CommScope Ruckus IoT Controller 1.7.1.0 Hard-Coded Web Application Administrator Password
Authored by Jim Becher | Site korelogic.com
An undocumented, administrative-level, hard-coded web application account exists in the IoT Controller OVA which cannot be changed by the customer.
advisories | CVE-2021-33219
Change Mirror...
CommScope Ruckus IoT Controller 1.7.1.0 Web Application Directory Traversal
Authored by Jim Becher | Site korelogic.com
A Python script (web.py) for a Dockerized webservice contains a directory traversal vulnerability, which can be leveraged by an authenticated attacker to view...
CommScope Ruckus IoT Controller 1.7.1.0 Web Application Arbitrary Read/Write
Authored by Jim Becher | Site korelogic.com
The IoT Controller web application includes a NodeJS module, node-red, which has the capability for users to read or write to local files...
CommScope Ruckus IoT Controller 1.7.1.0 Undocumented Account
Authored by Jim Becher | Site korelogic.com
An upgrade account is included in the IoT Controller OVA that provides the vendor undocumented access via Secure Copy (SCP).
advisories | CVE-2021-33216
Change Mirror...
Selenium 3.141.59 Remote Code Execution
Authored by Jon Stratton
Selenium version 3.141.59 remote code execution exploit.
Change Mirror Download
# Exploit Title: Selenium 3.141.59 - Remote Code Execution (Firefox/geckodriver)# Date: 2021-05-27# Exploit Author: Jon Stratton# Vendor Homepage:...
WordPress LifterLMS 4.21.0 Cross Site Scripting
Authored by Captain_hook
WordPress LifterLMS plugin version 4.21.0 suffers from a persistent cross site scripting vulnerability.
advisories | CVE-2021-24308
Change Mirror Download
# Exploit Title: WordPress Plugin LifterLMS 4.21.0 - Stored Cross-Site Scripting...
PHPFusion 9.03.50 Remote Code Execution
Authored by ThienNV, g0ldm45k
PHPFusion version 9.03.50 suffers from a remote code execution vulnerability.
advisories | CVE-2020-24949
Change Mirror Download
# Exploit Title: PHPFusion 9.03.50 - Remote Code Execution# Date: 20/05/2021# Exploit Author:...
Trixbox 2.8.0.4 Path Traversal
Authored by Ron Jost
Trixbox version 2.8.0.4 has path traversal via the xajaxargs array parameter to /maint/index.php?packages or the lang parameter to /maint/modules/home/index.php.
advisories | CVE-2017-14537
Change Mirror Download
# Exploit Title: Trixbox...
Trixbox 2.8.0.4 Remote Code Execution
Authored by Ron Jost
Trixbox version 2.8.0.4 has an OS command injection vulnerability that can be leveraged via shell metacharacters in the lang parameter to /maint/modules/home/index.php.
advisories | CVE-2017-14535
Change Mirror Download
#...
Postbird 0.8.4 Cross Site Scripting / Local File Inclusion
Authored by Debshubra Chakraborty
Postbird version 0.8.4 suffers from a javascript injection vulnerability that allows for cross site scripting and local file inclusion.
advisories | CVE-2021-33570
Change Mirror Download
# Exploit Title: Postbird...





