Online Shopping Alphaware version 1.0 suffers from an unauthorized administrative functionality access vulnerability.
Victor CMS version 1.0 suffers from a search remote SQL injection vulnerability. Original discovery of SQL injection in this version is attributed to BKpatron.
This Metasploit module escapes from a privileged Docker container and obtains root on the host machine by abusing the Linux cgroup notification on release feature. This exploit should work against…
Daily Expenses Management System 1.0 – ‘item’ SQL Injection
All-Dynamics Digital Signage System 2.0.2 – Cross-Site Request Forgery (Add Admin)
http://mueang.trang.doae.go.th notified by Zeerx7
Victor CMS 1.0 – ‘Search’ SQL Injection
Car Rental Management System version 1.0 suffers from a persistent cross site scripting vulnerability.
Car Rental Management System version 1.0 unauthenticated remote code execution exploit.
Pi-hole version 4.3.2 authenticated remote code execution exploit.