This Metasploit module exploits an ACL bypass in MobileIron MDM products to execute a Groovy gadget against a Hessian-based Java deserialization endpoint.
Backdoor.Win32.DarkKomet.bhfh malware suffers from an insecure permissions vulnerability.
Oracle WebLogic Server 12.2.1.0 – RCE (Unauthenticated)
Tenda AC5 AC1200 Wireless – ‘WiFi Name & Password’ Stored Cross Site Scripting
Simple College Website 1.0 – ‘full’ Stored Cross Site Scripting
Simple College Website 1.0 – ‘name’ Sql Injection (Authentication Bypass)
Cemetry Mapping and Information System 1.0 – ‘user_email’ Sql Injection (Authentication Bypass)
Library System 1.0 – ‘category’ SQL Injection
CASAP Automated Enrollment System 1.0 – ‘route’ Stored XSS