This Metasploit module exploits a remote code execution vulnerability in Apache Struts versions 2.3 through 2.3.4, and 2.5 through 2.5.16. Remote code execution can be performed via an endpoint that…
This is a small tutorial write up that provides a DynoRoot exploit proof of concept.
Apache Roller version 5.0.3 suffers from an XML external entity injection vulnerability that allows for file disclosure.
Jorani Leave Management System version 0.6.5 suffers from a cross site scripting vulnerability.
Jorani Leave Management System version 0.6.5 suffers from a remote SQL injection vulnerability.
WirelessHART Fieldgate SWG70 version 3.0 suffers from a directory traversal vulnerability.
D-Link Dir-600M N150 suffers from a cross site scripting vulnerability.
KONE KGC versions 4.6.4 and below suffer from unauthenticated remote code execution, denial of service, local file inclusion, and missing FTP access control vulnerabilities.
Cisco Umbrella Roaming Client version 2.0.168 suffers from a privilege escalation vulnerability.
IDOR on ProConf Peer-Review and Conference Management versions 6.0 and below suffer from an insecure direct object reference vulnerability that allows for file disclosure.