WP Mobile Detector Plugin for WordPress contains a flaw that allows a remote attacker to execute arbitrary PHP code. This flaw exists because the /wp-content/plugins/wp-mobile-detector/resize.php script does contains a remote file include for files not cached by the system already. By uploading a .php file, the remote system will place the file in a user-accessible path. Making a direct request to the uploaded file will allow the attacker to execute the script with the privileges of the web server.
78c713af652be903f93b72d84bd37300ff88c13c97f655448730f42c48f8d6a6
Brave Browser suffers from an address bar spoofing vulnerability. iOS version 1.2.16 (16.09.30.10) and Android version 1.9.56 is affected.
c069cc5fd270e74c97b4fecf56ed55ff2a5716dfe46f318f46caefbe5ba9815f
Beats By Dre suffered from a cross site request forgery vulnerability.
2d3ccb9df19abcc28429634123e168d9e2ecdb52d40839bf2919ce9377d2a86d
WordPress CM Ad Changer plugin version 1.7.7 suffers from a cross site scripting vulnerability.
c0be27eebca044470644e7a969b0287dff5a39a5a9e9b7408c2acf09861d5431
WordPress Levo-Slideshow plugin version 2.3 suffers from a remote shell upload vulnerability.
91775de6a26e93b2855a33e099c804901147d66ccd04b4eb384eb92a9f0580b8
WordPress Levo-Slideshow plugin version 2.3 suffers from a persistent cross site scripting vulnerability.
9607cdb93fb7ba7480efd9dcf67bf508b308c45ffbf0f540e4aacf6a6be04828
WordPress WP Mobile Detector versions 3.5 and below suffer from a remote shell upload vulnerability.
54c52f7c04066173a12655663242297e4ea661b091061074d1b10b403959b4bd
WordPress Levo-Slideshow plugin version 2.3 suffers from a remote shell upload vulnerability.
1e3a87c6e895d83107e72876740165625d6152fbd1f136ce8f74484c904d980d
WordPress WP Mobile Detector plugin versions 3.5 and below suffer from a remote shell upload vulnerability.
85f64637f7e3d070e1c1fb384164c477e46d51fa5c96abcd37721c75c40e3eff
WebComIndia CMS 2015Q4 suffers from an authentication bypass vulnerability via remote SQL injection.
afc30dbcbcfb0ef32c6e8696ef381ed2d5d31290833839f08df44da1dacba8e1
LinuxOptic CMS 2009 suffers from an authentication bypass vulnerability.
fb5510a4e8241f843f5f5647141f946a2f3127a5a149a226a545326bfffff821
Dogma India dogmaindia CMS suffers from an authentication bypass vulnerability.
e83e7863e16b666b0fa577c942a5232b031229a84ba725a9bedf9a2cb44b6929