Symantec DLP versions 15.5 MP1 and below suffer from a cross site scripting vulnerability.
Hawtio versions 2.5.0 and below suffer from a server side request forgery vulnerability.
BKS EBK Ethernet-Buskoppler Pro versions prior to 3.01 suffer from a remote shell upload vulnerability.
Centreon version 19.04 suffers from an authenticated remote code execution vulnerability.
This Metasploit module attempts to gain root privileges on systems running Serv-U FTP Server versions prior to 15.1.7. The Serv-U executable is setuid root, and uses ARGV[0] in a call…
This Metasploit module exploits a vulnerability in Apache Tomcat’s CGIServlet component. When the enableCmdLineArguments setting is set to true, a remote user can abuse this to execute system commands, and…
Serv-U FTP Server – prepareinstallation Privilege Escalation (Metasploit)
Symantec DLP 15.5 MP1 – Cross-Site Scripting
This Metasploit module exploits a vulnerability within the “ghelp”, “help” and “man” URI handlers within Linux Mint’s “ubuntu-system-adjustments” package. Invoking any one the URI handlers will call the python script…
FaceSentry Access Control System version 6.4.8 suffers from an authenticated OS command injection vulnerability using default credentials. This can be exploited to inject and execute arbitrary shell commands as the…