Polkit 0.105-26 0.117-2 Privilege Escalation
Authored by J Smith
Polkit version Polkit 0.105-26 0.117-2 suffers from a local privilege escalation vulnerability.
advisories | CVE-2021-3560
Change Mirror Download
# Exploit Title: Polkit 0.105-26 0.117-2 - Local Privilege Escalation# Date:...
XML External Entity Via MP3 File Upload On WordPress
Authored by Vallari Sharma, Archie Midha
This document illustrates proof of concept exploitation of a vulnerability in WordPress versions 5.6.0 through 5.7.0 that gives a user the ability to upload...
Brother BRPrint Auditor 3.0.7 Unquoted Service Path
Authored by Brian Rodriguez
Brother BRPrint Auditor version 3.0.7 suffers from an unquoted service path vulnerability.
Change Mirror Download
# Exploit Title: Brother BRPrint Auditor 3.0.7 - 'Multiple' Unquoted Service Path# Discovery...
HashiCorp Nomad Remote Command Execution
Authored by Wyatt Dahlenburg | Site metasploit.com
This Metasploit module lets you create a batch job on HashiCorp's Nomad service to spawn a shell. The default option is to use...
IPFire 2.25 Remote Code Execution
Authored by Grant Willcox, Mucahit Saratar | Site metasploit.com
This Metasploit module exploits an authenticated command injection vulnerability in the /cgi-bin/pakfire.cgi web page of IPFire devices running versions 2.25 Core...
Client Management System 1.1 SQL Injection
Authored by BHAVESH KAUL
Client Management System version 1.1 suffers from a remote SQL injection vulnerability.
Change Mirror Download
# Exploit Title: Client Management System 1.1 - 'Search' SQL Injection# Date: 14...
SAP Netweaver JAVA 7.50 Missing Authorization
Authored by Ignacio D. Favro | Site onapsis.com
A malicious unauthenticated user could abuse the lack of authentication check on SAP Java P2P cluster communication in order to connect to...
Backdoor.Win32.Pazus.18 Authentication Bypass / Code Execution
Authored by malvuln | Site malvuln.com
Backdoor.Win32.Pazus.18 malware suffers from bypass and code execution vulnerabilities.
Change Mirror Download
Discovery / credits: Malvuln - malvuln.com (c) 2021Original source: https://malvuln.com/advisory/5be13eb16018ab69157f8c8e96e7d6bf.txtContact: [email protected]: twitter.com/malvulnThreat: Backdoor.Win32.Pazus.18Vulnerability: Authentication...
Accela Civic Platform 21.1 Cross Site Scripting / Open Redirection
Authored by Abdulazeez Alaseeri
Accela Civic Platform version 21.1 suffers from cross site scripting and open redirection vulnerabilities.
advisories | CVE-2021-34370
Change Mirror Download
# Exploit Title: Accela Civic Platform 21.1 - 'successURL'...
Accela Civic Platform 21.1 Insecure Direct Object Reference
Authored by Abdulazeez Alaseeri
Accela Civic Platform version 21.1 suffers from an insecure direct object reference vulnerability.
advisories | CVE-2021-34369
Change Mirror Download
# Exploit Title: Accela Civic Platform 21.1 - 'contactSeqNumber' Insecure...





