Subscribe via feed.
Archive for September, 2022

Gitea 1.16.6 Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits the Git fetch command in Gitea repository migration process that leads to a remote command execution on the system. This vulnerability affects Gitea versions prior to 1.16.7.

News247 News Magazine 1.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

News247 News Magazine version 1.0 suffers from a persistent cross site scripting vulnerability.

WordPress WPGateway 3.5 Privilege Escalation

Posted by deepcore under exploit (No Respond)

WordPress WPGateway plugin versions 3.5 and below suffer from an unauthenticated privilege escalation vulnerability.

[webapps] Gitea 1.16.6 – Remote Code Execution (RCE) (Metasploit)

Posted by deepcore under Security (No Respond)

Gitea 1.16.6 – Remote Code Execution (RCE) (Metasploit)

Tags: ,

http://itservice.fpo.go.th/z.php

Posted by deepcore under defacement (No Respond)

http://itservice.fpo.go.th/z.php notified by ./Anon666Txploit

Tags:

http://www.rattanaburilocal.go.th/!.php

Posted by deepcore under defacement (No Respond)

http://www.rattanaburilocal.go.th/!.php notified by ./Anon666Txploit

Tags:

Rocket LMS 1.6 Shell Upload

Posted by deepcore under exploit (No Respond)

Rocket LMS version 1.6 suffers from a remote shell upload vulnerability.

Rocket LMS 1.6 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Rocket LMS version 1.6 suffers from a cross site scripting vulnerability.

Academy Learning Management System 5.7 Shell Upload

Posted by deepcore under exploit (No Respond)

Academy Learning Management System version 5.7 suffers from a remote shell upload vulnerability.

TIBCO JasperReports Server 8.0.2 Community Edition Code Execution

Posted by deepcore under exploit (No Respond)

Due to JMX/RMI services in TIBCO JasperReports Server version 8.0.2 Community Edition performing unsafe deserialization, it is possible to execute arbitrary code and system commands on the server system.