Unsanitized user input in ExpressionEngine <= 5.4.0 control panel member creation leads to an SQL injection. The user needs member creation/admin control panel access to execute the attack.
Category Archives: Advisories
Datarobot — Remote Code Execution
Posted by Michael Coers on Feb 18
Exploit Title: Datarobot — Remote Code Execution
Date: 9/28/2021
Vendor Homepage: https://www.datarobot.com
Software Link: https://app.datarobot.com/
Version: TBD – awaiting build version from vendor
Tested on: The issue affects all versions of the product up to the date of this submission
Exploit Authors: Mike Coers & Pathfynder Inc
Exploit Contact: sm0key a t dnsfiltrate_io & micheal.coers a t pathfynder dot_io
Exploit Technique:…
MartFury Marketplace – Cross Site Scripting Vulnerability
Posted by info () vulnerability-lab com on Feb 18
Document Title:
===============
MartFury Marketplace – Cross Site Scripting Vulnerability
References (Source):
====================
https://www.vulnerability-lab.com/get_content.php?id=2282
Release Date:
=============
2022-02-17
Vulnerability Laboratory ID (VL-ID):
====================================
2282
Common Vulnerability Scoring System:
====================================
5.5
Vulnerability Class:
====================
Cross Site…
Vicidial v2.14-783a – (DB) SQL Injection Web Vulnerability
Posted by info () vulnerability-lab com on Feb 18
Document Title:
===============
Vicidial v2.14-783a – (DB) SQL Injection Web Vulnerability
References (Source):
====================
https://www.vulnerability-lab.com/get_content.php?id=2312
Release Date:
=============
2022-02-17
Vulnerability Laboratory ID (VL-ID):
====================================
2312
Common Vulnerability Scoring System:
====================================
7.3
Vulnerability Class:
====================
SQL Injection…
WordPress v5.9 – Reflected Cross Site Scripting Web Vulnerability
Posted by info () vulnerability-lab com on Feb 18
Document Title:
===============
Wordpress v5.9 – Reflected Cross Site Scripting Web Vulnerability
References (Source):
====================
https://www.vulnerability-lab.com/get_content.php?id=2316
Release Date:
=============
2022-02-09
Vulnerability Laboratory ID (VL-ID):
====================================
2316
Common Vulnerability Scoring System:
====================================
4.2
Vulnerability Class:
====================
Cross…
Car Portal Template – (Search) Persistent Web Vulnerability
Posted by info () vulnerability-lab com on Feb 18
Document Title:
===============
Car Portal Template – (Search) Persistent Web Vulnerability
References (Source):
====================
https://www.vulnerability-lab.com/get_content.php?id=2299
Release Date:
=============
2022-02-08
Vulnerability Laboratory ID (VL-ID):
====================================
2299
Common Vulnerability Scoring System:
====================================
5.6
Vulnerability Class:
====================
Cross Site…
Multiple Vulnerabilities in Adobe Commerce and Magento Could Allow for Remote Code Execution
Multiple vulnerabilities have been discovered in Adobe Commerce and Magento Open Source, the most severe of which could allow for remote code execution.
Adobe Commerce is a leading provider of cloud commerce innovation to merchants and brands across B2C and B2B industries.
Magento is a web-based e-commerce application written in PHP.
Successful exploitation of the most severe of these vulnerabilities could allow for remote code execution. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.
CVE-2020-8107
A Process Control vulnerability in ProductAgentUI.exe as used in Bitdefender Antivirus Plus allows an attacker to tamper with product settings via a specially crafted DLL file. This issue affects: Bitdefender Antivirus Plus versions prior to 24.0.26.136. Bitdefender Internet Security versions prior to 24.0.26.136. Bitdefender Total Security versions prior to 24.0.26.136.
ZDI-22-386: Parallels Desktop HDAudio Buffer Overflow Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability.
ZDI-22-385: Parallels Desktop Service Time-Of-Check Time-Of-Use Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.