Subscribe via feed.
Archive for February, 2016

Microsoft Windows WebDAV BSoD Proof Of Concept

Posted by deepcore under exploit (No Respond)

Microsoft Windows WebDAV blue screen of death denial of service proof of concept exploit that leverages the vulnerability outlined in MS16-016.

SIMOGEO FileManager 2.3.0 Path Traversal

Posted by deepcore under exploit (No Respond)

SIMOGEO FileManager version 2.3.0 suffers from a path traversal vulnerability.

Gongwalker API Manager 1.1 Blind SQL Injection

Posted by deepcore under exploit (No Respond)

Gongwalker API Manager version 1.1 suffers from a remote blind SQL injection vulnerability.

WordPress Duplicator 1.1.0 / 1.2.0 Cross Site Request Forgery

Posted by deepcore under exploit (No Respond)

WordPress Duplicator plugin versions 1.1.0 and 1.2.0 suffers from a cross site request forgery vulnerability.

Adobe Photoshop CC 16.1.1 / Bridge CC 6.1.1 Memory Corruption

Posted by deepcore under exploit (No Respond)

Adobe Photoshop CC versions 16.1.1 (2015.1.1) and below and Bridge CC versions 6.1.1 and below suffer from multiple memory corruption vulnerabilities. Proof of concept files included.

Investors Application – Client Side Cross Site Vulnerability

Posted by deepcore under exploit (No Respond)

The Vulnerability Laboratory Research Team discovered a client-side cross site scripting web vulnerability in the official Shareholder Investor Relations web-application. (2015-Q2)

Getdpd Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Getdpd suffers from cross site scripting vulnerability.

MyScript Memo 3.0 Persistent Script Insertion

Posted by deepcore under exploit (No Respond)

MyScript Memo version 3.0 suffers from a persistent script insertion vulnerability.

File Sharing Manager 1.0 Local File Inclusion / File Upload

Posted by deepcore under exploit (No Respond)

File Sharing Manager version 1.0 suffers from local file inclusion and remote file upload vulnerabilities.

Apache Sling Framework 2.3.6 Information Disclosure

Posted by deepcore under exploit (No Respond)

Apache Sling Framework version 2.3.6 suffers from an information disclosure vulnerability.