Subscribe via feed.
Archive for September, 2015

Anchor CMS 0.9.2 Cross Site Scripting / Open Redirect

Posted by deepcore under exploit (No Respond)

Anchor CMS version 0.9.2 suffers from cross site scripting and open redirect vulnerabilities.

Kirby CMS 2.1.0 CSRF / Shell Upload

Posted by deepcore under exploit (No Respond)

Kirby CMS versions 2.1.0 and below suffer from cross site request forgery and remote shell upload vulnerabilities.

ZeusCart 4.0 Code Execution

Posted by deepcore under exploit (No Respond)

ZeusCart version 4.0 suffers from a remote code execution vulnerability.

Kirby CMS 2.1.0 Authentication Bypass / Traversal

Posted by deepcore under exploit (No Respond)

Kirby CMS versions 2.1.0 and below suffer from an authentication bypass vulnerability via path traversal.

Zen Cart 1.5.4 Code Execution / Information Disclosure

Posted by deepcore under exploit (No Respond)

Zen Cart version 1.5.4 suffers from code execution and information leakage vulnerabilities.

.NET MVC Denial Of Service

Posted by deepcore under exploit (No Respond)

Microsoft released a security bulletin (MS15-101) describing a .NET MVC denial of service vulnerability. This post analyzes the vulnerability in detail, starting from the theory and then providing a PoC exploit against a MVC web application developed with Visual Studio 2013.

MS15-078 Microsoft Windows Font Driver Buffer Overflow

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a pool based buffer overflow in the atmfd.dll driver when parsing a malformed font. The vulnerability was exploited by the hacking team and disclosed on the july data leak. This Metasploit module has been tested successfully on vulnerable builds of Windows 8.1 x64.

ManageEngine OpManager Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a default credential vulnerability in ManageEngine OpManager, where a default hidden account “IntegrationUser” with administrator privileges exists. The account has a default password of “plugin” which can not be reset through the user interface. By log-in and abusing the default administrator’s SQL query functionality, it’s possible to write a WAR payload […]

[dos] – Wireshark 1.12.7 – Division by Zero Crash PoC

Posted by deepcore under Security (No Respond)

Wireshark 1.12.7 – Division by Zero Crash PoC

Tags: ,

[webapps] – Pligg CMS 2.0.2 – (load_data_for_search.php) SQL Injection

Posted by deepcore under Security (No Respond)

Pligg CMS 2.0.2 – (load_data_for_search.php) SQL Injection

Tags: ,