Prestashop 1.7.7.0 SQL Injection
Authored by Jaimin Gondaliya
Prestashop version 1.7.7.0 suffers from a remote blind SQL injection vulnerability.
Change Mirror Download
# Exploit Title: Prestashop 1.7.7.0 - 'id_product' Time Based Blind SQL Injection# Date: 08-01-2021#...
OX App Suite / OX Documents 7.10.x XSS / SSRF
Authored by Martin Heiland, notoriousrip, Stuart Redman
OX App Suite and OX Documents suffer from server-side request forgery and multiple cross site scripting vulnerabilities. Various versions are affected including 7.10.4...
Curfew e-Pass Management System 1.0 Cross Site Scripting
Authored by Arnav Tripathy
Curfew e-Pass Management System version 1.0 suffers from a cross site scripting vulnerability.
Change Mirror Download
# Exploit Title: Curfew e-Pass Management System 1.0 - Stored XSS #...
ECSIMAGING PACS 6.21.5 SQL Injection
Authored by shoxxdj
ECSIMAGING PACS version 6.21.5 suffers from a remote SQL injection vulnerability.
Change Mirror Download
# Exploit Title: ECSIMAGING PACS 6.21.5 - SQL injection# Date: 06/01/2021# Exploit Author: shoxxdj# Vendor...
dnsrecon 0.10.0 CSV Injection
Authored by Dolev Farhi
dnsrecon version 0.10.0 suffers from a CSV injection vulnerability.
Change Mirror Download
# Exploit Title: dnsrecon 0.10.0 - CSV Injection# Author: Dolev Farhi# Date: 2021-01-07# Vendor Homepage: https://github.com/darkoperator/dnsrecon/#...
Online Doctor Appointment System 1.0 Cross Site Scripting
Authored by Mohamed Habib Smidi
Online Doctor Appointment System version 1.0 suffers from multiple persistent cross site scripting vulnerabilities.
Change Mirror Download
# Exploit Title: Online Doctor Appointment System 1.0 -...
Backdoor.Win32.Agent.dcbh Insecure Permissions / Privilege Escalation
Authored by malvuln | Site malvuln.com
Backdoor.Win32.Agent.dcbh malware suffers from an insecure permissions vulnerability that can allow for privilege escalation.
Change Mirror Download
Discovery / credits: malvuln - Malvuln.com (c) 2021Original source:...
Cockpit 234 Server-Side Request Forgery
Authored by Metin Yunus Kandemir
Cockpit version 234 suffers from an unauthenticated server-side request forgery vulnerability.
Change Mirror Download
# Exploit Title: Cockpit Version 234 - Server-Side Request Forgery (Unauthenticated)# Date: 08.01.2021#...
Backdoor.Win32.Xtreme.yvp Insecure Permissions / Privilege Escalation
Authored by malvuln | Site malvuln.com
Backdoor.Win32.Xtreme.yvp malware suffers from an insecure permissions vulnerability that can allow for privilege escalation.
Change Mirror Download
Discovery / credits: malvuln - Malvuln.com (c) 2021Original source:...
Backdoor.Win32.NinjaSpy.c Remote Stack Buffer Overflow
Authored by malvuln | Site malvuln.com
Backdoor.Win32.NinjaSpy.c suffers from a remote stack buffer overflow vulnerability. The specimen drops a DLL named "cmd.dll" under C:WINDOWS which listens on both TCP ports...





