D-Link DIR-868L version 1.12 suffers from a cross site request forgery vulnerability.
Apple Security Advisory 2018-05-08-1 – This advisory provides additional information for APPLE-SA-2018-04-24-2 Security Update 2018-001.
Web Forensics
FxCop 10/12 – XML External Entity Injection
Linux/x86 – Bind TCP Shell + fork() Shellcode (113 bytes)
HWiNFO version 5.82-3410 suffers from a denial of service vulnerability.
This Metasploit module exploits a code injection vulnerability within an authenticated file upload feature in PlaySMS version 1.4. This issue is caused by improper file name handling in sendfromfile.php file….
This Metasploit module exploits an authenticated file upload remote code execution vulnerability in PlaySMS version 1.4. This issue is caused by improper file contents handling in import.php (aka the Phonebook…
The WordPress User Role Editor plugin prior to v4.25, is lacking an authorization check within its update user profile functionality (“update” function, contained within the “class-user-other-roles.php” module). Instead of verifying…
DeviceLock Plug and Play Auditor version 5.72 suffers from a unicode buffer overflow vulnerability.