This Metasploit module exploits an arbitrary file upload vulnerability in MaraCMS versions 7.5 and below in order to execute arbitrary commands. The module first attempts to authenticate to MaraCMS. It…
This Metasploit module exploit uses access to the UniversalOrchestrator ScheduleWork API call which does not verify the caller’s token before scheduling a job to be run as SYSTEM. You cannot…
MSI Ambient Link Driver version 1.0.0.8 suffers from a local privilege escalation vulnerability.
Joplin version 1.0.245 suffers from a cross site scripting vulnerability that can lead to allowing for remote code execution.
Mida eFramework version 2.8.9 suffers from a remote code execution vulnerability.
CloudMe 1.11.2 – Buffer Overflow ROP (DEP,ASLR)
BearShare Lite 5.2.5 – ‘Advanced Search’Buffer Overflow in (PoC)
WebsiteBaker 2.12.2 – Remote Code Execution
Joplin 1.0.245 – Arbitrary Code Execution (PoC)
MSI Ambient Link Driver 1.0.0.8 – Local Privilege Escalation