bloofoxCMS 0.5.2.1 – CSRF (Add user)
>> TAG: #remote exploit
bloofoxCMS 0.5.2.1 – CSRF (Add user)
BloofoxCMS 0.5.2.1 – ‘text’ Stored Cross Site Scripting
Online Grading System 1.0 – ‘uname’ SQL Injection
Quick.CMS 6.7 – Remote Code Execution (Authenticated)
EgavilanMedia PHPCRUD 1.0 – ‘Full Name’ Stored Cross Site Scripting
CMSUno 1.6.2 – ‘lang/user’ Remote Code Execution (Authenticated)
jQuery UI 1.12.1 – Denial of Service (DoS)
STVS ProVision 5.9.10 – File Disclosure (Authenticated)
STVS ProVision 5.9.10 – Cross-Site Request Forgery (Add Admin)
Openlitespeed Web Server 1.7.8 – Command Injection (Authenticated)