February 28, 2023Osprey Pump Controller 1.0.1 userName Command Injection

Osprey Pump Controller version 1.0.1 suffers from an unauthenticated OS command injection vulnerability. This can be exploited to inject and execute arbitrary shell commands through the userName HTTP POST parameter called by index.php script.

February 28, 2023Osprey Pump Controller 1.0.1 pseudonym Command Injection

Osprey Pump Controller version 1.0.1 suffers from an unauthenticated OS command injection vulnerability. This can be exploited to inject and execute arbitrary shell commands through the pseudonym HTTP POST parameter called by index.php script.

February 28, 2023WordPress Real Estate 7 Theme 3.3.4 Cross Site Request Forgery

WordPress Real Estate 7 Theme versions 3.3.4 and below suffer from multiple cross site request forgery vulnerabilities.

February 28, 2023Osprey Pump Controller 1.0.1 Administrator Backdoor Access

Osprey Pump Controller version 1.0.1 has a hidden administrative account admin that has the hardcoded password Mirage1234 that allows full access to the web management interface configuration. The user admin is not visible in Usernames and Passwords menu

February 28, 2023Osprey Pump Controller 1.0.1 Unauthenticated File Disclosure

Osprey Pump Controller version 1.0.1 suffers from an unauthenticated file disclosure vulnerability.

February 28, 2023WordPress Real Estate 7 Theme 3.3.4 Abuse Of Functionality

WordPress Real Estate 7 Theme versions 3.3.4 and below suffer from an abuse of functionality vulnerability.

February 28, 2023Osprey Pump Controller 1.0.1 Predictable Session Token / Session Hijacking

Osprey Pump Controller version 1.0.1 has an ELF binary called Mirage_CreateSessionCode.x that contains a weak session token generation algorithm that can be predicted and can aid in authentication and authorization bypass attacks. Further, session hijacki

February 28, 2023WordPress WoodMart Theme 7.1.0 Shortcodes Injection

The WoodMart premium theme for WordPress is vulnerable to unauthenticated arbitrary shortcodes injection in versions 7.1.0 and below. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

February 28, 2023ME-FI DOT 2.2 SQL Injection

ME-FI DOT version 2.2 suffers from a remote SQL injection vulnerability.

February 28, 2023ME-FI DOT 2.2 Default Credentials

ME-FI DOT version 2.2 leaves default administrative credentials installed post installation.

Archives
Categories
  • All Exploits 4105
  • Remote Code Execution
  • SQL Injection
  • Command Injection
  • Local File Inclusion
  • Cross Site Scripting
  • Privilege Escalation
  • Denial Of Service
  • Authentication Bypass
  • Buffer Overflow