November 25, 2022Helmet Store Showroom 1.0 SQL Injection

Helmet Store Showroom version 1.0 suffers from an authenticated remote SQL injection vulnerability.

November 25, 2022Sanitization Management System 1.0 SQL Injection

Sanitization Management System version 1.0 suffers from a remote SQL injection vulnerability.

November 24, 2022F5 BIG-IP iControl Remote Command Execution

This Metasploit module exploits a newline injection into an RPM .rpmspec file that permits authenticated users to remotely execute commands. Successful exploitation results in remote code execution as the root user.

November 24, 2022Ecommerce 1.0 Cross Site Scripting / Open Redirect

Ecommerce version 1.0 suffers from cross site scripting and open redirection vulnerabilities.

November 23, 2022Backdoor.Win32.Serman.a MVID-2022-0659 Unauthenticated Open Proxy

Backdoor.Win32.Serman.a malware suffers from an unauthenticated open proxy vulnerability.

November 21, 2022ChurchInfo 1.2.13-1.3.0 Remote Code Execution

This Metasploit module exploits the logic in the CartView.php page when crafting a draft email with an attachment. By uploading an attachment for a draft email, the attachment will be placed in the /tmp_attach/ folder of the ChurchInfo web server, which i

November 21, 2022F5 BIG-IP iControl Cross Site Request Forgery

This Metasploit module exploits a cross-site request forgery (CSRF) vulnerability in F5 Big-IP's iControl interface to write an arbitrary file to the filesystem. While any file can be written to any location as root, the exploitability is limited by SELin

November 21, 2022Roxy Fileman 1.4.6 Remote Shell Upload

Roxy Fileman versions 1.4.6 and below remote shell upload proof of concept exploit.

November 21, 2022Boa Web Server 0.94.13 / 0.94.14 Authentication Bypass

Boa Web Server versions 0.94.13 through 0.94.14 fail to validate the correct security constraint on the HEAD HTTP method allowing everyone to bypass the Basic Authorization mechanism.

November 21, 2022ZTE ZXHN-H108NS Authentication Bypass

ZTE ZXHN-H108NS router with firmware version H108NSV1.0.7u_ZRD_GR2_A68 suffers from an authentication bypass vulnerability when alternate HTTP methods are leveraged.

Archives
Categories
  • All Exploits 4105
  • Remote Code Execution
  • SQL Injection
  • Command Injection
  • Local File Inclusion
  • Cross Site Scripting
  • Privilege Escalation
  • Denial Of Service
  • Authentication Bypass
  • Buffer Overflow