This Metasploit module exploits a command injection vulnerability in Quest KACE Systems Management Appliance version 8.0.318 (and possibly prior). The download_agent_installer.php file allows unauthenticated users to execute arbitrary commands as…
The vulnerability laboratory core research team discovered mutliple cross site scripting vulnerabilities in the offici…
The vulnerability laboratory core research team discovered an application-side vulnerability in the official GhostMail c…
WordPress < 4.9.6 – (Authenticated) Arbitrary File Deletion
HPE VAN SDN 2.7.18.0503 – Remote Root
Quest KACE Systems Management – Command Injection (Metasploit)
UAC Bypass & Research with UAC-A-Mola
When KVM (on Intel) virtualizes another hypervisor as L1 VM it does not verify that VMX instructions from the L1 VM (which trigger a VM exit and are emulated by…
AsusWRT RT-AC750GF suffers from a cross site request forgery vulnerability in the change admin password flow.
Intex Router N-150 suffers from a remote arbitrary file upload vulnerability.