This Metasploit module exploits a vulnerability found in Fitnesse Wiki, version 20140201 and earlier.
42f6beeb835a921ce8418c6797220575
This Metasploit module exploits a vulnerability found in SePortal version 2.5. When logging in as any non-admin user, it's possible to retrieve the admin session from the database through SQL injection. The SQL injection vulnerability exists in the "staticpages.php" page. This hash can be used to take over the admin user session. After logging in, the "/admin/downloads.php" page will be used to upload arbitrary code.
63435169c72cc2d2e9cc30ef51896580
Debian Linux Security Advisory 2889-1 - An SQL injection vulnerability was discovered in postfixadmin, a web administration interface for the Postfix Mail Transport Agent, which allowed authenticated users to make arbitrary manipulations to the database.
5d2a5d97f29a80e7c8532454c554b4e6
Debian Linux Security Advisory 2888-1 - Toby Hsieh, Peter McLarnan, Ankit Gupta, Sudhir Rao and Kevin Reintjes discovered multiple cross-site scripting and denial of service vulnerabilities in Ruby Actionpack.
50af68b6056896c76834c7995af29ced
Symantec LiveUpdate Administrator versions 2.3.2.99 and below suffer from password reset and remote SQL injection vulnerabilities.
a8ff4d370b9610bdeaefb0bdd8fbb50d
LibYAML versions 0.1.5 and below are affected by a heap-based buffer overflow which can lead to arbitrary code execution. The vulnerability is caused by lack of proper expansion for the string passed to the yaml_parser_scan_uri_escapes() function. A specially crafted YAML file, with a long sequence of percent-encoded characters in a URL, can be used to trigger the overflow.
ac045385785224679f4d12e08802ffed
Ajax Pagination version 1.1 suffers from a local file inclusion vulnerability.
182a531b5368c59241ffb27a0e1278d4
HP Security Bulletin HPSBST02968 2 - A potential security vulnerability has been identified with certain HP StoreOnce appliances. This vulnerability could be exploited to allow remote unauthorized access to the appliance. Revision 2 of this advisory.
2bb75c03699ba7140c7c6bf16a9f5739
Debian Linux Security Advisory 2887-1 - Aaron Neyer discovered that missing input sanitizing in the logging component of Ruby Actionmailer could result in denial of service through a malformed e-mail message.
449b4050f0ef00095fe99ff6b7f4dfce
iStArtApp FileXChange version 6.2 for iOS suffers from command injection, local file inclusion, and remote shell upload vulnerabilities.
70dae1718a79ae642e94afe4649efc42
WordPress HTML Sitemap version 1.2 suffers from a cross site request forgery vulnerability.
15c5fb3e31f742f1d305ea74fe6d222a
GD Star Rating version 1.9.22 suffers from cross site request forgery, cross site scripting, and remote blind SQL injection vulnerabilities.
55f7f773448bb33d99953fffa9cdb37c
Canon PIXMA MX722 printer suffers from a WiFi password disclosure vulnerability.
8c091c0ab4ba66491ca381b75483768c
WordPress wp-business-intelligence plugin version 1.0.6 suffers from a remote shell upload vulnerability due to including ofc_upload_image.php.
08b10dacca3c19abadcf9a52eed81ece
ASP-Nuke version 2.0.7 suffers from an open redirect vulnerability.
320246de1354caff29a2016cda4dd56d