po

Horde 5.2.22 CSV Import Code Execution

The Horde_Data module version 2.1.4 (and before) present in Horde Groupware version 5.2.22 allows authenticated users to inject arbitrary PHP code thus achieving remote code execution the server hosting the web application.




po

Russian Loses Wife In Poker Game




po

Another Online Poker Site Caught Cheating - UltimateBet




po

Net Sleuths Spot Poker Site Cheat Code




po

Hackers Busted In Online Poker Cheats






po

European Union Backs Biometric Passports




po

US Names The Day For Biometric Passports




po

DHS Completes Live Test Of E-Passports




po

U.S. Deploys First e-Passport Readers





po

British E-Passports Arrive, With Questions




po

Home Office Issued 10,000 Fake UK Passports Last Year




po

Crypto Boffins Urge Belgium To Withdraw Early ePassports





po

Germany Rolls Out ePassport II - It's Fingerprinting Good!





po

Rice Apologizes To Obama For Passport Hack




po

Awed Fraudsters Defeated By UK's Passport Interviews




po

UK Electronic Passports Cloned Within Minutes




po

THC/vonJeek Provide You The Ability To Clone ePassports




po

Passport Snoop Snared




po

State Department Passport Snoop Faces Little Or No Jail Time




po

Passport RFIDs Cloned Wholesale By $250 eBay Auction Spree




po

Hacker War Drives San Francisco Cloning RFID Passports




po

South Africa Rolls Out Biometric Passports




po

Interpol Issues Arrest Warrant For Fake Passport Hit Team




po

Hackers Expose Security Flaws With Elvis Presley Passport




po

CyberArk PSMP 10.9.1 Policy Restriction Bypass

CyberArk PSMP versions 10.9.1 and below suffer from a policy restriction bypass vulnerability.




po

Liferay Portal Java Unmarshalling Remote Code Execution

This Metasploit module exploits a Java unmarshalling vulnerability via JSONWS in Liferay Portal versions prior to 6.2.5 GA6, 7.0.6 GA7, 7.1.3 GA4, and 7.2.1 GA2 to execute code as the Liferay user. Tested against 7.2.0 GA1.




po

Nexus Repository Manager 3.21.1-01 Remote Code Execution

This Metasploit module exploits a Java Expression Language (EL) injection in Nexus Repository Manager versions up to and including 3.21.1 to execute code as the Nexus user. Tested against 3.21.1-01.







po

POS PHP 17.5 Cross Site Scripting

POS PHP version 17.5 suffers from a persistent cross site scripting vulnerability.




po

WordPress WooCommerce Advanced Order Export 3.1.3 Cross Site Scripting

WordPress WooCommerce Advanced Order Export plugin version 3.1.3 suffers from a cross site scripting vulnerability.








po

Hackers Pop Brazil Newspapers To Root Home Routers






po

Brazilian Firm Exposes Personal Details Of Thousands Of Soccer Fans




po

POC OR GTFO 0x16

This is the sixteenth issue of POC || GTFO.




po

POC OR GTFO 0x17

This is the seventeenth issue of POC || GTFO.




po

Linux/x86 Bind TCP Port 43690 Null-Free Shellcode

53 bytes small Linux/x86 bind TCP port 43690 null-free shellcode.