QT PNG ICC Processing Out-Of-Bounds Read
Authored by Google Security Research, natashenka
The QImage class can read out-of-bounds when reading a specially-crafted PNG file, where a tag byte offset goes out of bounds. This could potentially...
Pandora FMS 6.0SP3 Cross Site Scripting
Authored by nu11secur1ty
Pandora FMS version 6.0SP3 suffers from a cross site scripting vulnerability.
advisories | CVE-2021-0527
Change Mirror Download
# Exploit Title: XSS vulnerability for (keywords) searching parameter inpandorafms-6.0SP3/pandora_console# Author: @nu11secur1ty# Testing...
CommScope Ruckus IoT Controller 1.7.1.0 Unauthenticated API Endpoints
Authored by Jim Becher | Site korelogic.com
Three API endpoints for the IoT Controller are accessible without authentication. Two of the endpoints result in information leakage and consumption of computing/storage...
CommScope Ruckus IoT Controller 1.7.1.0 Hard-Coded API Keys Exposed
Authored by Jim Becher | Site korelogic.com
API keys for CommScope Ruckus are included in the IoT Controller OVA image, and are exposed to attackers who mount the filesystem.
advisories |...
Gadget Works Online Ordering System 1.0 Cross Site Scripting
Authored by Vinay H C
Gadget Works Online Ordering System version 1.0 suffers from a persistent cross site scripting vulnerability.
Change Mirror Download
# Exploit Title: Gadget Works Online Ordering System 1.0...
WordPress Cookie Law Bar 1.2.1 Cross Site Scripting
Authored by Mesut Cetin
WordPress Cookie Law Bar plugin version 1.2.1 suffers from a persistent cross site scripting vulnerability.
Change Mirror Download
# Exploit Title: WordPress Plugin Cookie Law Bar 1.2.1 -...
QT TIFF Processing Out-Of-Bounds Read
Authored by Google Security Research, natashenka
The QImageReader class can read out-of-bounds when converting a specially-crafted TIFF file into a QImage, where the TIFF tile length is inconsistent with the...
RarmaRadio 2.72.8 Denial Of Service
Authored by Ismael Nava
RarmaRadio version 2.72.8 denial of service proof of concept exploit.
Change Mirror Download
# Exploit Title: RarmaRadio 2.72.8 - Denial of Service (PoC)# Date: 2021-05-25# Exploit Author: Ismael...
ProFTPd 1.3.5 Remote Command Execution
Authored by Shellbr3ak
ProFTPd version 1.3.5 remote command execution exploit. This is a variant of the original vulnerability discovered in 2015 with credit going to R-73eN.
advisories | CVE-2015-3306
Change Mirror Download
#...
Nagios XI / Fusion Privilege Escalation / Cross Site Scripting / Code Execution
Authored by Shahar Zini, Samir Ghanem | Site skylightcyber.com
Skylight Cyber has identified a total of 13 vulnerabilities in Nagios XI and Nagios Fusion servers. These include remote code execution,...





