Biggest News Aggregation in the World
📰 Software Link News

Page 8 - Software Link News Today

Fast, Ad-Free News Updates

Stay updated with breaking news from Software Link. Real-time updates on events, politics, business and more.

Academy LMS 5.15 Cross Site Scripting - KizzMyAnthia.com

# Exploit Title: Academy LMS 5.15 - Reflected XSS# Exploit Author: CraCkEr# Date: 09/07/2023# Vendor: Creativeitem# Vendor Homepage: https://creativeitem.com/# Software Link: https://demo.creativeitem.com/academy/# Tested on: Windows 10 Pro# Impact: Manipulate the content of the site ## DescriptionAllow Attacker to inject malicious code into website, give ability to steal sensitiveinformation, manipulate data, and launch additional attacks.Path: /home/coursesGET
Software Link Exploit Title Exploit Author Vendor Homepage

Mastery LMS 1.2 Cross Site Scripting - KizzMyAnthia.com

# Exploit Title: Mastery LMS 1.2 - Reflected XSS# Exploit Author: CraCkEr# Date: 09/07/2023# Vendor: Creativeitem# Vendor Homepage: https://creativeitem.com/# Software Link: https://demo.creativeitem.com/mastery/# Tested on: Windows 10 Pro# Impact: Manipulate the content of the site ## DescriptionAllow Attacker to inject malicious code into website, give ability to steal sensitiveinformation, manipulate data, and launch additional attacks.Path: /browseGET
Software Link Exploit Title Exploit Author Vendor Homepage

Beauty Salon Management System 1.0 SQL Injection

# Exploit Title: Beauty Salon Management System v1.0 - SQLi# Date of found: 04/07/2023# Exploit Author: Fatih Nacar# Version: V1.0# Tested on: Windows 10# Vendor Homepage: https://www.campcodes.com # Software Link: https://www.campcodes.com/projects/beauty-salon-management-system-in-php-and-mysqli/# CWE: CWE-89Vulnerability Description -Beauty Salon Management System: V1.0, developed by Campcodes, has beenfound to be vulnerable to SQL Injection (SQLI) attacks. This vulnerabilityallows an
Fatih Nacar Software Link Exploit Title Beauty Salon Management System Exploit Author Vendor Homepage

POS Codekop 2.0 Shell Upload - KizzMyAnthia.com

# Exploit Title: POS Codekop v2.0 - Authenticated Remote Code Execution (RCE)# Date: 25-05-2023# Exploit Author: yuyudhn# Vendor Homepage: https://www.codekop.com/# Software Link: https://github.com/fauzan1892/pos-kasir-php# Version: 2.0# Tested on: Linux# CVE: CVE-2023-36348# Vulnerability description: The application does not sanitize the filenameparameter when sending data to /fungsi/edit/edit.php?gambar=user. Anattacker can exploit this issue by uploading a PHP file and
Software Link Exploit Title Authenticated Remote Code Execution Exploit Author Vendor Homepage Remote Code

Alkacon OpenCMS 15.0 Cross Site Scripting - KizzMyAnthia.com

# Exploit Title: Alkacon OpenCMS 15.0 - Multiple Cross-Site Scripting# Date: 1/07/2023# Exploit Author: tmrswrr# Vendor Homepage: http://www.opencms.org# Software Link: https://github.com/alkacon/opencms-core# Version: v15.0POC:1 ) Login in demo page , go to this urlhttps://demo.opencms.org/workplace#!explorer/8b72b2fe-180f-11ee-b326-0242ac11002b!!/sites/livedemo!!/.galleries/livedemo/!!2 ) Click /.galleries/ , after right click any png file , open gallery, write in search button this payload3 )...
Alkacon Open Software Link Exploit Title Multiple Cross Site Exploit Author Vendor Homepage

