Rausoft ID.prove 2.95 – ‘Username’ SQL injection
>> TAG: #remote exploit
Rausoft ID.prove 2.95 – ‘Username’ SQL injection
ManageEngine Desktop Central 10.0.271 – Cross-Site Scripting
TransMac 12.2 – Denial of Service (PoC)
CrossFont 7.5 – Denial of Service (PoC)
Linux/ARM – Bind (0.0.0.0:4444/TCP) Shell (/bin/sh) + Null-Free Shellcode (92 Bytes)
Linux – VMA Use-After-Free via Buggy vmacache_flush_all() Fastpath
Joomla Component eXtroForms 2.1.5 – ‘filter_type_id’ SQL Injection
WebKit – ‘WebCore::RenderLayer::updateDescendantDependentFlags’ Use-After-Free
Joomla! Component Raffle Factory 3.5.2 – SQL Injection
WebKit – ‘WebCore::SVGTRefElement::updateReferencedText’ Use-After-Free