This Metasploit module exploits an authentication bypass in the WordPress InfiniteWP Client plugin to log in as an administrator and execute arbitrary PHP code by overwriting the file specified by…
Vanilla Forum version 2.6.3 suffers from a persistent cross site scripting vulnerability.
OpenSMTPD 6.4.0 < 6.6.1 – Local Privilege Escalation + Remote Code Execution
Wedding Slideshow Studio 1.36 – ‘Name’ Buffer Overflow
Disk Savvy Enterprise 12.3.18 – Unquoted Service Path
WordPress InfiniteWP – Client Authentication Bypass (Metasploit)
Disk Sorter Enterprise 12.4.16 – ‘Disk Sorter Enterprise’ Unquoted Service Path
Sync Breeze Enterprise 12.4.18 – ‘Sync Breeze Enterprise’ Unquoted Service Path
DVD Photo Slideshow Professional 8.07 – ‘Name’ Buffer Overflow
FreeSSHd 1.3.1 – ‘FreeSSHDService’ Unquoted Service Path