Stay Updated with Latest News

Get breaking news updates delivered to your inbox

Browse All News →

Smart Office Web 20.28 Information Disclosure / Insecure Direct Object Reference

# Exploit Title: Smart Office Web 20.28 - Remote Information Disclosure (Unauthenticated)# Shodan Dork:: inurl:"https://www.shodan.io/search?query=smart+office"# Date: 09/Dec/2022# Exploit Author: Tejas Nitin Pingulkar (https://cvewalkthrough.com/)# Vendor Homepage: https://smartofficepayroll.com/# Software Link: https://smartofficepayroll.com/downloads# Version: Smart Office Web 20.28 and before# CVE Number : CVE-2022-47075 and CVE-2022-47076# CVSS : 7.5 (High)# Reference : https://cv...
Tejas Nitin Pingulkar Smart Office Web Software Link Exploit Title Remote Information Disclosure Shodan Dork

Symantec SiteMinder WebAgent 12.52 Cross Site Scripting

Exploit Title: Symantec SiteMinder WebAgent v12.52 - Cross-site scripting (XSS)Google Dork: N/ADate: 18-06-2023Exploit Author: Harshit JoshiVendor Homepage: https://community.broadcom.com/homeSoftware Link: https://www.broadcom.com/products/identity/siteminderVersion: 12.52Tested on: Linux, WindowsCVE: CVE-2023-23956Security Advisory: https://support.broadcom.com/external/content/SecurityAdvisories/0/22221*Description:*I am writing to report two XSS vulnerabilities (CVE-2023-23956) that I havedi...
Harshit Joshi Symantec Siteminder Webagent Software Link Exploit Title Symantec Siteminder Weakness Enumeration

Student Study Center Management System 1.0 Cross Site Scripting

# Exploit Title: Student Study Center Management System v1.0 - Stored Cross-Site Scripting (XSS)# Date of found: 12/05/2023# Exploit Author: VIVEK CHOUDHARY @sudovivek# Version: V1.0# Tested on: Windows 10# Vendor Homepage: https://phpgurukul.com# Software Link: https://phpgurukul.com/student-study-center-management-system-using-php-and-mysql/# CVE: CVE-2023-33580# CVE URL: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-33580Vulnerability Description -The Student Study Center Management...
Software Link Student Study Center Management System Exploit Title Stored Cross Site Scripting Exploit Author Vendor Homepage

Online Art Gallery Project 1.0 Arbitrary File Upload

# Exploit Title: Online Art gallery project 1.0 - Arbitrary File Upload (Unauthenticated)# Google Dork: n/a# Date: 14/06/2023# Exploit Author: Ramil Mustafayev# Vendor Homepage: https://github.com/projectworldsofficial# Software Link: https://github.com/projectworlds32/Art-Gallary-php/archive/master.zip# Version: 1.0# Tested on: Windows 10, XAMPP for Windows 8.0.28 / PHP 8.0.28# CVE : n/a# Vulnerability Description:## Online Art Gallery Project 1.0 allows unauthenticated users to
Ramil Mustafayev Software Link Exploit Title Online Art Arbitrary File Upload Google Dork

PyLoad 0.5.0 Remote Code Execution - KizzMyAnthia.com

# Exploit Title: PyLoad 0.5.0 - Pre-auth Remote Code Execution (RCE)# Date: 06-10-2023# Credits: bAu @bauh0lz # Exploit Author: Gabriel Lima (0xGabe)# Vendor Homepage: https://pyload.net/# Software Link: https://github.com/pyload/pyload# Version: 0.5.0# Tested on: Ubuntu 20.04.6# CVE: CVE-2023-0297import requests, argparseparser = argparse.ArgumentParser()parser.add_argument('-u', action='store', dest='url', required=True, help='Target url.')parser.add_arg...
Gabriel Lima Software Link Exploit Title Pre Auth Remote Code Execution Exploit Author Vendor Homepage

Explore More Categories

World News India News Business Technology Sports Entertainment Health Science