Subscribe via feed.
Archive for February, 2016

Wieland wieplan 4.1 Document Parsing Java Code Execution Using XMLDecoder

Posted by deepcore under exploit (No Respond)

Wieland wieplan version 4.1 suffers from an arbitrary java code execution when parsing WIE documents that uses XMLDecoder, allowing system access to the affected machine. The software is used to generate custom specification order saved in .wie XML file that has to be sent to the vendor offices to be processed.

[webapps] – Oracle GlassFish Server <= 4.1 – Directory Traversal

Posted by deepcore under Security (No Respond)

Oracle GlassFish Server <= 4.1 – Directory Traversal

Tags: ,

HD Video Player v2.5 iOS – Multiple Web Vulnerabilities

Posted by deepcore under exploit (No Respond)

The Vulnerability Laboratory Core Research Team discovered multiple web vulnerabilities in the HD Video Player v2.5 iOS mobile web-application (wifi).

ManageEngine Network Configuration Management Build 11000 Privilege Escalation

Posted by deepcore under exploit (No Respond)

ManageEngine Network Configuration Management build version 11000 suffers from a privilege escalation vulnerability.

Joomla Subcategory 1.2.15 SQL Injection

Posted by deepcore under exploit (No Respond)

Joomla Subcategory component version 1.2.15 suffers from a remote SQL injection vulnerability.

Joomla Scatalog 2.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Joomla Scatalog component version 2.0 suffers from a remote SQL injection vulnerability.

D-Link DCS-930L Authenticated Remote Command Execution

Posted by deepcore under exploit (No Respond)

The D-Link DCS-930L Network Video Camera is vulnerable to OS Command Injection via the web interface. The vulnerability exists at /setSystemCommand, which is accessible with credentials. This vulnerability was present in firmware version 2.01 and fixed by 2.12.

[remote] – File Replication Pro <= 7.2.0 – Multiple Vulnerabilities

Posted by deepcore under Security (No Respond)

File Replication Pro <= 7.2.0 – Multiple Vulnerabilities

Tags: ,

[papers] – NDI5aster – Privilege Escalation through NDIS 5.x Filter Intermediate Drivers

Posted by deepcore under Security (No Respond)

NDI5aster – Privilege Escalation through NDIS 5.x Filter Intermediate Drivers

Tags: ,

MyScript Memo v3.0 iOS – (Mail) Persistent Vulnerability

Posted by deepcore under exploit (No Respond)

The Vulnerability Laboratory Core Research Team discovered a persistent mail encoding web vulnerability in the official MyScript Memo iOS mobile web-application.