Data Of Nearly 700,000 Amex India Customers Exposed Via Unsecured MongoDB Server
Google's Bug Bounty Program Just Had A Record-Breaking Year Of Payouts
Google Data Shines Light On Whether Coronavirus Lockdowns Worldwide Are Working
Citrix Application Delivery Controller / Gateway Remote Code Execution / Traversal
Citrix Application Delivery Controller and Citrix Gateway directory traversal remote code execution exploit.
Huawei HG255 Directory Traversal
Citrix ADC / Gateway Path Traversal
This is an nmap nse script to test for the path traversal vulnerability in Citrix Application Delivery Controller (ADC) and Gateway.
Pachev FTP Server 1.0 Path Traversal
Lotus Core CMS 1.0.1 Local File Inclusion
SuiteCRM 7.11.11 Broken Access Control / Local File Inclusion
SuiteCRM versions 7.11.11 and below suffer from an add_to_prospect_list broken access control that allows for local file inclusion attacks.
DotNetNuke CMS 9.4.4 Zip Directory Traversal
DotNetNuke CMS version 9.4.4 suffers from zip split issue where a directory traversal attack can be performed to overwrite files or execute malicious code.
Apache Tomcat AJP Ghostcat File Read / Inclusion
PHPKB Multi-Language 9 Authenticated Directory Traversal
PHPKB Multi-Language 9 suffers from an authenticated directory traversal vulnerability.
FIBARO System Home Center 5.021 Remote File Inclusion / XSS
FIBARO System Home Center version 5.021 suffers from cross site scripting and remote file inclusion vulnerabilities.
Jinfornet Jreport 15.6 Directory Traversal
Jinfornet Jreport version 15.6 suffers from an unauthenticated directory traversal vulnerability.
Joomla Fabrik 3.9.11 Directory Traversal
Joomla Fabrik component version 3.9.11 suffers from a directory traversal vulnerability.
LimeSurvey 4.1.11 Path Traversal
Zen Load Balancer 3.10.1 Directory Traversal
Zen Load Balancer version 3.10.1 suffers from a directory traversal vulnerability. This finding was originally discovered by Cody Sixteen.
TVT NVMS 1000 Directory Traversal
QRadar Community Edition 7.3.1.6 Arbitrary Object Instantiation
QRadar Community Edition version 7.3.1.6 is vulnerable to instantiation of arbitrary objects based on user-supplied input. An authenticated attacker can abuse this to perform various types of attacks including server-side request forgery and (potentially) arbitrary execution of code.
Booked Scheduler 2.7.7 Directory Traversal
Booked Scheduler version 2.7.7 suffers from an authenticated directory traversal vulnerability.