[webapps] TestLink 1.19 – Arbitrary File Download (Unauthenticated)
[webapps] Employees Daily Task Management System 1.0 – 'username' SQLi Authentication Bypass
Employees Daily Task Management System 1.0 – ‘username’ SQLi Authentication Bypass
Tags: 0day, remote exploit[webapps] Chikitsa Patient Management System 2.0.2 – 'backup' Remote Code Execution (RCE) (Authenticated)
Chikitsa Patient Management System 2.0.2 – ‘backup’ Remote Code Execution (RCE) (Authenticated)
Tags: 0day, remote exploit[webapps] Chikitsa Patient Management System 2.0.2 – Remote Code Execution (RCE) (Authenticated)
Chikitsa Patient Management System 2.0.2 – Remote Code Execution (RCE) (Authenticated)
Tags: 0day, remote exploitSimple Online Men's Salon Management System 1.0 SQL Injection
Simple Online Men’s Salon Management System version 1.0 appears to suffer from a time-based remote SQL injection vulnerability.
HCL Lotus Notes 12 Unquoted Service Path
HCL Lotus Notes version 12 suffers from an unquoted service path vulnerability.
Microsoft Internet Explorer Active-X Control Security Bypass
Microsoft Internet Explorer suffers from an active-x related bypass vulnerability. Microsoft will not address the issue as it is end of life.
Croogo 3.0.2 Remote Code Execution
Croogo version 3.0.2 suffers from an authenticated remote code execution vulnerability.
Auerswald COMfortel 1400/2600/3600 IP 2.8F Authentication Bypass
RedTeam Pentesting discovered a vulnerability in the web-based configuration management interface of the Auerswald COMfortel 1400 and 2600 IP desktop phones. The vulnerability allows accessing configuration data and settings in the web-based management interface without authentication. Versions 2.8F and below are affected.