NewsP Free News Script 1.4.7 – User Credentials Disclosure
>> TAG: #0day
NewsP Free News Script 1.4.7 – User Credentials Disclosure
Exploiting Apache James Server 2.3.2
Linux/x86-64 – Syscall Persistent Bind Shell + (Multi-terminal) + Password + Daemon (83, 148, 177 bytes)
OpenSSHD <= 7.2p2 – User Enumeration
vBulletin 4.x – SQLi in breadcrumbs via xmlrpc API (Post-Auth)
DropBearSSHD <= 2015.71 – Command Injection
Internet Explorer 11 (on Windows 10) – VBScript Memory Corruption Proof-of-Concept Exploit (MS16-051)
vBulletin 5.x/4.x – Persistent XSS in AdminCP/ApiLog via xmlrpc API (Post-Auth)
Clear Voyager Hotspot IMW-C910W – Arbitrary File Disclosure
Joomla Guru Pro (com_guru) Component – SQL Injection