WordPress Plugin W3 Total Cache – Unauthenticated Arbitrary File Read (Metasploit)
>> TAG: #remote exploit
WordPress Plugin W3 Total Cache – Unauthenticated Arbitrary File Read (Metasploit)
Pandora FMS 7.0 NG 750 – ‘Network Scan’ SQL Injection (Authenticated)
WordPress Plugin Contact Form 7 5.3.1 – Unrestricted File Upload
Queue Management System 4.0.0 – “Add User” Stored XSS
Spotweb 1.4.9 – ‘search’ SQL Injection
Academy-LMS 4.3 – Stored XSS
Spiceworks 7.5 – HTTP Header Injection
Flexmonster Pivot Table & Charts 2.7.17 – ‘To OLAP’ Reflected XSS
Flexmonster Pivot Table & Charts 2.7.17 – ‘Remote Report’ Reflected XSS
Flexmonster Pivot Table & Charts 2.7.17 – ‘To remote CSV’ Reflected XSS