Subscribe via feed.
Archive for January, 2016

[webapps] – Glassfish Server – Arbitrary File Read Vulnerability

Posted by deepcore under Security (No Respond)

Glassfish Server – Arbitrary File Read Vulnerability

Tags: ,

WebMartIndia CMS 2016 Q1 – SQL Injection Vulnerability

Posted by deepcore under exploit (No Respond)

An independent vulnerability laboratory research group discovered a sql injection web vulnerability in the official WebMartIndia Content Management System (2016-Q1).

smod Modbus Assessment Framework 1.0.1

Posted by deepcore under Apple (No Respond)

smod is a modular framework with every kind of diagnostic and offensive feature you could need in order to pentest the modbus protocol. It is a full modbus protocol implementation using Python and Scapy. This software can be run on Linux/OSX under python 2.7.x.

Tags: , ,

XMB – eXtreme Message Board 1.9.11.13 Weak Crypto / Insecure Password Storage

Posted by deepcore under exploit (No Respond)

XMB – eXtreme Message Board version 1.9.11.13 suffers from weak crypto and insecure password storage vulnerabilities.

ZyXel WAP3205 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

ZyXel WAP3205 suffers from multiple cross site scripting vulnerabilities.

Buffalo NAS Remote Shutdown

Posted by deepcore under exploit (No Respond)

Buffalo NAS devices suffer from a remote shutdown / denial of service vulnerability.

FreeBSD SCTP ICMPv6 Denial Of Service

Posted by deepcore under exploit (No Respond)

FreeBSD suffers from an SCTP ICMPv6 error processing denial of service vulnerability.

Linux Kernel prima WLAN Driver Heap Overflow

Posted by deepcore under exploit (No Respond)

The Linux prima WLAN driver suffers from a heap overflow vulnerability.

pfSense Firewall 2.2.5 Cross Site Request Forgery

Posted by deepcore under exploit (No Respond)

pfSense Firewall version 2.2.5 cross site request forgery exploit.

Android ADB Debug Server Remote Payload Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module writes and spawns a native payload on an android device that is listening for adb debug messages.