Vimarsana
Biggest News Aggregation in the World

Page 21 - Exploit Title News Today : Breaking News, Live Updates & Top Stories | Vimarsana

Stay updated with breaking news from Exploit Title. Get real-time updates on events, politics, business, and more. Visit us for reliable news and exclusive interviews.

Top News In Exploit Title Today - Breaking & Trending Today

UliCMS 2023-1 Sniffing-Vicuna Shell Upload - KizzMyAnthia.com - Vimarsana News

UliCMS 2023-1 Sniffing-Vicuna Shell Upload - KizzMyAnthia.com

#Exploit Title: Ulicms-2023.1 sniffing-vicuna - Remote Code Execution (RCE)#Application: Ulicms#Version: 2023.1-sniffing-vicuna#Bugs: RCE#Technology: PHP#Vendor URL: https://en.ulicms.de/#Software Link: https://www.ulicms.de/content/files/Releases/2023.1/ulicms-2023.1-sniffing-vicuna-full.zip#Date of found: 04-05-2023#Author: Mirabbas Ağalarov#Tested on: Linux 2. Technical Details & POC========================================steps: 1. Login to account and edit profile.2.Upload new Avatar3. It is possible to include the php file with the phar extension when uploading the image. Rce

Jedox 2020.2.5 Configurable Storage Path Remote Code Execution - Vimarsana News

Jedox 2020.2.5 Configurable Storage Path Remote Code Execution

# Exploit Title: Jedox 2020.2.5 - Remote Code Execution via Configurable Storage Path# Date: 28/04/2023# Exploit Author: Team Syslifters / Christoph MAHRL, Aron MOLNAR, Patrick PIRKER and Michael WEDL# Vendor Homepage: https://jedox.com# Version: Jedox 2020.2 (20.2.5) and older# CVE : CVE-2022-47878Introduction=================Incorrect input validation for the default storage path variable in the settings page allows remote,

Jedox 2020.2.5 Database Credential Disclosure - Vimarsana News

Jedox 2020.2.5 Database Credential Disclosure

# Exploit Title: Jedox 2020.2.5 - Disclosure of Database Credentials via Improper Access Controls# Date: 28/04/2023# Exploit Author: Team Syslifters / Christoph MAHRL, Aron MOLNAR, Patrick PIRKER and Michael WEDL# Vendor Homepage: https://jedox.com# Version: Jedox 2020.2 (20.2.5) and older# CVE : CVE-2022-47874Introduction=================Improper access controls in `/tc/rpc` allows remote authenticated users to view details of database

Jedox 2022.4.2 Database Credential Disclosure - Vimarsana News

Jedox 2022.4.2 Database Credential Disclosure

# Exploit Title: Jedox 2022.4.2 - Disclosure of Database Credentials via Connection Checks# Date: 28/04/2023# Exploit Author: Team Syslifters / Christoph MAHRL, Aron MOLNAR, Patrick PIRKER and Michael WEDL# Vendor Homepage: https://jedox.com# Version: Jedox 2022.4 (22.4.2) and older# CVE : CVE-2022-47880Introduction=================An information disclosure vulnerability in `/be/rpc.php` allows remote authenticated users with the appropriate permissions to

EasyPHP Webserver 14.1 Path Traversal / Remote Code Execution - Vimarsana News

EasyPHP Webserver 14.1 Path Traversal / Remote Code Execution

# Exploit Title: EasyPHP Webserver 14.1 - Multiple Vulnerabilities (RCE andPath Traversal)# Discovery by: Rafael Pedrero# Discovery Date: 2022-02-06# Vendor Homepage: https://www.easyphp.org/# Software Link : https://www.easyphp.org/# Tested Version: 14.1# Tested on: Windows 7 and 10# Vulnerability Type: Remote Command Execution (RCE)CVSS v3: 9.8CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCWE: CWE-78Vulnerability description: There is an OS Command Injection in EasyPHPWebserver