Subscribe via feed.
Archive for March, 2016

AppLocker Execution Prevention Bypass

Posted by deepcore under exploit (No Respond)

This Metasploit module will generate a .NET service executable on the target and utilise InstallUtil to run the payload bypassing the AppLocker protection. Currently only the InstallUtil method is provided, but future methods can be added easily.

WordPress Bulk Delete 5.5.3 Privilege Escalation

Posted by deepcore under exploit (No Respond)

WordPress Bulk Delete plugin version 5.5.3 suffers from a privilege escalation vulnerability.

PHPNuke (Mod_weblink) – SQL Injection Vulnerability

Posted by deepcore under exploit (No Respond)

An independent vulnerability laboratory researcher discovered a remote sql injection vulnerability in the official persian PHPNuke Mod_weblink web extension.

AVG Threat Labs – Cross Site Request Forgery Vulnerability

Posted by deepcore under exploit (No Respond)

An independent vulnerability laboratory researcher discovered a cross site request forgery web vulnerability in the official AVG Threat Labs web-application.

[local] – AppLocker Execution Prevention Bypass

Posted by deepcore under Security (No Respond)

AppLocker Execution Prevention Bypass

Tags: ,

[webapps] – WordPress Bulk Delete Plugin 5.5.3 – Privilege Escalation

Posted by deepcore under Security (No Respond)

WordPress Bulk Delete Plugin 5.5.3 – Privilege Escalation

Tags: ,

[remote] – Schneider Electric SBO / AS – Multiple Vulnerabilities

Posted by deepcore under Security (No Respond)

Schneider Electric SBO / AS – Multiple Vulnerabilities

Tags: ,

Telecom Charging Panel ADSL (IR) – CSRF Web Vulnerability

Posted by deepcore under exploit (No Respond)

An independent vulnerability laboratory researcher discovered a client-side cross site request forgery vulnerability in the Iran Telecom Charging Panel ADSL.

Adobe (Edex) – CS Cross Site & Redirect Vulnerability

Posted by deepcore under exploit (No Respond)

An independent vulnerability laboratory researcher discovered a client-side url redirect and cross site scripting web vulnerability in the official Adobe (Edex) web-application.

Packet Storm New Exploits For February, 2016

Posted by deepcore under exploit (No Respond)

This archive contains all of the 240 exploits added to Packet Storm in February, 2016.