ad

FCKEditor 2.6.8 ASP File Upload Protection Bypass

FCKEditor version 2.6.8 ASP version suffers from a file upload protection bypass.




ad

Kaseya uploadImage Arbitrary File Upload

This Metasploit module exploits an arbitrary file upload vulnerability found in Kaseya versions below 6.3.0.2. A malicious user can upload an ASP file to an arbitrary directory without previous authentication, leading to arbitrary code execution with IUSR privileges.




ad

Telerik ASP.NET AJAX RadEditor Control 2014.1.403.35 XSS

Telerik ASP.NET AJAX RadEditor Control versions 2014.1.403.35 and 2009.3.1208.20 suffer from a persistent cross site scripting vulnerability.




ad

Numara / BMC Track-It! FileStorageService Arbitrary File Upload

This Metasploit module exploits an arbitrary file upload vulnerability in Numara / BMC Track-It! v8 to v11.X. The application exposes the FileStorageService .NET remoting service on port 9010 (9004 for version 8) which accepts unauthenticated uploads. This can be abused by a malicious user to upload a ASP or ASPX file to the web root leading to arbitrary code execution as NETWORK SERVICE or SYSTEM. This Metasploit module has been tested successfully on versions 11.3.0.355, 10.0.51.135, 10.0.50.107, 10.0.0.143, 9.0.30.248 and 8.0.2.51.




ad

Kaseya VSA uploader.aspx Arbitrary File Upload

This Metasploit module exploits an arbitrary file upload vulnerability found in Kaseya VSA versions between 7 and 9.1. A malicious unauthenticated user can upload an ASP file to an arbitrary directory leading to arbitrary code execution with IUSR privileges. This Metasploit module has been tested with Kaseya v7.0.0.17, v8.0.0.10 and v9.0.0.3.




ad

ASP Dynamika 2.5 File Upload / SQL Injection

ASP Dynamika version 2.5 suffers from arbitrary file upload and remote SQL injection vulnerabilities.




ad

ASP.NET Core 5-RC1 HTTP Header Injection

ASP.NET Core version 5.-RC1 suffers from an HTTP header injection vulnerability.




ad

Hack In The Box Heading To Holland










ad

Sneaky Malware Disguises Itself As An Adobe Flash Installer






ad

Adobe Patches Critical Vulnerabilities In Flash, InDesign





ad

Adobe Fixes Over 100 Vulnerabilities In Latest Security Patch Update




ad

Adobe Fixes Critical Code Execution Flaws In Latest Patch Update









ad

Adobe Patches Important Bugs In Connect And Digital Edition






ad

Adobe Patch Update Squashes Critical Code Execution Bugs




ad

Adobe Fixes Critical Security Flaws In Flash, ColdFusion, Campaign






ad

Adobe Releases Patch For Critical Code Execution Vulnerability





ad

Telnet Backdoor Opens More Than 1M IoT Radios To Hijack








ad

IBM: Mind Reading Is Less Than Five Years Away. For Real.




ad

macOS/iOS ImageIO PVR Processing Out-Of-Bounds Read

macOS and iOS suffer from an ImageIO out-of-bounds read when processing PVR images.




ad

ProficySCADA For iOS 5.0.25920 Denial Of Service

ProficySCADA for iOS version 5.0.25920 suffers from a denial of service vulnerability.




ad

Secunia Security Advisory 29803

Secunia Security Advisory - A vulnerability has been reported in MirBSD Korn Shell, which can be exploited by malicious, local users to gain escalated privileges.




ad

School ERP Pro 1.0 Arbitrary File Read

School ERP Pro version 1.0 suffers from an arbitrary file read vulnerability.




ad

GitLab 12.9.0 Arbitrary File Read

GitLab version 12.9.0 suffers from an arbitrary file read vulnerability.




ad

MPC Sharj 3.11.1 Arbitrary File Download

MPC Sharj version 3.11.1 suffers from an arbitrary file download vulnerability.




ad

RSA Boss Packs His Fishing Rod And Heads For The Hills