Category: CVSS2 - HIGH
MOVEit SQL Injection Exploit

This Metasploit module exploits an SQL injection vulnerability in the MOVEit Transfer web application that allows an unauthenticated attacker to gain access to MOVEit Transfer's database. Depending on ...

Continue Reading
CVE-2023-3197

The MStore API plugin for WordPress is vulnerable to Unauthenticated Blind SQL Injection via the 'id' parameter in versions up to, and including, 4.0.1 due to insufficient escaping on the user supplie ...

Continue Reading
CVE-2023-3197

The MStore API plugin for WordPress is vulnerable to Unauthenticated Blind SQL Injection via the 'id' parameter in versions up to, and including, 4.0.1 due to insufficient escaping on the user supplie ...

Continue Reading
Metasploit Weekly Wrap-Up

## I like to MOVEit, MOVEit, We like to MOVEit! ![Metasploit Weekly Wrap-Up](https://blog.rapid7.com/content/images/2023/06/metasploit-sky.png) Party hard just like it's Mardi Gras! [bwatters-r7]() de ...

Continue Reading
Description of the security update for SharePoint Server 2019: June 13, 2023 (KB5002402)

None ## Summary This security update resolves a Microsoft SharePoint Server elevation of privilege vulnerability, Microsoft SharePoint denial of service vulnerability, and Microsoft SharePoint Server ...

Continue Reading
MOVEit SQL Injection

Post ContentRead More ...

Continue Reading
GCP ESPv2 Hit with Critical API Authorization Bypass CVE-2023-30845

This post delves into a very impactful JWT Authentication Bypass vulnerability ([CVE-2023-30845]()) found in [ESP-v2](), an open-source service proxy that provides API management capabilities using Go ...

Continue Reading
Alert! Hackers Exploiting Critical Vulnerability in VMware’s Aria Operations Networks

[![Vulnerability in VMware](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8Xw8AAoMBgDTD2qgAAAAASUVORK5CYII=)]() VMware has flagged that a recently patched critical c ...

Continue Reading
GCP ESPv2 Hit with Critical API Authorization Bypass CVE-2023-30845

This post delves into a very impactful JWT Authentication Bypass vulnerability ([CVE-2023-30845]()) found in [ESP-v2](), an open-source service proxy that provides API management capabilities using Go ...

Continue Reading
GCP ESPv2 Hit with Critical API Authorization Bypass CVE-2023-30845

This post delves into a very impactful JWT Authentication Bypass vulnerability ([CVE-2023-30845]()) found in [ESP-v2](), an open-source service proxy that provides API management capabilities using Go ...

Continue Reading
Load more