May 5, 2023Oracle RMAN Missing Auditing

Proof of concept exploit for Oracle RMAN on Oracle database versions 19c, 18c, 12.2.0.1, and 12.1.0.2 where recovery actions are not adequately logged.

May 5, 2023Online Pizza Ordering System 1.0 Shell Upload

Online Pizza Ordering System version 1.0 suffers from an unauthenticated remote shell upload vulnerability.

May 5, 2023Codigo Markdown Editor 1.0.1 Code Execution

Codigo Markdown Editor version 1.0.1 suffers from an arbitrary code execution vulnerability.

May 5, 2023UliCMS 2023-1 Sniffing-Vicuna Shell Upload

UliCMS version 2023-1 Sniffing-Vicuna suffers from a remote shell upload vulnerability.

May 5, 2023UliCMS 2023-1 Sniffing-Vicuna Cross Site Scripting

UliCMS version 2023-1 Sniffing-Vicuna suffers from a persistent cross site scripting vulnerability.

May 5, 2023File Thingie 2.5.7 Shell Upload

File Thingie version 2.5.7 remote shell upload exploit. This exploit is based on the vulnerability priorly discovered by Cakes in September of 2019.

May 5, 2023Wolf CMS 0.8.3.1 Shell Upload

Wolf CMS version 0.8.3.1 suffers from a remote shell upload vulnerability.

May 5, 2023Pluck CMS 4.7.18 Cross Site Scripting

Pluck CMS version 4.7.18 suffers from a persistent cross site scripting vulnerability.

May 5, 2023EasyPHP Webserver 14.1 Path Traversal / Remote Code Execution

EasyPHP Webserver version 14.1 suffers from remote code execution and path traversal vulnerabilities.

May 5, 2023Jedox 2022.4.2 Database Credential Disclosure

Jedox version 2022.4.2 has an information disclosure vulnerability in /be/rpc.php that allows remote authenticated users with the appropriate permissions to modify database connections to disclose the clear text credentials via the test connection functio

Archives
Categories
  • All Exploits 4122
  • Remote Code Execution
  • SQL Injection
  • Command Injection
  • Local File Inclusion
  • Cross Site Scripting
  • Privilege Escalation
  • Denial Of Service
  • Authentication Bypass
  • Buffer Overflow