August 4, 2023Intelliants Subrion CMS 4.2.1 Remote Code Execution

This Metasploit module exploits an authenticated file upload vulnerability in Subrion CMS versions 4.2.1 and lower. The vulnerability is caused by the .htaccess file not preventing the execution of .pht, .phar, and .xhtml files. Files with these extension

August 4, 2023Citrix ADC (NetScaler) Remote Code Execution

A vulnerability exists within Citrix ADC that allows an unauthenticated attacker to trigger a stack buffer overflow of the nsppe process by making a specially crafted HTTP GET request. Successful exploitation results in remote code execution as root.

August 4, 2023WordPress Adivaha Travel 2.3 Cross Site Scripting

WordPress Adivaha Travel plugin version 2.3 suffers from a cross site scripting vulnerability.

August 4, 2023Xlight FTP Server 3.9.3.6 Stack Buffer Overflow

Xlight FTP Server version 3.9.3.6 suffers from a stack buffer overflow vulnerability.

August 4, 2023WordPress EventON Calendar 4.4 Insecure Direct Object Reference

WordPress EventON Calendar plugin version 4.4 suffers from an insecure direct object reference vulnerability.

August 4, 2023WordPress Ninja Forms 3.6.25 Cross Site Scripting

WordPress Ninja Forms plugin version 3.6.25 suffers from a cross site scripting vulnerability.

August 4, 2023COURIER DEPRIXA 2.5 Cross Site Request Forgery

COURIER DEPRIXA version 2.5 suffers from a cross site request forgery vulnerability.

August 4, 2023Webedition CMS 2.9.8.8 Cross Site Scripting

Webedition CMS version 2.9.8.8 suffers from a persistent cross site scripting vulnerability.

August 4, 2023Webedition CMS 2.9.8.8 Remote Code Execution

Webedition CMS version 2.9.8.8 suffers from a remote code execution vulnerability.

August 4, 2023Webutler 3.2 Shell Upload

Webutler version 3.2 suffers from a remote shell upload vulnerability.

Archives
Categories
  • All Exploits 4105
  • Remote Code Execution
  • SQL Injection
  • Command Injection
  • Local File Inclusion
  • Cross Site Scripting
  • Privilege Escalation
  • Denial Of Service
  • Authentication Bypass
  • Buffer Overflow