Subscribe via feed.
Archive for March, 2022

[webapps] ImpressCMS 1.4.2 – Remote Code Execution (RCE)

Posted by deepcore under Security (No Respond)

ImpressCMS 1.4.2 – Remote Code Execution (RCE)

Tags: ,

Message System 1.0 Shell Upload

Posted by deepcore under exploit (No Respond)

Message System version 1.0 suffers from a remote shell upload vulnerability.

One Church Management System 1.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

One Church Management System version 1.0 suffers from multiple cross site scripting vulnerabilities.

Microfinance Management System 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Microfinance Management System version suffers from multiple remote SQL injection vulnerabilities including one that allows for authentication bypass. Original discovery of SQL injection in this version is attributed to Hejap Zairy in March of 2022.

One Church Management System 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

One Church Management System version 1.0 suffers from a remote SQL injection vulnerability.

FruityWifi Remote Code Execution

Posted by deepcore under exploit (No Respond)

This is an exploit for FruityWifi that binds a shell to tcp port 4444 using a remote code execution vulnerability leveraged via a SOAP request.

ALLMediaServer 1.6 Remote Buffer Overflow

Posted by deepcore under exploit (No Respond)

ALLMediaServer version 1.6 suffers from a remote buffer overflow vulnerability.

Backdoor.Win32.Cyn.20 Insecure Permissions

Posted by deepcore under exploit (No Respond)

Backdoor.Win32.Cyn.20 malware suffers from an insecure permissions vulnerability.

Pay Slip PDF Generator System 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Pay Slip PDF Generator System version suffers from multiple remote SQL injection vulnerabilities that can lead to remote code execution.

Pay Slip PDF Generator System 1.0 Shell Upload

Posted by deepcore under exploit (No Respond)

Pay Slip PDF Generator System version 1.0 suffers from a remote shell upload vulnerability.