VestaCP 0.9.8 – ‘v_sftp_licence’ Command Injection
VestaCP 0.9.8 – ‘v_sftp_licence’ Command Injection
BRAdmin Professional 3.75 – ‘BRA_Scheduler’ Unquoted Service Path
Profiling System for Human Resource Management 1.0 – Remote Code Execution (Unauthenticated)
WoWonder Social Network Platform version 3.1 suffers from a remote SQL injection vulnerability.
Trojan-Dropper.Win32.Delf.p malware suffers from a missing authentication vulnerability.
Trojan-Dropper.Win32.Delf.p malware suffers from a buffer overflow vulnerability.
CuteNews version 2.1.2 Avatar upload remote shell upload exploit. Original discovery of remote shell upload in this version is attributed to Ozkan Mustafa Akkus in April of 2019.
VestaCP version 0.9.8 suffers from a cross site request forgery that can be leveraged to add remote ssh access.
Backdoor.Win32.Agent.mzn malware suffers from a buffer overflow vulnerability.
Hestia Control Panel 1.3.2 – Arbitrary File Write