Subscribe via feed.
Archive for March, 2022

WordPress Easy Cookie Policy 1.6.2 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

WordPress Easy Cookie Policy plugin version 1.6.2 suffers from persistent cross site scripting vulnerability due to a broken access control.

Joomla! 4.1.0 Zip Slip File Overwrite / Path Traversal

Posted by deepcore under exploit (No Respond)

Joomla! versions 4.1.0 and below suffer from path traversal and file overwrite vulnerabilities due to misplaced trust in the handling of compressed archives.

Chrome safe_browsing::ThreatDetails::OnReceivedThreatDOMDetails Use-After-Free

Posted by deepcore under exploit (No Respond)

Chrome suffers from a heap use-after-free vulnerability in safe_browsing::ThreatDetails::OnReceivedThreatDOMDetails. Versions affected include Google Chrome 96.0.4664.110 (Official Build) (64-bit) and Chromium 99.0.4807.0 (Developer Build) (64-bit).

[remote] Kramer VIAware 2.5.0719.1034 – Remote Code Execution (RCE)

Posted by deepcore under Security (No Respond)

Kramer VIAware 2.5.0719.1034 – Remote Code Execution (RCE)

Tags: ,

[remote] PostgreSQL 9.3-11.7 – Remote Code Execution (RCE) (Authenticated)

Posted by deepcore under Security (No Respond)

PostgreSQL 9.3-11.7 – Remote Code Execution (RCE) (Authenticated)

Tags: ,

[webapps] CSZ CMS 1.2.9 – 'Multiple' Blind SQLi(Authenticated)

Posted by deepcore under Security (No Respond)

CSZ CMS 1.2.9 – ‘Multiple’ Blind SQLi(Authenticated)

Tags: ,

[webapps] WordPress Plugin video-synchro-pdf 1.7.4 – Local File Inclusion

Posted by deepcore under Security (No Respond)

WordPress Plugin video-synchro-pdf 1.7.4 – Local File Inclusion

Tags: ,

[webapps] WordPress Plugin cab-fare-calculator 1.0.3 – Local File Inclusion

Posted by deepcore under Security (No Respond)

WordPress Plugin cab-fare-calculator 1.0.3 – Local File Inclusion

Tags: ,

[webapps] WordPress Plugin Curtain 1.0.2 – Cross-site Request Forgery (CSRF)

Posted by deepcore under Security (No Respond)

WordPress Plugin Curtain 1.0.2 – Cross-site Request Forgery (CSRF)

Tags: ,

[webapps] Atom CMS 2.0 – Remote Code Execution (RCE)

Posted by deepcore under Security (No Respond)

Atom CMS 2.0 – Remote Code Execution (RCE)

Tags: ,