Part-DB 0.4 – Authentication Bypass
>> TAG: #0day
Part-DB 0.4 – Authentication Bypass
waldronmatt FullCalendar-BS4-PHP-MySQL-JSON 1.21 – ‘start’ SQL Injection
waldronmatt FullCalendar-BS4-PHP-MySQL-JSON 1.21 – ‘description’ Cross-Site Scripting
JumpStart 0.6.0.0 – ‘jswpbapi’ Unquoted Service Path
delpino73 Blue-Smiley-Organizer 1.32 – ‘datetime’ SQL Injection
ChaosPro 2.0 – Buffer Overflow (SEH)
WebKit – Universal XSS in HTMLFrameElementBase::isURLAllowed
ClonOs WEB UI 19.09 – Improper Access Control
Linux Polkit – pkexec helper PTRACE_TRACEME local root (Metasploit)
WordPress Sliced Invoices 3.8.2 – ‘post’ SQL Injection