Bravo Tejari Web Portal Cross Site Scripting
Bravo Tejari Web Portal suffers from a cross site request forgery vulnerability.MD5 | 7ecca80a8288e258acba28bb0e281483DownloadExploit Title: Bravo Tejari Web Portal-CSRFCVE-ID:...
View ArticleXion 1.0.125 Buffer Overflow
Xion version 1.0.125 .m3u file local SEH-based unicode buffer overflow exploit.MD5 | 14739b703be3b3ebe7e0e6a065133dc2Download#!/usr/bin/perl#...
View ArticleMemcached memcrashed Denial Of Service
This is a proof of concept exploit for the memcached denial of service vulnerability.MD5 | 2b76cf893e1e529dcdcc9dfd0e852de4Download# Written by Alex Conrey## This program is free software: you can...
View ArticleDup Scout Enterprise 10.5.12 Share Username Buffer Overflow
Dup Scout Enterprise version 10.5.12 suffers from a share username local buffer overflow vulnerability.MD5 | c1f9273e8568edb503dbf1133637a46cDownload#!/usr/bin/python## Exploit Author: bzyo# Twitter:...
View ArticleRapid Scada 5.5.0 Insecure Permissions
Rapid Scada version 5.5.0 suffers from an insecure permission vulnerability.MD5 | c81b2a59f24e59822c91601bace1421dDownload=====[ Tempest Security Intelligence - ADV-21/2018 ]===Rapid Scada - 5.5.0 -...
View ArticleMagento User Info Cross Site Scripting
Magento suffers from user information related cross site scripting vulnerabilities. Versions affected include Magento 2.0 prior to 2.0.18, Magento 2.1 prior to 2.1.12, and Magento 2.2 prior to...
View ArticleMagento Backups Cross Site Request Forgery
Magento Backups suffer from a cross site request forgery vulnerability. Versions affected include Magento Open Source prior to 1.9.3.8, Magento Commerce prior to 1.14.3.8, Magento 2.0 prior to 2.0.18,...
View ArticleMagento Downloadable Products Cross Site Scripting
Magento suffers from downloadable product information related cross site scripting vulnerabilities. Versions affected include Magento 2.0 prior to 2.0.18, Magento 2.1 prior to 2.1.12, and Magento 2.2...
View ArticleMagento Product Attributes Cross Site Scripting
Magento suffers from product attribute information related cross site scripting vulnerabilities. Versions affected include Magento 2.0 prior to 2.0.18, Magento 2.1 prior to 2.1.12, and Magento 2.2...
View ArticleChrome V8 JIT - Empty BytecodeJumpTable Out-of-Bounds Read
EDB-ID: 44260Author: Google Security ResearchPublished: 2018-03-06CVE: N/A Type: DosPlatform: MultipleAliases: N/AAdvisory/Source: LinkTags: Out Of BoundsVulnerable App: N/A In the current...
View ArticleChrome V8 JIT - 'GetSpecializationContext' Type Confusion
EDB-ID: 44259Author: Google Security ResearchPublished: 2018-03-06CVE: N/A Type: DosPlatform: MultipleAliases: N/AAdvisory/Source: LinkTags: Type ConfusionVulnerable App: N/A function* opt(arg = ()...
View ArticleChrome V8 JIT - Simplified-lowererer IrOpcode::kStoreField,...
EDB-ID: 44257Author: Google Security ResearchPublished: 2018-03-06CVE: N/A Type: DosPlatform: MultipleAliases: N/AAdvisory/Source: LinkTags: N/AVulnerable App: N/A I think this commit has introduced...
View ArticleBravo Tejari Web Portal - Cross-Site Request Forgery
EDB-ID: 44256Author: Arvind VPublished: 2018-03-06CVE: CVE-2018-7216 Type: WebappsPlatform: MultipleVulnerable App: N/A CVE-ID: CVE-2018-7216 Vulnerability Type: Cross Site Request Forgery (CSRF)...
View ArticleChrome V8 JIT - JSBuiltinReducer::ReduceObjectCreate Fails to Ensure that...
EDB-ID: 44258Author: Google Security ResearchPublished: 2018-03-06CVE: N/A Type: DosPlatform: MultipleAliases: N/AAdvisory/Source: LinkTags: N/AVulnerable App: N/A I think this commit has introduced...
View ArticleGraphicsMagick CVE-2017-18219 Denial of Service Vulnerability
GraphicsMagick is prone to a remote denial-of-service vulnerability. Attackers can exploit this issue to cause denial-of-service conditions. Versions prior to GraphicsMagick 1.3.26 are vulnerable....
View ArticleGraphicsMagick CVE-2017-18220 Multiple Denial of Service Vulnerabilities
GraphicsMagick is prone to multiple denial-of-service vulnerabilities. Attackers can exploit these issues to cause denial-of-service conditions. GraphicsMagick 1.3.26 is vulnerable; other versions may...
View ArticleRedaxo CMS Addon MyEvents 2.2.1 - SQL Injection
EDB-ID: 44261Author: h0n1gsp3chtPublished: 2018-03-07CVE: N/A Type: WebappsPlatform: PHPAliases: N/AAdvisory/Source: N/ATags: SQL Injection (SQLi)Vulnerable App: # Date: 01.03.2018 # Exploit Author:...
View ArticleantMan 0.9.0c - Authentication Bypass
EDB-ID: 44262Author: Joshua BowserPublished: 2018-03-07CVE: CVE-2018-7739 Type: WebappsPlatform: JavaVulnerable App: N/A # Date: 02-27-2018 # Software Link: https://www.antsle.com # Version: <=...
View ArticleRedaxo CMS Addon MyEvents 2.2.1 SQL Injection
Redaxo CMS Addon MyEvents version 2.2.1 suffers from a remote SQL injection vulnerability.MD5 | 23cf272ee641aa9e438c4bfa7a336c4aDownload# Exploit Title: Redaxo CMS Addon MyEvents SQL Injection [...
View ArticleantMan 0.9.0c Authentication Bypass
antMan version 0.9.0c suffers from an authentication bypass vulnerability.MD5 | 5635112c9320095f5537738416c30290Download# Exploit Title: antMan <= 0.9.0c Authentication Bypass# Date: 02-27-2018#...
View Article