Joomla JCK Editor 6.4.4 – ‘parent’ SQL Injection (2)
Joomla JCK Editor 6.4.4 – ‘parent’ SQL Injection (2)
Hotel and Lodge Management System 1.0 – Remote Code Execution (Unauthenticated)
Configuration Tool 1.6.53 – ‘OpLclSrv’ Unquoted Service Path
Pingzapper 2.3.1 – ‘PingzapperSvc’ Unquoted Service Path
Print Job Accounting 4.4.10 – ‘OkiJaSvc’ Unquoted Service Path
http://iud.phitsanulok3.go.th/ina.htm notified by Xyp3r2667
http://tamkrataitong.go.th/ownd.htm notified by No_Identity
CatDV version 9.2 RMI authentication bypass exploit.
Fluig versions 1.7.0-210217 and below suffer from a path traversal vulnerability.
This Metasploit module exploits an overflow in the Windows Routing and Remote Access Service (RRAS) to execute code as SYSTEM. The RRAS DCERPC endpoint is accessible to unauthenticated users via…