Subscribe via feed.
Posts under exploit

Online Food Ordering System 2.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Online Food Ordering System version 2.0 suffers from a cross site scripting vulnerability.

Linux khugepaged Race Conditions

Posted by deepcore under exploit (No Respond)

khugepaged on Linux races with rmap-based zap, races with GUP-fast, and fails to call MMU notifiers.

WordPress Royal Elementor 1.3.59 XSS / CSRF / Insufficient Access Controls

Posted by deepcore under exploit (No Respond)

WordPress Royal Elementor add-ons versions 1.3.59 and below suffer from cross site request forgery, insufficient access control, cross site scripting vulnerabilities.

ADMINA BULGARIA Ltd 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

ADMINA BULGARIA Ltd version 1.0 suffers from a remote SQL injection vulnerability.

AdminSeg 2.15 Insecure Direct Object Reference

Posted by deepcore under exploit (No Respond)

AdminSeg version 2.15 suffers from an insecure direct object reference that allows users to access the administrative interface.

BDWeb-Link LMS 1.11.5 Insecure Direct Object Reference

Posted by deepcore under exploit (No Respond)

BDWeb-Link LMS version 1.11.5 suffers from an insecure direct object reference that allows users to access the administrative interface.

Corpatech CMS 2 SQL Injection

Posted by deepcore under exploit (No Respond)

Corpatech CMS version 2 suffers from a remote SQL injection vulnerability.

Dcastalia CMS 1.2 Insecure Direct Object Reference

Posted by deepcore under exploit (No Respond)

Dcastalia CMS version 1.2 suffers from an insecure direct object reference that allows users to access the administrative interface.

Deprixa Pro CMS 3.2.5 Insecure Settings

Posted by deepcore under exploit (No Respond)

Deprixa Pro CMS version 3.2.5 appears to leave a default administrative account in place post installation.

WordPress Slider Revolution 4.6.5 Shell Upload

Posted by deepcore under exploit (No Respond)

WordPress Slider Revolution plugin version 4.6.5 suffers from a remote shell upload vulnerability.