This Metasploit module exploits an incorrect side-effect modeling of the ‘in’ operator. The DFG compiler assumes that the ‘in’ operator is side-effect free, however the embed element with the PDF…
>> AUTHOR: deepcore
MedDream PACS Server 6.8.3.751 – Remote Code Execution (Authenticated)
Photo Share Website 1.0 – Persistent Cross-Site Scripting
It appears that the corona virus Exposure Notifications API for iOS and Android may have a data leakage issue.
BearShare Lite version 5.2.5 buffer overflow proof of concept exploit.
Qiata FTA versions 1.70.19 and below suffer from a cross site scripting vulnerability.
WebsiteBaker version 2.12.2 suffers from a remote code execution vulnerability.
DOMOS versions 5.8 and below suffer from a command injection vulnerability.
MailDepot version 2032 SP2 (2.2.1242) suffers from a session expiration design issue.
The installer component of Cisco AnyConnect Secure Mobility Client for Windows prior to 4.8.02042 is vulnerable to path traversal and allows local attackers to create/overwrite files in arbitrary locations with…