SecPod Labs
Security Research
In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.
XSS Vulnerability in ZeusCart Shopping Cart [0day]
CVE Research
XSS Vulnerability in ZeusCart Shopping Cart [0day]
Folks, SecPod Research Team member (Sooraj K.S) found an XSS flaw in ZeusCart Ecommerce Shopping Cart, which can be used to gain sensitive information and launch further attacks. The flaw lies in the search parameter while ZeusCart web app processes the user-supplied input and renders the content ba...
Sphinix Mobile Web Server Multiple Persistence XSS Vulnerabilities
CVE Research
Sphinix Mobile Web Server Multiple Persistence XSS Vulnerabilities
SecPod Research Team member (Prabhu S Angadi) has found Multiple Persistence Cross-Site Scripting Vulnerabilities in Sphinix Mobile Web Server Blog. The vulnerability is caused by improper validation of “comment” parameter in “/Blog/MyFirstBlog.txt” and “/Blog/AboutSomething.txt” pages. This may all...
Multiple XSS Vulnerabilities in Wiccle Web Builder CMS and iWiccle CMS Community Builder
CVE Research
Multiple XSS Vulnerabilities in Wiccle Web Builder CMS and iWiccle CMS Community Builder
Folks, SecPod Research Team member (Veerendra G.G) found multiple XSS flaws in Wiccle Web Builder CMS and iWiccle CMS Community Builder M, which can be used to gain sensitive information and launch further attacks. Multiple flaws lies in multiple parameters while the web Application processes the us...
Micro CMS Persistent Cross-Site Scripting Vulnerability
CVE Research
Micro CMS Persistent Cross-Site Scripting Vulnerability
Folks, SecPod Research Team member (Veerendra G.G) found persistent XSS flaw in Micro CMS, which can be used to gain sensitive information and launch further attacks. The flaw lies in name parameters while the web Application processes the user-supplied input and renders the content back to the clie...
ClipBucket 2.7.0.5 Multiple Stored Cross-site Scripting Vulnerability
CVE Research
ClipBucket 2.7.0.5 Multiple Stored Cross-site Scripting Vulnerability
SecPod Research Team member (Deependra Bapna) has found Multiple Stored Cross-site. Scripting Vulnerabilities(CVE-2015-4673) in ClipBucket. The vulnerabilities are due to improper validation of various parameters in various pages. This may allow an attacker to steal cookie-based authentication crede...
Andy’s PHP Knowledgebase Multiple Cross-Site Scripting Vulnerabilities
CVE Research
Andy’s PHP Knowledgebase Multiple Cross-Site Scripting Vulnerabilities
SecPod Research Team member (Sooraj K.S) has found multiple cross-site scripting vulnerabilities in Andy’s PHP Knowledgebase. The vulnerability is caused by improper validation of various parameters in several pages. This may allow an attacker to steal cookie-based authentication credentials or inje...
Metasploit Module – Freefloat FTP Server APPE Command Overflow

CVE Research
Microsoft’s October 2021 Patch Tuesday Squashes 4 Zero-days and a Total of 81 Vulnerabilities
Microsoft has released October Patch Tuesday security updates with a total of 81 vulnerabilities, which include Four Zero-Days, Three CVEs rated as critical, and 70 rated as important by a vulnerability scanning tool. The products covered in October’s security update include Microsoft Office, Window...

