Subscribe via feed.
Archive for May, 2022

http://www.wangsaphung.go.th/readme.html

Posted by deepcore under defacement (No Respond)

http://www.wangsaphung.go.th/readme.html notified by AnonSec Team

Tags:

Toll Tax Management System 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Toll Tax Management System version 1.0 suffers from a remote SQL injection vulnerability.

Covid 19 Travel Pass Management System 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Covid 19 Travel Pass Management System version 1.0 suffers from a remote SQL injection vulnerability.

Ransom.LockBit DLL Hijacking

Posted by deepcore under exploit (No Respond)

Ransom.LockBit malware suffers from a dll hijacking vulnerability.

Strapi 3.6.8 Password Disclosure / Insecure Handling

Posted by deepcore under exploit (No Respond)

Strap versions prior to 3.6.9 and 4.1.5 disclose a user’s password due to simply base64 encoding it and sticking it in a cookie.

WordPress Stafflist 3.1.2 SQL Injection

Posted by deepcore under exploit (No Respond)

WordPress Stafflist plugin version 3.1.2 suffers from a remote SQL injection vulnerability.

WordPress Stafflist 3.1.2 Cross Site Request Forgery

Posted by deepcore under exploit (No Respond)

WordPress Stafflist plugin version 3.1.2 suffers from a cross site request forgery vulnerability.

WSO Arbitrary File Upload / Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module abuses a vulnerability in certain WSO2 products that allow unrestricted file upload with resultant remote code execution. This affects WSO2 API Manager 2.2.0 and above through 4.0.0; WSO2 Identity Server 5.2.0 and above through 5.11.0; WSO2 Identity Server Analytics 5.4.0, 5.4.1, 5.5.0, and 5.6.0; WSO2 Identity Server as Key Manager 5.3.0 and […]

Packet Storm New Exploits For April, 2022

Posted by deepcore under exploit (No Respond)

This archive contains all of the 150 exploits added to Packet Storm in April, 2022.

Packet Storm New Exploits For April, 2022

Posted by deepcore under exploit (No Respond)

This archive contains all of the 150 exploits added to Packet Storm in April, 2022.