February 24, 2023Auto Dealer Management System 1.0 Privilege Escalation

Auto Dealer Management System version 1.0 suffers from a privilege escalation vulnerability due to a broken access control where a lower privileged user's cookie can be leveraged to takeover an administrative account.

February 24, 2023Kshitish 2.0 Default Credentials

Kshitish Multipurpose eCommerce Platform version 2.0 leaves default administrative credentials installed post installation.

February 23, 2023Device Manager Express 7.8.20002.47752 SQL Injection / XSS / Code Execution / Traversal

Device Manager Express versions 7.8.20002.47752 and below suffer from code execution, command execution, cross site scripting, remote SQL injection, and traversal vulnerabilities.

February 23, 2023Froxlor 2.0.6 Remote Command Execution

Froxlor versions 2.0.6 and below suffer from a bug that allows authenticated users to change the application logs path to any directory on the OS level which the user www-data can write without restrictions from the backend which leads to writing a malici

February 23, 2023Yoga Class Registration System 1.0 SQL Injection

Yoga Class Registration System version 1.0 suffers from multiple remote SQL injection vulnerabilities.

February 22, 2023pyLoad js2py Python Execution

pyLoad versions prior to 0.5.0b3.dev31 are vulnerable to Python code injection due to the pyimport functionality exposed through the js2py library. An unauthenticated attacker can issue a crafted POST request to the flash/addcrypted2 endpoint to leverage

February 21, 2023Sales Tracker System 1.0 SQL Injection

Sales Tracker System version 1.0 suffers from an authenticated remote SQL injection vulnerability.

February 17, 2023Kardex Mlog MCC 5.7.12+0-a203c2a213-master File Inclusion / Remote Code Execution

Kardex Mlog MCC version 5.7.12+0-a203c2a213-master suffers from a file inclusion vulnerability that allows for remote code execution.

February 17, 2023Best POS Management System 1.0 Shell Upload

Best POS Management System version 1.0 suffers from a remote shell upload vulnerability.

February 17, 2023Best POS Management System 1.0 SQL Injection

Best POS Management System version 1.0 suffers from multiple remote SQL injection vulnerabilities.

Archives
Categories
  • All Exploits 4105
  • Remote Code Execution
  • SQL Injection
  • Command Injection
  • Local File Inclusion
  • Cross Site Scripting
  • Privilege Escalation
  • Denial Of Service
  • Authentication Bypass
  • Buffer Overflow