Subscribe via feed.
Posts under exploit

Sales Tracker Management System 1.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Sales Tracker Management System version 1.0 suffers from a cross site scripting vulnerability.

Online Graduate Tracer System 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Online Graduate Tracer System version 1.0 suffers from a remote SQL injection vulnerability.

Joomla! 4.2.7 Unauthenticated Information Disclosure

Posted by deepcore under exploit (No Respond)

Joomla! versions prior to 4.2.8 suffer from an unauthenticated information disclosure vulnerability.

RSA NetWitness Endpoint EDR Agent 12.x Incorrect Access Control / Code Execution

Posted by deepcore under exploit (No Respond)

RSA NetWitness Endpoint EDR Agent version 12.x suffers from incorrect access controls that allow for code execution. It allows local users to stop the Endpoint Windows agent from sending the events to a SIEM or make the agent run user-supplied commands.

RSA NetWitness Endpoint EDR Agent 12.x Incorrect Access Control / Code Execution

Posted by deepcore under exploit (No Respond)

RSA NetWitness Endpoint EDR Agent version 12.x suffers from incorrect access controls that allow for code execution. It allows local users to stop the Endpoint Windows agent from sending the events to a SIEM or make the agent run user-supplied commands.

WordPress Watu Quiz 3.3.9 / GN Publisher 1.5.5 / Japanized For WooComerce 2.5.4 XSS

Posted by deepcore under exploit (No Respond)

WordPress plugins Watu Quiz versions 3.3.9 and below, GN Publisher versions 1.5.5 and below, and Japanized For WooCommerce versions 2.5.4 and below suffer from cross site scripting vulnerabilities.

Monitorr 1.7.6m / 1.7.7d Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits an arbitrary file upload vulnerability and achieves remote code execution in the Monitorr application. Using a specially crafted request, custom PHP code can be uploaded and injected through endpoint upload.php because of missing input validation. Any user privileges can exploit this vulnerability and it results in access to the underlying operating […]

Monitorr 1.7.6m / 1.7.7d Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits an arbitrary file upload vulnerability and achieves remote code execution in the Monitorr application. Using a specially crafted request, custom PHP code can be uploaded and injected through endpoint upload.php because of missing input validation. Any user privileges can exploit this vulnerability and it results in access to the underlying operating […]

Python CGI Documentation Cross Site Scripting

Posted by deepcore under exploit (No Respond)

The documentation for the python CGI module suffers from a cross site scripting vulnerability.

MyBB Export User 2.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

MyBB Export User plugin version 2.0 suffers from a cross site scripting vulnerability.