This Metasploit module exploits a remote command execution vulnerability in Nostromo versions 1.9.6 and below. This issue is caused by a directory traversal in the function http_verify in nostromo nhttpd…
Nostromo – Directory Traversal Remote Command Execution (Metasploit)
ownCloud 10.3.0 stable – Cross-Site Request Forgery
OpenVPN Private Tunnel 2.8.4 – ‘ovpnagent’ Unquoted Service Path
TheJshen contentManagementSystem 1.04 – ‘id’ SQL Injection
Apache Solr 8.2.0 – Remote Code Execution
This Metasploit module exploits a command injection vulnerability in Ajenti versions 2.1.31 and below. By injecting a command into the username POST parameter to api/core/auth, a shell can be spawned.
WMV to AVI MPEG DVD WMV Converter version 4.6.1217 suffers from a denial of service vulnerability.
Citrix StoreFront Server version 7.15 suffers from an XML external entity injection vulnerability.
JavaScriptCore (JSC) GetterSetter suffers from a type confusion vulnerability during DFG compilation.