Subscribe via feed.
Archive for November, 2021

[webapps] WordPress Plugin Hotel Listing 3 – 'Multiple' Cross-Site Scripting (XSS)

Posted by deepcore under Security (No Respond)

WordPress Plugin Hotel Listing 3 – ‘Multiple’ Cross-Site Scripting (XSS)

Tags: ,

[webapps] PHPJabbers Simple CMS 5 – 'name' Persistent Cross-Site Scripting (XSS)

Posted by deepcore under Security (No Respond)

PHPJabbers Simple CMS 5 – ‘name’ Persistent Cross-Site Scripting (XSS)

Tags: ,

i3 International Annexxus Cameras Ax-n 5.2.0 Application Logic Flaw

Posted by deepcore under exploit (No Respond)

i3 International Annexxus Cameras Ax-n version 5.2.0 does not allow creation of more than one administrator account on the system. This also applies for deletion of the administrative account. The logic behind this restriction can be bypassed by parameter manipulation using dangerous verbs like PUT and DELETE and improper server-side validation. Once a normal account […]

Trojan.Win32.Pasta.mca Insecure Permissions

Posted by deepcore under exploit (No Respond)

Trojan.Win32.Pasta.mca malware suffers from an insecure permissions vulnerability.

PHPJabbers Simple CMS 5 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

PHPJabbers Simple CMS version 5 suffers from a persistent cross site scripting vulnerability.

WordPress Hotel Listing 3.x Cross Site Scripting

Posted by deepcore under exploit (No Respond)

WordPress Hotel Listing plugin version 3.x suffers from a cross site scripting vulnerability.

My Movie Collection Sinatra App Movie Cross Site Scripting

Posted by deepcore under exploit (No Respond)

My Movie Collection Sinatra App suffers from a Movie related cross site scripting vulnerability.

My Movie Collection Sinatra App Login Cross Site Scripting

Posted by deepcore under exploit (No Respond)

My Movie Collection Sinatra App suffers from Login related cross site scripting vulnerabilities.

Trojan.Win32.Phires.zm Insecure Permissions

Posted by deepcore under exploit (No Respond)

Trojan.Win32.Phires.zm malware suffers from an insecure permissions vulnerability.

Trojan.Win32.Delf.bna Information Disclosure

Posted by deepcore under exploit (No Respond)

Trojan.Win32.Delf.bna malware suffers from an information leakage vulnerability.