The CAPTCHA function for iDS6 DSSPro Digital Signage System version 6.2 is prone to a security bypass vulnerability that occurs in the CAPTCHA authentication routine. By requesting the autoLoginVerifyCode object…
iDS6 DSSPro Digital Signage System version 6.2 suffers from a privilege escalation vulnerability. An authenticated user can elevate his/her privileges by calling JS functions from the console or by insecure…
BlogEngine 3.3.8 – ‘Content’ Stored XSS
Sentrifugo Version 3.2 – ‘announcements’ Remote Code Execution (Authenticated)
Sentrifugo 3.2 – ‘assets’ Remote Code Execution (Authenticated)
SmartBlog 2.0.1 – ‘id_post’ Blind SQL injection
CMSUno 1.6.2 – ‘lang’ Remote Code Execution (Authenticated)
Processwire CMS version 2.4.0 suffers from a local file inclusion vulnerability.
PDW File Browser version 1.3 suffers from a remote shell upload vulnerability.
School Log Management System version 1.0 suffers from a remote SQL injection vulnerability that could lead to code execution.