Chamilo LMS 1.11.14 – Remote Code Execution (Authenticated)
>> TAG: #remote exploit
Chamilo LMS 1.11.14 – Remote Code Execution (Authenticated)
Podcast Generator 3.1 – ‘Long Description’ Persistent Cross-Site Scripting (XSS)
Student Management System 1.0 – ‘message’ Persistent Cross-Site Scripting (Authenticated)
Dental Clinic Appointment Reservation System 1.0 – ‘date’ UNION based SQL Injection (Authenticated)
Dental Clinic Appointment Reservation System 1.0 – Authentication Bypass (SQLi)
ZeroShell 3.9.0 – Remote Command Execution
Microsoft Internet Explorer 8/11 and WPAD service ‘Jscript.dll’ – Use-After-Free
Firefox 72 IonMonkey – JIT Type Confusion
Splinterware System Scheduler Professional 5.30 – Unquoted Service Path
Chevereto 3.17.1 – Cross Site Scripting (Stored)