Subscribe via feed.
Posts under exploit

Packet Storm New Exploits For January, 2023

Posted by deepcore under exploit (No Respond)

This archive contains all of the 130 exploits added to Packet Storm in January, 2023.

mRemoteNG 1.76.20 Privilege Escalation

Posted by deepcore under exploit (No Respond)

mRemoteNG version 1.76.20 suffers from a weak permission privilege escalation vulnerability.

PHPJabbers Business Directory Script 3.2 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

PHPJabbers Business Directory Script version 3.2 suffers from a cross site scripting vulnerability.

PHPJabbers Auto Classifieds Script 3.2 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

PHPJabbers Auto Classifieds Script version 3.2 suffers from a cross site scripting vulnerability.

Control Web Panel Unauthenticated Remote Command Execution

Posted by deepcore under exploit (No Respond)

Control Web Panel versions prior to 0.9.8.1147 are vulnerable to unauthenticated OS command injection. Successful exploitation results in code execution as the root user. The results of the command are not contained within the HTTP response and the request will block while the command is running.

PHPJabbers Property Listing Script 3.1 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

PHPJabbers Property Listing Script version 3.1 suffers from a cross site scripting vulnerability.

PHPJabbers Property Listing Script 3.1 SQL Injection

Posted by deepcore under exploit (1 Respond)

PHPJabbers Property Listing Script version 3.1 suffers from a remote SQL injection vulnerability.

PHPJabbers Travel Tours Script 1.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

PHPJabbers Travel Tours Script version 1.0 suffers from a cross site scripting vulnerability.

PHPJabbers Travel Tours Script 1.0 SQL Injection

Posted by deepcore under exploit (1 Respond)

PHPJabbers Travel Tours Script version 1.0 suffers from a remote SQL injection vulnerability.

PHPJabbers Event Ticketing System Script 1.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

PHPJabbers Event Ticketing System Script version 1.0 suffers from a cross site scripting vulnerability.