Subscribe via feed.
Archive for January, 2016

Linux Kernel overlayfs Local Privilege Escalation

Posted by deepcore under exploit (No Respond)

This program demonstrates how to escalate privileges using an overlayfs mount within a user namespace.

Amanda 3.3.1 Local Root Privilege Escalation

Posted by deepcore under exploit (No Respond)

Amanda version 3.3.1 suffers from a local root privilege escalation vulnerability via the setuid runtar binary.

TrendMicro Node.js HTTP Server Command Execution

Posted by deepcore under exploit (No Respond)

When you install TrendMicro Antivirus on Windows, by default a component called Password Manager is also installed and automatically launched on startup. This product is primarily written in JavaScript with node.js, and opens multiple HTTP RPC ports for handling API requests. It took about 30 seconds to spot one that permits arbitrary command execution, openUrlInDefaultBrowser, […]

[dos] – SNScan 1.05 – Scan Hostname/IP Field Buffer Overflow Crash PoC

Posted by deepcore under Security (No Respond)

SNScan 1.05 – Scan Hostname/IP Field Buffer Overflow Crash PoC

Tags: ,

[remote] – Konica Minolta FTP Utility 1.00 – CWD Command SEH Overflow

Posted by deepcore under Security (No Respond)

Konica Minolta FTP Utility 1.00 – CWD Command SEH Overflow

Tags: ,

KeePass Password Safe Classic 1.29 Buffer Overflow

Posted by deepcore under exploit (No Respond)

KeePass Password Safe Classic version 1.29 suffers from a denial of service vulnerability.

Dolibarr 3.8.3 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Dolibarr version 3.8.3 suffers from a stored cross site scripting vulnerability.

Dream Gallery 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Dream Gallery version 1.0 suffers from a remote SQL injection vulnerability.

OpenBravo Hibernate HQL Injection

Posted by deepcore under exploit (No Respond)

OpenBravo Hibernate suffers from a remote HQL injection vulnerability. Vendor has patched this in versions 3.0PR15Q3.4 and 3.0PR15Q4.1.

Netgear 1.0.0.24 Cross Site Request Forgery

Posted by deepcore under exploit (No Respond)

Netgear router version 1.0.0.24 with JNR1010 firmware suffers from a cross site request forgery vulnerability.