Subscribe via feed.
Archive for January, 2016

WordPress Extredj Open Redirection

Posted by deepcore under exploit (No Respond)

WordPress Extredj plugin suffers from an open redirection vulnerability.

CakePHP 3.2.0 CSRF Bypass

Posted by deepcore under exploit (No Respond)

CakePHP versions 3.2.0 and below suffer from a _method cross site request forgery protection bypass vulnerability.

SeaWell Networks Spectrum SDC 02.05.00 Traversal / Privilege Escalation

Posted by deepcore under exploit (No Respond)

SeaWell Networks Spectrum SDC version 02.05.00 suffers from weak default credentials, path traversal, and privilege escalation vulnerabilities.

Samsung KNOX 1.0 Weak eCryptFS Key Generation

Posted by deepcore under exploit (No Respond)

Samsung KNOX version 1.0 suffers from a weak eCryptFS implementation.

WEG SuperDrive G2 12.0.0 Insecure File Permissions

Posted by deepcore under exploit (No Respond)

SuperDrive suffers from an elevation of privileges vulnerability which can be used by a simple authenticated user that can change the executable file with a binary of choice. The vulnerability exist due to the improper permissions, with the ‘C’ flag (Change) for ‘Authenticated Users’ group.

Advanced Electron Forum 1.0.9 Cross Site Request Forgery

Posted by deepcore under exploit (No Respond)

Advanced Electron Forum version 1.0.9 suffers from a cross site request forgery vulnerability.

Advanced Electron Forum 1.0.9 Cross Site Request Forgery / Remote File Inclusion

Posted by deepcore under exploit (No Respond)

Advanced Electron Forum version 1.0.9 suffers from cross site request forgery and remote file inclusion vulnerabilities.

Joomla Fsave 2.0 Local File Disclosure

Posted by deepcore under exploit (No Respond)

Joomla Fsave component version 2.0 suffers from a local file disclosure vulnerability.

Art Systems FluidDraw P5/S5 5.3n Binary Planting Arbitrary Code Execution

Posted by deepcore under exploit (No Respond)

FluidDraw suffers from a DLL Hijacking issue. The vulnerability is caused due to the application loading libraries (siappdll.dll) in an insecure manner. This can be exploited to load arbitrary libraries by tricking a user into opening a related application files (.PRJ, .CIRC, .CT, .DXF, .SYM) located on a remote WebDAV or SMB share.

Advanced Electron Forum 1.0.9 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Advanced Electron Forum version 1.0.9 suffers from a cross site scripting vulnerability.