Security
Headlines
HeadlinesLatestCVEs

Tag

#csrf

Intelliants Subrion CMS 4.2.1 Remote Code Execution

This Metasploit module exploits an authenticated file upload vulnerability in Subrion CMS versions 4.2.1 and lower. The vulnerability is caused by the .htaccess file not preventing the execution of .pht, .phar, and .xhtml files. Files with these extensions are not included in the .htaccess blacklist, hence these files can be uploaded and executed to achieve remote code execution. In this module, a .phar file with a randomized name is uploaded and executed to receive a Meterpreter session on the target, then deletes itself afterwards.

Packet Storm
#csrf#vulnerability#web#js#git#intel#php#rce#auth
COURIER DEPRIXA 2.5 Cross Site Request Forgery

COURIER DEPRIXA version 2.5 suffers from a cross site request forgery vulnerability.

CVE-2023-36255: Security Advisory 2303-01 - Trovent Security GmbH

An issue in Eramba Limited Eramba Enterprise v.3.19.1 allows a remote attacker to execute arbitrary code via the path parameter in the URL.

Courier Deprixa Pro Integrated Web System 3.2.5 Cross Site Request Forgery

Courier Deprixa Pro Integrated Web System version 3.2.5 suffers from a cross site request forgery vulnerability.