Subscribe via feed.
Archive for March, 2023

WordPress Watu Quiz 3.3.9 / GN Publisher 1.5.5 / Japanized For WooComerce 2.5.4 XSS

Posted by deepcore under exploit (No Respond)

WordPress plugins Watu Quiz versions 3.3.9 and below, GN Publisher versions 1.5.5 and below, and Japanized For WooCommerce versions 2.5.4 and below suffer from cross site scripting vulnerabilities.

Monitorr 1.7.6m / 1.7.7d Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits an arbitrary file upload vulnerability and achieves remote code execution in the Monitorr application. Using a specially crafted request, custom PHP code can be uploaded and injected through endpoint upload.php because of missing input validation. Any user privileges can exploit this vulnerability and it results in access to the underlying operating […]

Monitorr 1.7.6m / 1.7.7d Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits an arbitrary file upload vulnerability and achieves remote code execution in the Monitorr application. Using a specially crafted request, custom PHP code can be uploaded and injected through endpoint upload.php because of missing input validation. Any user privileges can exploit this vulnerability and it results in access to the underlying operating […]

http://www.tessabanthungyang.go.th/images/license.jpg

Posted by deepcore under defacement (No Respond)

http://www.tessabanthungyang.go.th/images/license.jpg notified by tegal9etar

Tags:

Python CGI Documentation Cross Site Scripting

Posted by deepcore under exploit (No Respond)

The documentation for the python CGI module suffers from a cross site scripting vulnerability.

MyBB Export User 2.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

MyBB Export User plugin version 2.0 suffers from a cross site scripting vulnerability.

Zyxel Unauthenticated LAN Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a buffer overflow in the zhttpd binary (/bin/zhttpd). It is present on more than 40 Zyxel routers and CPE devices. The code execution vulnerability can only be exploited by an attacker if the zhttp webserver is reachable. No authentication is required. After exploitation, an attacker will be able to execute any […]

Hackers Drain Bitcoin ATMs Of $1.5 Million By Exploiting 0-Day Bug

Posted by deepcore under exploit (No Respond)

Now Patched Outlook Zero Day Gains PoC And Growing Concerns

Posted by deepcore under exploit (No Respond)

https://www.hnonghaiud.go.th/kurd.html

Posted by deepcore under defacement (No Respond)

https://www.hnonghaiud.go.th/kurd.html notified by 0x1998

Tags: