February 1, 2024GlobalScape Secure FTP Server 3.0 Denial Of Service

GlobalScape Secure FTP Server version 3.0 remote denial of service exploit.

January 26, 2024Vinchin Backup And Recovery 7.2 SystemHandler.class.php Command Injection

Vinchin Backup and Recovery versions 7.2 and below suffer from a command injection vulnerability in SystemHandler.class.php.

January 26, 2024Vinchin Backup And Recovery 7.2 Default Root Credentials

Vinchin Backup and Recovery version 7.2 has been identified as being configured with default root credentials, posing a significant security vulnerability.

January 26, 2024Vinchin Backup And Recovery 7.2 Default MySQL Credentials

A critical security issue has been discovered in Vinchin Backup and Recovery version 7.2. The software has been found to use default MYSQL credentials, which could lead to significant security risks.

January 26, 2024Vinchin Backup And Recovery 7.2 syncNtpTime Command Injection

Vinchin Backup and Recovery versions 7.2 and below suffer from a command injection vulnerability in the syncNtpTime function.

January 26, 2024CloudLinux CageFS 7.0.8-2 Insufficiently Restricted Proxy Command

CloudLinux CageFS versions 7.0.8-2 and below insufficiently restrict file paths supplied to the sendmail proxy command. This allows local users to read and write arbitrary files of certain file formats outside the CageFS environment.

January 26, 2024CloudLinux CageFS 7.1.1-1 Token Disclosure

CloudLinux CageFS versions 7.1.1-1 and below pass the authentication token as a command line argument. In some configurations this allows local users to view the authentication token via the process list and gain code execution as another user.

January 26, 2024Atlassian Confluence SSTI Injection

This Metasploit module exploits an SSTI injection in Atlassian Confluence servers. A specially crafted HTTP request uses the injection to evaluate an OGNL expression resulting in OS command execution. Versions 8.5.0 through 8.5.3 and 8.0 to 8.4 are known

January 26, 2024Vinchin Backup And Recovery 7.2 setNetworkCardInfo Command Injection

Vinchin Backup and Recovery versions 7.2 and below suffer from a command injection vulnerability in the setNetworkCardInfo function.

January 26, 2024YahooPOPs 1.6 Denial Of Service

YahooPOPs version 1.6 remote denial of service exploit.

Archives
Categories
  • All Exploits 4095
  • Remote Code Execution
  • SQL Injection
  • Command Injection
  • Local File Inclusion
  • Cross Site Scripting
  • Privilege Escalation
  • Denial Of Service
  • Authentication Bypass
  • Buffer Overflow