Subscribe via feed.
Archive for October, 2015

Pligg CMS 2.0.2 CSRF / Code Execution

Posted by deepcore under exploit (No Respond)

Pligg CMS version 2.0.2 suffers from code execution and cross site request forgery vulnerabilities.

Pligg CMS 2.0.2 Directory Traversal

Posted by deepcore under exploit (No Respond)

Pligg CMS version 2.0.2 suffers from a directory traversal vulnerability.

Pligg CMS 2.0.2 SQL Injection

Posted by deepcore under exploit (No Respond)

Pligg CMS version 2.0.2 suffers from multiple remote SQL injection vulnerabilities.

eBay Magento XXE Injection

Posted by deepcore under exploit (No Respond)

eBay Magento CE versions 1.9.2.1 and below and eBay Magento EE versions 1.14.2.1 and below suffer from an XXE injection vulnerability.

PHP Server Monitor 3.1.1 Cross Site Request Forgery

Posted by deepcore under exploit (No Respond)

PHP Server Monitor version 3.1.1 suffers from a cross site request forgery vulnerability.

PHP Server Monitor 3.1.1 Privilege Escalation

Posted by deepcore under exploit (No Respond)

PHP Server Monitor version 3.1.1 suffers from a privilege escalation vulnerability.

Mozilla SETUP.EXE DLL Injection

Posted by deepcore under exploit (No Respond)

Mozilla’s SETUP.exe suffers from a classic DLL injection vulnerability.

Joomla JNews SQL Injection

Posted by deepcore under exploit (No Respond)

The Joomla JNews component suffers from a remote SQL injection vulnerability.

Oxwall 1.7.4 Cross Site Request Forgery

Posted by deepcore under exploit (No Respond)

Oxwall version 1.7.4 suffers from a cross site request forgery vulnerability.

Libstagefright Integer Overflow Check Bypass

Posted by deepcore under exploit (No Respond)

Libstagefright integer overflow checks can be bypassed with extended chunk lengths.