SiteMagic CMS 4.4.2 – Arbitrary File Upload (Authenticated)
>> AUTHOR: deepcore
SiteMagic CMS 4.4.2 – Arbitrary File Upload (Authenticated)
BarracudaDrive v6.5 – Insecure Folder Permissions
This archive contains all of the 128 exploits added to Packet Storm in August, 2020.
As of 2020/09/01, all versions of Bagisto appear to leak database and email server credentials in the document root.
Rebar3 versions 3.0.0-beta.3 through 3.13.2 suffer from a command injection vulnerability.
Sagemcom F@ST 5280 routers using firmware version 1.150.61, and possibly others, have an insecure deserialization vulnerability that allows any authenticated user to perform a privilege escalation to any other user….
Mara CMS version 7.5 suffers from a remote code execution vulnerability.
Kamailio version 5.4.0 is vulnerable to header smuggling via a bypass of remove_hf.
moziloCMS version 2.0 suffers from a persistent cross site scripting vulnerability.
Stock Management System 1.0 – Cross-Site Request Forgery (Change Username)