Subscribe via feed.
Archive for February, 2023

PHPJabbers Business Directory Script 3.2 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

PHPJabbers Business Directory Script version 3.2 suffers from a cross site scripting vulnerability.

Control Web Panel Unauthenticated Remote Command Execution

Posted by deepcore under exploit (No Respond)

Control Web Panel versions prior to 0.9.8.1147 are vulnerable to unauthenticated OS command injection. Successful exploitation results in code execution as the root user. The results of the command are not contained within the HTTP response and the request will block while the command is running.