Subscribe via feed.
Archive for February, 2023

Employee Task Management System 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Employee Task Management System version 1.0 suffers from multiple remote SQL injection vulnerabilities.

Arm Mali Insufficient Cache Invalidation

Posted by deepcore under exploit (No Respond)

Arm Mali suffers from an insufficient cache invalidation for non-page-aligned user buffer imports.

Music Gallery Site 1.0 Privilege Escalation / Missing Authentication

Posted by deepcore under exploit (No Respond)

Music Gallery Site version 1.0 suffers from a missing authentication vulnerability that allows for privilege escalation.

Music Gallery Site 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Music Gallery Site version 1.0 suffers from multiple remote SQL injection vulnerabilities.

Simple Food Ordering System 1.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Simple Food Ordering System version 1.0 suffers from a cross site scripting vulnerability.

Simple Food Ordering System 1.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Simple Food Ordering System version 1.0 suffers from a cross site scripting vulnerability.

https://phafaek.go.th/pwn.htm

Posted by deepcore under defacement (No Respond)

https://phafaek.go.th/pwn.htm notified by F4st~03

Tags:

Yoga Class Registration System 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Yoga Class Registration System version 1.0 suffers from multiple remote SQL injection vulnerabilities.

Froxlor 2.0.6 Remote Command Execution

Posted by deepcore under exploit (No Respond)

Froxlor versions 2.0.6 and below suffer from a bug that allows authenticated users to change the application logs path to any directory on the OS level which the user www-data can write without restrictions from the backend which leads to writing a malicious Twig template that the application will render. That leads to remote command […]

Device Manager Express 7.8.20002.47752 SQL Injection / XSS / Code Execution / Traversal

Posted by deepcore under exploit (No Respond)

Device Manager Express versions 7.8.20002.47752 and below suffer from code execution, command execution, cross site scripting, remote SQL injection, and traversal vulnerabilities.