Subscribe via feed.
Archive for December, 2021

[webapps] Arunna 1.0.0 – 'Multiple' Cross-Site Request Forgery (CSRF)

Posted by deepcore under Security (No Respond)

Arunna 1.0.0 – ‘Multiple’ Cross-Site Request Forgery (CSRF)

Tags: ,

[webapps] Croogo 3.0.2 – Unrestricted File Upload

Posted by deepcore under Security (No Respond)

Croogo 3.0.2 – Unrestricted File Upload

Tags: ,

[webapps] Croogo 3.0.2 – 'Multiple' Stored Cross-Site Scripting (XSS)

Posted by deepcore under Security (No Respond)

Croogo 3.0.2 – ‘Multiple’ Stored Cross-Site Scripting (XSS)

Tags: ,

[webapps] Cibele Thinfinity VirtualUI 2.5.41.0 – User Enumeration

Posted by deepcore under Security (No Respond)

Cibele Thinfinity VirtualUI 2.5.41.0 – User Enumeration

Tags: ,

Apache Log4j2 2.14.1 Information Disclosure

Posted by deepcore under exploit (No Respond)

Apache Log4j2 versions 2.14.1 and below information disclosure exploit.

Booked Scheduler 2.7.5 Shell Upload

Posted by deepcore under exploit (No Respond)

Booked Scheduler version 2.75 authenticated remote shell upload exploit.

AbanteCart Arbitrary File Upload / Cross Site Scripting

Posted by deepcore under exploit (No Respond)

AbanteCart e-commerce platform versions prior to 1.3.2 suffer from cross site scripting and file upload vulnerabilities.

Zucchetti Axess CLOKI Access Control 1.64 Cross Site Request Forgery

Posted by deepcore under exploit (No Respond)

Zucchetti Axess CLOKI Access Control version 1.64 suffers from a cross site request forgery vulnerability.

Ticket Booking 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Ticket Booking version 1.0 suffers from a remote SQL injection vulnerability.

Apache Log4j2 2.14.1 Remote Code Execution

Posted by deepcore under exploit (No Respond)

Apache Log4j2 versions 2.0-beta-9 and 2.14.1 remote code execution exploit.