Security
Headlines
HeadlinesLatestCVEs

Tag

#php

Anevia Flamingo XL 3.6.20 Authenticated Root Remote Code Execution

Anevia Flamingo XL version 3.6.20 suffers from an authenticated remote code execution vulnerability. A remote attacker can exploit this issue and execute arbitrary system commands granting her system access with root privileges.

Packet Storm
#vulnerability#web#linux#apache#git#php#rce#auth#ssl
Anevia Flamingo XS 3.6.5 Authenticated Root Remote Code Execution

Anevia Flamingo XS version 3.6.5 suffers from an authenticated remote code execution vulnerability. A remote attacker can exploit this issue and execute arbitrary system commands granting her system access with root privileges.

Anevia Flamingo XL/XS 3.6.x Default / Hardcoded Credentials

Anevia Flamingo XL/XS versions 3.6.20 and 3.2.9 have a weak set of default and hardcoded administrative credentials that can be easily guessed in remote password attacks and gain full control of the system.

OmniCart 3.4.0 Cross Site Scripting

OmniCart version 3.4.0 suffers from a cross site scripting vulnerability.

PhotoSwipe 5.3.7 Arbitrary File Download

PhotoSwipe version 5.3.7 suffers from an arbitrary file download vulnerability.

PES Pro CMS 1.9.7 Add Administrator

PES Pro CMS version 1.9.7 suffers from an add administrator vulnerability.

Pannres-Idence CMS 7.3 Cross Site Request Forgery

Pannres-Idence CMS version 7.3 suffers from a cross site request forgery vulnerability.

osCommerce 4 Local File Inclusion

osCommerce version 4 suffers from a local file inclusion vulnerability.

WordPress Workreap 2.2.2 Shell Upload

WordPress theme Workreap version 2.2.2 suffers from a remote shell upload vulnerabilities.

Anevia Flamingo XL 3.2.9 (login) Remote Root Jailbreak

Once the admin establishes a secure shell session, she gets dropped into a sandboxed environment using the login binary that allows specific set of commands. One of those commands that can be exploited to escape the jailed shell is traceroute. A remote attacker can breakout of the restricted environment and have full root access to the device.