Subscribe via feed.

[webapps] WordPress Plugin TablePress 1.14 – CSV Injection

Posted by deepcore under Security (No Respond)

WordPress Plugin TablePress 1.14 – CSV Injection

Tags: ,

[webapps] WordPress Plugin WP Sitemap Page 1.6.4 – Stored Cross-Site Scripting (XSS)

Posted by deepcore under Security (No Respond)

WordPress Plugin WP Sitemap Page 1.6.4 – Stored Cross-Site Scripting (XSS)

Tags: ,

[local] Argus Surveillance DVR 4.0 – Unquoted Service Path

Posted by deepcore under Security (No Respond)

Argus Surveillance DVR 4.0 – Unquoted Service Path

Tags: ,

[webapps] OpenEMR 6.0.0 – 'noteid' Insecure Direct Object Reference (IDOR)

Posted by deepcore under Security (No Respond)

OpenEMR 6.0.0 – ‘noteid’ Insecure Direct Object Reference (IDOR)

Tags: ,

[webapps] FlatCore CMS 2.0.7 – Remote Code Execution (RCE) (Authenticated)

Posted by deepcore under Security (No Respond)

FlatCore CMS 2.0.7 – Remote Code Execution (RCE) (Authenticated)

Tags: ,

[webapps] Bus Pass Management System 1.0 – 'viewid' Insecure direct object references (IDOR)

Posted by deepcore under Security (No Respond)

Bus Pass Management System 1.0 – ‘viewid’ Insecure direct object references (IDOR)

Tags: ,

[webapps] Patient Appointment Scheduler System 1.0 – Unauthenticated File Upload & Remote Code Execution (RCE)

Posted by deepcore under Security (No Respond)

Patient Appointment Scheduler System 1.0 – Unauthenticated File Upload & Remote Code Execution (RCE)

Tags: ,

[webapps] Patient Appointment Scheduler System 1.0 – Persistent/Stored XSS

Posted by deepcore under Security (No Respond)

Patient Appointment Scheduler System 1.0 – Persistent/Stored XSS

Tags: ,

[dos] SmartFTP Client 10.0.2909.0 – 'Multiple' Denial of Service

Posted by deepcore under Security (No Respond)

SmartFTP Client 10.0.2909.0 – ‘Multiple’ Denial of Service

Tags: ,

[webapps] Antminer Monitor 0.5.0 – Authentication Bypass

Posted by deepcore under Security (No Respond)

Antminer Monitor 0.5.0 – Authentication Bypass

Tags: ,