header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

Webutler v3.2 – Remote Code Execution (RCE)

This exploit allows an attacker to execute arbitrary code remotely on a system running Webutler CMS v3.2. By uploading a specially crafted phar file, the attacker can trigger the execution of arbitrary PHP code, in this case, printing the contents of the /etc/passwd file. This vulnerability can be used to gain unauthorized access to sensitive information or further compromise the system.

WordPress Plugin EventON Calendar 4.4 – Unauthenticated Post Access via IDOR

The plugin does not validate that the event_id parameter in its eventon_ics_download ajax action is a valid Event, allowing unauthenticated visitors to access any Post (including unpublished or protected posts) content via the ics export functionality by providing the numeric id of the post.

Recent Exploits: