SecPod

Learn Search

Search across all Learn content

SecPod Labs

Security Research

In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

Open ArticleSetup Multiple Persistence Cross-Site Scripting and SQL Injection Vulnerabilities

ArticleSetup Multiple Persistence Cross-Site Scripting and SQL Injection Vulnerabilities

CVE Research

ArticleSetup Multiple Persistence Cross-Site Scripting and SQL Injection Vulnerabilities

SecPod Research Team member (Antu Sanadi) has found Multiple Persistence Cross-Site Scripting and SQL Injection Vulnerabilities in ArticleSetup. The vulnerability is caused by improper validation of various parameters in multiple pages. This may allow an attacker to steal cookie-based authentication...

Apr 28, 2026 • 1 min read

Open Netmechanica NetDecision Dashboard Server Information Disclosure Vulnerability

Netmechanica NetDecision Dashboard Server Information Disclosure Vulnerability

CVE Research

Netmechanica NetDecision Dashboard Server Information Disclosure Vulnerability

SecPod Research Team member (Prabhu S Angadi) has found Information Disclosure Vulnerability in Netmechanica NetDecision Dashboard Server. The vulnerability is caused due to improper validation of malicious HTTP requests to the Dashboard server appended with ‘?’ character, which discloses the Dashbo...

Apr 28, 2026 • 1 min read

Open Adiscon LogAnalyzer ‘highlight’ Parameter Cross Site Scripting Vulnerability

Adiscon LogAnalyzer ‘highlight’ Parameter Cross Site Scripting Vulnerability

CVE Research

Adiscon LogAnalyzer ‘highlight’ Parameter Cross Site Scripting Vulnerability

SecPod Research Team member (Sooraj K.S) has found Cross-Site Scripting Vulnerabilities in Adiscon LogAnalyzer. The vulnerability is caused by improper validation of “highlight” parameter in “index.php”. This may allow an attacker to steal cookie-based authentication credentials or inject arbitrary ...

Apr 28, 2026 • 1 min read

Open AR Web Content Manager (AWCM) Cross-Site scripting Vulnerability

AR Web Content Manager (AWCM) Cross-Site scripting Vulnerability

CVE Research

AR Web Content Manager (AWCM) Cross-Site scripting Vulnerability

SecPod Research Team member (Antu Sanadi) has found an XSS flaw in AR Web Content Manager (AWCM), which can be used to obtain sensitive information and launch further attacks. The flaw lies in the ‘search’ parameter in ‘search.php‘ while the application processes the user-supplied input and renders ...

Apr 28, 2026 • 1 min read

Open PowerZip Insecure Library Loading Vulnerability

PowerZip Insecure Library Loading Vulnerability

CVE Research

PowerZip Insecure Library Loading Vulnerability

Folks, SecPod Research Team member (Karthik N.) has found a DLL Insecure Loading vulnerability in PowerZip application, which can be used to call malicious arbitrary library files into the application context. For more details, please go though this below advisory link.

Apr 28, 2026 • 1 min read

Open Metasploit Module – BisonFTP Server Remote Buffer Overflow Vulnerability

Metasploit Module – BisonFTP Server Remote Buffer Overflow Vulnerability

CVE Research

Metasploit Module – BisonFTP Server Remote Buffer Overflow Vulnerability

SecPod Research Team member (Veerendra G.G) wrote Metasploit module for BisonFTP Server Remote Buffer Overflow Vulnerability.

Apr 28, 2026 • 2 min read

Open AT-TFTP Server v1.8 Remote Denial of Service Vulnerability

AT-TFTP Server v1.8 Remote Denial of Service Vulnerability

CVE Research

AT-TFTP Server v1.8 Remote Denial of Service Vulnerability

SecPod Research Team member (Antu Sanadi) has found a Denial of Service vulnerability in Allied Telesyn TFTP Server. The vulnerability is caused by an error in the “TFTPD.EXE”, which causes the server to crash when no acknowledgment response is sent back to the server after a successful ‘read’. The ...

Apr 28, 2026 • 1 min read

Open Habari Installation Path Disclosure Vulnerability

Habari Installation Path Disclosure Vulnerability

CVE Research

Habari Installation Path Disclosure Vulnerability

More information on the flaws can be found here.

Apr 28, 2026 • 1 min read

Open MYRE Real Estate Software Multiple XSS and SQL Injection Vulnerabilities

MYRE Real Estate Software Multiple XSS and SQL Injection Vulnerabilities

CVE Research

MYRE Real Estate Software Multiple XSS and SQL Injection Vulnerabilities

SecPod Research Team member (Sooraj K.S) has found Multiple XSS and SQL Injection Vulnerabilities in MYRE Real Estate Software. The vulnerability is caused by improper validation of various parameters in several pages. This may allow an attacker to steal cookie-based authentication credentials, comp...

Apr 28, 2026 • 1 min read