CSV (XLS) Injection (Excel Macro Injection or Formula Injection) exists in the AIM CrossChex version 4.3 when importing or exporting users using xls Excel file. This can be exploited to…
Jelastic 5.4 – ‘host’ SQL Injection
WinMTR 0.91 – Denial of Service (PoC)
qdPM 9.1 – ‘filter_by’ SQL Injection
Gate Pass Management System 2.1 – ‘login’ SQL Injection
Yot CMS 3.3.1 – ‘aid’ SQL Injection
Anviz AIM CrossChex Standard 4.3 – CSV Injection
Fantastic Blog CMS 1.0 – ‘id’ SQL Injection
http://watkoh-donation.lampangdopa.go.th/index.php notified by Ramil Feyziyev
http://www.mahasawat.go.th/customers/subject/subject-37.gif notified by Ramil Feyziyev