Subscribe via feed.
Archive for December, 2015

[webapps] – WordPress Users Ultra Plugin 1.5.50 – Blind SQL injection

Posted by deepcore under Security (No Respond)

Last Updated on December 3, 2015 by deepcore WordPress Users Ultra Plugin 1.5.50 – Blind SQL injection

Tags: ,

Huawei Wimax CSRF / Information Disclosure / Manipulation

Posted by deepcore under exploit (No Respond)

Last Updated on December 2, 2015 by deepcore Huawei Wimax routers suffer from cross site request forgery, information disclosure, and system manipulation vulnerabilities.

Kodi 15 Arbitrary File Access

Posted by deepcore under exploit (No Respond)

Last Updated on December 2, 2015 by deepcore Kodi 15 reintroduced an arbitrary file access vulnerability.

CentOS 7.1 / Fedora 22 abrt Local Root

Posted by deepcore under exploit (No Respond)

Last Updated on December 2, 2015 by deepcore CentOS version 7.1 and Fedora version 22 abrt local root exploit. It leverages abrt-hook-ccpp insecure open() usage and abrt-action-install-debuginfo insecure temp directory usage.

RHEL 7.0 / 7.1 abrt / sosreport Local Root

Posted by deepcore under exploit (No Respond)

Last Updated on December 2, 2015 by deepcore Local root exploit for Redhat Enterprise Linux versions 7.0 and 7.1 that leverages abrt/sosreport.

Zenphoto 1.4.10 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Last Updated on December 2, 2015 by deepcore Zenphoto version 1.4.10 suffers from a cross site scripting vulnerability.

Zenphoto 1.4.10 Local File Inclusion

Posted by deepcore under exploit (No Respond)

Last Updated on December 2, 2015 by deepcore Zenphoto version 1.4.10 suffers from a local file inclusion vulnerability.

ntop-ng 2.0.15102 Privilege Escalation

Posted by deepcore under exploit (No Respond)

Last Updated on December 2, 2015 by deepcore ntop-ng versions 2.0.151021 and below suffer from a privilege escalation vulnerability.

Advantech Switch Bash Environment Variable Code Injection

Posted by deepcore under exploit (No Respond)

Last Updated on December 2, 2015 by deepcore This Metasploit module exploits the Shellshock vulnerability, a flaw in how the Bash shell handles external environment variables. This Metasploit module targets the ‘ping.sh’ CGI script, accessible through the Boa web server on Advantech switches. This Metasploit module was tested against firmware version 1322_D1.98.

[local] – Acunetix WVS 10 – Local Privilege escalation

Posted by deepcore under Security (No Respond)

Last Updated on December 2, 2015 by deepcore Acunetix WVS 10 – Local Privilege escalation

Tags: ,