TheSystem 1.0 – Command Injection
TheSystem 1.0 – Command Injection
vBulletin 5.x – Remote Command Execution (Metasploit)
https://www.sukhothai1.go.th/wS0.php notified by Ramil Feyziyev
http://www.banmaeka.go.th/007.html notified by 0x1998
citecodecrashers Pic-A-Point version 1.1 suffers from a remote SQL injection vulnerability.
inoERP version 4.15 suffers from a remote SQL injection vulnerability.
all-in-one-seo-pack version 3.2.7 suffers from a persistent cross site scripting vulnerability.
Duplicate-Post version 3.2.3 suffers from a persistent cross site scripting vulnerability.
Nmap NSE script that exploits a pre-authentication remote command execution vulnerability in vBulletin versions 5.x.
eBrigade versions prior to 5.0 suffer from multiple remote SQL injection vulnerabilities.