header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

WordPress Plugin Colorbox Lightbox v1.1.1 – Persistent Cross-Site Scripting Vulnerability (Authenticated)

WordPress Colorbox plugin version v1.1.1 (and possibly previous versions) is affected by a stored XSS vulnerability due to improper input sanitization of the "hyperlink" field in the plugin shortcode.

Karel IP Phone IP1211 Web Management Panel – Directory Traversal

Directory traversal vulnerability on the Karel IP1211 IP Phone Web Panel. Remote authenticated users (Attackers used default credentials in this case) to perform directory traversal, provides access to sensitive data under indexes using the "cgiServer.exx?page=" parameter. In this case sensitive files, "passwd" and "shadow" files.

Typesetter CMS 5.1 – ‘Site Title’ Persistent Cross-Site Scripting

The Typesetter CMS version 5.1 is vulnerable to persistent cross-site scripting. An attacker can exploit this vulnerability by logging into the administrator page, navigating to Settings > Configuration > General Settings, and injecting a malicious payload into the 'title' field. This payload will be executed when the website is accessed.

SpinetiX Fusion Digital Signage 3.4.8 – Cross-Site Request Forgery (Add Admin)

The application interface allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to perform certain actions with administrative privileges if a logged-in user visits a malicious web site.

Recent Exploits: