Axis Communications MPQT/PACS 5.20.x – Server Side Include (SSI) Daemon Remote Format String Exploit
>> CATEGORY: Security
newsp.eu PHP Calendar Script 1.0 – User Credentials Disclosure
NewsP Free News Script 1.4.7 – User Credentials Disclosure
Exploiting Apache James Server 2.3.2
Linux/x86-64 – Syscall Persistent Bind Shell + (Multi-terminal) + Password + Daemon (83, 148, 177 bytes)
OpenSSHD <= 7.2p2 – User Enumeration
vBulletin 4.x – SQLi in breadcrumbs via xmlrpc API (Post-Auth)
DropBearSSHD <= 2015.71 – Command Injection
Internet Explorer 11 (on Windows 10) – VBScript Memory Corruption Proof-of-Concept Exploit (MS16-051)
vBulletin 5.x/4.x – Persistent XSS in AdminCP/ApiLog via xmlrpc API (Post-Auth)