Subscribe via feed.
Archive for September, 2015

VuFind 1.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

VuFind version 1.0 suffers from a cross site scripting vulnerability.

Good Technology Authentication Insecure Coupling

Posted by deepcore under exploit (No Respond)

The Good Mobile Device Management solution suffers from an insecure application-coupling vulnerability.

WinRaR SFX Remote Code Execution

Posted by deepcore under exploit (No Respond)

WinRaR SFX remote code execution exploit that just requires a malicious file to get loaded.

X2Engine 4.2 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

X2Engine version 4.2 suffers from multiple cross site scripting vulnerabilities.

X2Engine 4.2 Arbitrary File Upload

Posted by deepcore under exploit (No Respond)

X2Engine version 4.2 suffers from a remote arbitrary file upload vulnerability.

X2Engine 4.2 Cross Site Request Forgery

Posted by deepcore under exploit (No Respond)

X2Engine version 4.2 suffers from cross site request forgery vulnerabilities.

Watchguard XCS FixCorruptMail Local Privilege Escalation

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a vulnerability in the Watchguard XCS ‘FixCorruptMail’ script called by root’s crontab which can be exploited to run a command as root within 3 minutes.

Watchguard XCS Remote Command Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits two separate vulnerabilities found in the Watchguard XCS virtual appliance to gain command execution. By exploiting an unauthenticated SQL injection, a remote attacker may insert a valid web user into the appliance database, and get access to the web interface. On the other hand, a vulnerability in the web interface allows […]

Flowdock API Script Insertion

Posted by deepcore under exploit (No Respond)

Flowdock API suffered from a script insertion vulnerability.

Unified Layer Shell Upload

Posted by deepcore under exploit (No Respond)

Due to a server misconfiguration, customers of Unified Layer suffer from a remote shell upload vulnerability.