pro 2021.10 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

WordPress WP Symposium Pro version 2021.10 suffers from a persistent cross site scripting vulnerability.

Xlight FTP 3.9.3.1 Buffer Overflow

Posted by deepcore under exploit (No Respond)

Xlight FTP version 3.9.3.1 suffers from a buffer overflow vulnerability.

WordPress AccessPress Social Icons 1.8.2 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

WordPress AccessPress Social Icons plugin version 1.8.2 suffers from a persistent cross site scripting vulnerability.

Aerohive NetConfig 10.0r8a Local File Inclusion / Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits local file inclusion and log poisoning vulnerabilities (CVE-2020-16152) in Aerohive NetConfig, version 10.0r8a build-242466 and older in order to achieve unauthenticated remote code execution as the root user. NetConfig is the Aerohive/Extreme Networks HiveOS administrative webinterface. Vulnerable versions allow for LFI because they rely on a version of PHP 5 that […]

Aerohive NetConfig 10.0r8a Local File Inclusion / Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits local file inclusion and log poisoning vulnerabilities (CVE-2020-16152) in Aerohive NetConfig, version 10.0r8a build-242466 and older in order to achieve unauthenticated remote code execution as the root user. NetConfig is the Aerohive/Extreme Networks HiveOS administrative webinterface. Vulnerable versions allow for LFI because they rely on a version of PHP 5 that […]

[webapps] Mumara Classic 2.93 – 'license' SQL Injection (Unauthenticated)

Posted by deepcore under Security (No Respond)

Mumara Classic 2.93 – ‘license’ SQL Injection (Unauthenticated)

Tags: ,

[local] Windows MultiPoint Server 2011 SP1 – RpcEptMapper and Dnschade Local Privilege Escalation

Posted by deepcore under Security (No Respond)

Windows MultiPoint Server 2011 SP1 – RpcEptMapper and Dnschade Local Privilege Escalation

Tags: ,