Tenda HG6 v3.3.0 – Remote Command Injection
>> TAG: #0day
Tenda HG6 v3.3.0 – Remote Command Injection
Wondershare Dr.Fone 11.4.10 – Insecure File Permissions
Anuko Time Tracker – SQLi (Authenticated)
UDisk Monitor Z5 Phone – ‘MonServiceUDisk.exe’ Unquoted Service Path
Apache CouchDB 3.2.1 – Remote Code Execution (RCE)
CSZ CMS 1.3.0 – ‘Multiple’ Blind SQLi
Wondershare Dr.Fone 12.0.7 – Privilege Escalation (InstallAssistService)
Bookeen Notea – Directory Traversal
Wondershare Dr.Fone 12.0.7 – Privilege Escalation (ElevationService)
WordPress Plugin Advanced Uploader 4.2 – Arbitrary File Upload (Authenticated)