This Metasploit module takes advantage of a protocol design issue with the Rosewill admin executable in order to retrieve passwords, allowing remote attackers to take administrative control over the device. Other similar IP Cameras such as Edimax, Hawking, Zonet, etc, are also believed to have the same flaw, but not fully tested. The protocol design issue also allows attackers to reset passwords on the device.
362007d6c9e7ed189b21c55291fc6aa6c1c4b1494d29638e41d80a4dd9cf8eac
WordPress Relocate Upload plugin version 0.14 suffers from a remote file inclusion vulnerability.
4bbe8fbb769a5b00cc395ace0a6db17412d3437d2bc1ff4f2c7211144d670b91
WordPress Mini Mail Dashboard Widget plugin version 1.36 suffers from a remote file inclusion vulnerability.
22b8b46f36afaf271f47a324d98d3dfe771d22dbfd2307d2cabfd63b7bac9ea9
WordPress Zingiri Web Shop plugin version 2.2.0 suffers from a remote file inclusion vulnerability.
eb86823281e55aaf1a6c7deaa561f14cc74a0659373aae29549e9aa8cc507d5c
WordPress Mailing List plugin version 1.3.2 suffers from a remote file inclusion vulnerability.
c62dd24b059c91a378049c480428ca9765b7b65f1ace1718c81835ae8bc9a488
Multiple WordPress plugins suffer from a remote shell upload vulnerability due to the reuse of the vulnerable timthumb.php library.
321c3ad06b0f47075ec9eb1b1882d1392ead87ce0674e1dbfd83a2020fa2909d
WordPress TheCartPress plugin version 1.1.1 suffers from a remote file inclusion vulnerability.
51de8edbe4033bacd0f4611cbca6a1140cd31164ab53aa95b893d748467e6ff8
WordPress AllWebMenus plugin version 1.1.3 suffers from a remote file inclusion vulnerability.
f5992b2e2ebf81baa29016bfe3528094294216f811d0fa8fbeaaaa77bd9ce35c
WordPress WPEasyStats plugin version 1.8 suffers from a remote file inclusion vulnerability.
d3f013a760a7b4563260188e45ab4a66c858aef58be11b3225d2ee692195009e
WordPress Annonces plugin version 1.2.0.0 suffers from a remote file inclusion vulnerability.
2e4ae0c37dabeb183163b80fa8ef260ca92eb9b43ff547a9b25552e65bf84af8
WordPress Livesig plugin version 0.4 suffers from a remote file inclusion vulnerability.
87c4823c00d785ca175170726e8c75d327a8c835b78969ac014324cd04befe8b
WordPress Disclosure Policy plugin version 1.0 suffers from a remote file inclusion vulnerability.
0883309d0035ccfbd29c2ac569cbe354ce45ea78f5c74ad7108f607655fd0d98
The WordPress 1 Flash Gallery plugin suffers a remote shell upload vulnerability. Metasploit exploit included.
7c6886b81cc82871636398334c3d892069f858273408a672e8f0001cbcb54b85