AUO SunVeillance Monitoring System 1.1.9e – Incorrect Access Control
AUO SunVeillance Monitoring System 1.1.9e – Incorrect Access Control
WordPress Sliced Invoices 3.8.2 – ‘post’ SQL Injection
Linux Polkit – pkexec helper PTRACE_TRACEME local root (Metasploit)
This Metasploit module attempts to gain root privileges with SUID Xorg X11 server versions 1.19.0 up to 1.20.3. A permission check flaw exists for -modulepath and -logfile options when starting…
Joomla! 3.4.6 – Remote Code Execution (Metasploit)
IObit Uninstaller 9.1.0.8 – ‘IObitUnSvr’ Unquoted Service Path
Rocket.Chat 2.1.0 – Cross-Site Scripting
https://ic.nbtc.go.th/xampp/lang.tmp notified by SeRaVo BlackHaT
This Metasploit module exploits a vulnerability in Total.js CMS. The issue is that a user with admin permission can embed a malicious JavaScript payload in a widget, which is evaluated…
Total.js CMS 12 – Widget JavaScript Code Injection (Metasploit)