Subscribe via feed.
Archive for March, 2023

Real Estate CRM Pro 5.7 SQL Injection

Posted by deepcore under exploit (No Respond)

Real Estate CRM Pro from IT Ways version 5.7 appears to suffer from a remote SQL injection vulnerability that can allow for authentication bypass.

Lucee Authenticated Scheduled Job Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module can be used to execute a payload on Lucee servers that have an exposed administrative web interface. It’s possible for an administrator to create a scheduled job that queries a remote ColdFusion file, which is then downloaded and executed when accessed. The payload is uploaded as a cfm file when queried by […]

Lucee Authenticated Scheduled Job Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module can be used to execute a payload on Lucee servers that have an exposed administrative web interface. It’s possible for an administrator to create a scheduled job that queries a remote ColdFusion file, which is then downloaded and executed when accessed. The payload is uploaded as a cfm file when queried by […]

Packet Storm New Exploits For February, 2023

Posted by deepcore under exploit (No Respond)

This archive contains all of the 82 exploits added to Packet Storm in February, 2023.

Oracle E-Business Suite (EBS) Unauthenticated Arbitrary File Upload

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits an unauthenticated arbitrary file upload vulnerability in Oracle Web Applications Desktop Integrator, as shipped with Oracle EBS versions 12.2.3 through to 12.2.11, in order to gain remote code execution as the oracle user.

Oracle E-Business Suite (EBS) Unauthenticated Arbitrary File Upload

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits an unauthenticated arbitrary file upload vulnerability in Oracle Web Applications Desktop Integrator, as shipped with Oracle EBS versions 12.2.3 through to 12.2.11, in order to gain remote code execution as the oracle user.

ChurchCRM 4.5.3 SQL Injection

Posted by deepcore under exploit (No Respond)

ChurchCRM version 4.5.3 suffers from a remote SQL injection vulnerability.

ME-FI DOT 2.2 Default Credentials

Posted by deepcore under exploit (No Respond)

ME-FI DOT version 2.2 leaves default administrative credentials installed post installation.

ME-FI DOT 2.2 SQL Injection

Posted by deepcore under exploit (No Respond)

ME-FI DOT version 2.2 suffers from a remote SQL injection vulnerability.

WordPress WoodMart Theme 7.1.0 Shortcodes Injection

Posted by deepcore under exploit (No Respond)

The WoodMart premium theme for WordPress is vulnerable to unauthenticated arbitrary shortcodes injection in versions 7.1.0 and below. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.