Subscribe via feed.
Archive for January, 2023

Tiki Wiki CMS Groupware 24.0 structlib.php Code Execution

Posted by deepcore under exploit (No Respond)

Tiki Wiki CMS Groupware versions 24.0 and below suffer from a PHP code injection vulnerability in structlib.php.

Tiki Wiki CMS Groupware 24.0 grid.php PHP Object Injection

Posted by deepcore under exploit (No Respond)

Tiki Wiki CMS Groupware versions 24.0 and below suffers from a PHP object injection vulnerability in grid.php.

Tiki Wiki CMS Groupware 24.1 tikiimporter_blog_wordpress.php PHP Object Injection

Posted by deepcore under exploit (No Respond)

Tiki Wiki CMS Groupware versions 24.1 and below suffer from a PHP object injection vulnerability in tikiimporter_blog_wordpress.php.

Control Web Panel 7 Remote Code Execution

Posted by deepcore under exploit (No Respond)

Control Web Panel 7 versions prior to 0.9.8.1147 suffer from an unauthenticated remote code execution vulnerability.

Excel Net Computer Institute 4.1 SQL Injection

Posted by deepcore under exploit (No Respond)

Excel Net Computer Institute version 4.1 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

Eatself 1.1.5 SQL Injection

Posted by deepcore under exploit (No Respond)

Eatself version 1.1.5 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

Linux videobuf2 Use-After-Free

Posted by deepcore under exploit (No Respond)

A vb2_mmap race with vb2_core_reqbufs leads to a use-after-free vulnerability in the Linux videobuf2 system.

Rackspace Blames Ransomware Woes On Zero-Day Attack

Posted by deepcore under exploit (No Respond)

Linear eMerge E3-Series Access Controller Command Injection

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a command injection vulnerability in the Linear eMerge E3-Series Access Controller. The Linear eMerge E3 versions 1.00-06 and below are vulnerable to unauthenticated command injection in card_scan_decoder.php via the No and door HTTP GET parameter. Successful exploitation results in command execution as the root user.

Oracle Database Vault Metadata Exposure

Posted by deepcore under exploit (No Respond)

Oracle Database versions 12.1.0.2, 12.2.0.1, 18c, and 19c suffer from a vault metadata exposure vulnerability.