1CRM versions 8.6.7 and below suffer from an insecure direct object reference vulnerability.
This Metasploit module exploits a command injection vulnerability in Mida Solutions eFramework version 2.9.0 and prior. The ajaxreq.php file allows unauthenticated users to inject arbitrary commands in the PARAM parameter…
Microsoft SQL Server Reporting Services 2016 – Remote Code Execution
http://chaleang.go.th/cl.html notified by Clash Hackers
Tailor MS version 1.0 suffers from a cross site scripting vulnerability.
ThinkAdmin version 6 suffers from an arbitrary file read vulnerability.
Piwigo 2.10.1 – Cross Site Scripting
Windows TCPIP Finger Command – C2 Channel and Bypassing Security Software
Microsoft Windows TCPIP Finger Command finger.exe that ships with the OS, can be used as a file downloader and makeshift C2 channel. Legitimate use of Windows Finger Command is to…
A race condition exists with munmap() downgrades in Linux kernel versions since 4.20.