Subscribe via feed.
Archive for March, 2023

BoxBilling 4.22.1.5 Remote Code Execution

Posted by deepcore under exploit (No Respond)

BoxBilling versions 4.22.1.55 and below suffer from a remote code execution vulnerability.

Subrion CMS 4.2.1 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Subrion CMS version 4.2.1 suffers from a persistent cross site scripting vulnerability.

X-Skipper-Proxy 0.13.237 Server-Side Request Forgery

Posted by deepcore under exploit (No Respond)

X-Skipper-Proxy version 0.13.237 suffers from a server-side request forgery vulnerability.

Label Studio 1.5.0 Server-Side Request Forgery

Posted by deepcore under exploit (No Respond)

Label Studio versions 1.5.0 and below suffer from a server-side request forgery vulnerability.

OPSWAT Metadefender Core 4.21.1 Privilege Escalation

Posted by deepcore under exploit (No Respond)

OPSWAT Metadefender Core version 4.21.1 suffers from a privilege escalation vulnerability.

Tunnel Interface Driver Denial Of Service

Posted by deepcore under exploit (No Respond)

Tunnel Interface Driver suffers from a denial of service vulnerability.

Moodle LMS 4.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Moodle LMS version 4.0 suffers from a cross site scripting vulnerability.

Hashicorp Consul 1.0 Remote Command Execution

Posted by deepcore under exploit (No Respond)

Hashicorp Consul version 1.0 suffers from a remote command execution vulnerability.

Optergy Proton And Enterprise BMS 2.0.3a Command Injection

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits an undocumented backdoor vulnerability in the Optergy Proton and Enterprise Building Management System (BMS) applications. Versions 2.0.3a and below are vulnerable. Attackers can exploit this issue by directly navigating to an undocumented backdoor script called Console.jsp in the tools directory and gain full system access. Successful exploitation results in root command […]

ReQlogic 11.3 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

ReQlogic version 11.3 suffers from a cross site scripting vulnerability.