June 13, 2023TerraMaster TOS 4.2.29 Remote Code Execution

This Metasploit module exploits an unauthenticated remote code execution vulnerability in TerraMaster TOS versions 4.2.29 and below by chaining two existing vulnerabilities, CVE-2022-24990 "Leaking sensitive information" and CVE-2022-24989, "Authenticated

June 13, 2023ProLogin 1.9 Insecure Direct Object Reference

ProLogin version 1.9 suffers from an insecure direct object reference vulnerability.

June 13, 2023Piyanas 0.1 Cross Site Request Forgery

Piyanas version 0.1 suffers from a cross site request forgery vulnerability.

June 13, 2023phpAnalyzer 2.0.4 Insecure Settings

phpAnalyzer version 2.0.4 appears to leave default credentials installed after installation.

June 13, 2023EasyAnswer 1.0.1 Cross Site Request Forgery

EasyAnswer version 1.0.1 suffers from a cross site request forgery vulnerability.

June 13, 2023Online Thesis Archiving System 1.0 SQL Injection

Online Thesis Archiving System version 1.0 suffers from a remote SQL injection vulnerability.

June 13, 2023Xoops CMS 2.5.10 Cross Site Scripting

Xoops CMS version 2.5.10 suffers from a persistent cross site scripting vulnerability.

June 12, 2023Anevia Flamingo XL 3.2.9 Remote Root Jailbreak

Anevia Flamingo XL version 3.2.9 suffers from an SSH sandbox escape via the use of traceroute. A remote attacker can breakout of the restricted environment and have full root access to the device.

June 12, 2023Anevia Flamingo XL 3.6.20 Authenticated Root Remote Code Execution

Anevia Flamingo XL version 3.6.20 suffers from an authenticated remote code execution vulnerability. A remote attacker can exploit this issue and execute arbitrary system commands granting her system access with root privileges.

June 12, 2023Anevia Flamingo XS 3.6.5 Authenticated Root Remote Code Execution

Anevia Flamingo XS version 3.6.5 suffers from an authenticated remote code execution vulnerability. A remote attacker can exploit this issue and execute arbitrary system commands granting her system access with root privileges.

Archives
Categories
  • All Exploits 4131
  • Remote Code Execution
  • SQL Injection
  • Command Injection
  • Local File Inclusion
  • Cross Site Scripting
  • Privilege Escalation
  • Denial Of Service
  • Authentication Bypass
  • Buffer Overflow