Subscribe via feed.
Archive for March, 2016

Crouzet em4 soft 1.1.04 / M3 soft 3.1.2.0 Insecure File Permissions

Posted by deepcore under exploit (No Respond)

em4 soft and M3 soft both suffer from a privilege escalation vulnerability. Executables can be changed by an authenticated user due to improper permissions.

Microsoft PowerPoint Viewer 12.0.6600.1000 DLL Hijacking

Posted by deepcore under exploit (No Respond)

Microsoft PowerPoint Viewer version 12.0.6600.1000 suffers from a DLL hijacking vulnerability.

ATutor 2.2.1 SQL Injection / Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a SQL Injection vulnerability and an authentication weakness vulnerability in ATutor. This essentially means an attacker can bypass authentication and reach the administrators interface where they can upload malicious code. You are required to login to the target to reach the SQL Injection, however this can be done as a student […]

[webapps] Gallery 2 < 2.0.2 – Multiple Vulnerabilities

Posted by deepcore under Security (No Respond)

Gallery 2 < 2.0.2 – Multiple Vulnerabilities

Tags: ,

[shellcode] – x86 Windows Null-Free Download & Run via WebDAV Shellcode (96 bytes)

Posted by deepcore under Security (No Respond)

x86 Windows Null-Free Download & Run via WebDAV Shellcode (96 bytes)

Tags: ,

[local] – Secret Net 7 and Secret Net Studio 8 – Local Privilege Escalation

Posted by deepcore under Security (No Respond)

Secret Net 7 and Secret Net Studio 8 – Local Privilege Escalation

Tags: ,

[dos] – PictureTrails Photo Editor GE.exe 2.0.0 – .bmp Crash PoC

Posted by deepcore under Security (No Respond)

PictureTrails Photo Editor GE.exe 2.0.0 – .bmp Crash PoC

Tags: ,

[dos] – Quick Tftp Server Pro 2.3 – Read Mode Denial of Service

Posted by deepcore under Security (No Respond)

Quick Tftp Server Pro 2.3 – Read Mode Denial of Service

Tags: ,

[dos] – Freeproxy Internet Suite 4.10 – Denial of Service

Posted by deepcore under Security (No Respond)

Freeproxy Internet Suite 4.10 – Denial of Service

Tags: ,

jcow v9.9.1 CE – Multiple Persistent Cross Site Vulnerabilities

Posted by deepcore under exploit (No Respond)

An independent vulnerability laboratory researcher discovered multiple application-side cross site scripting vulnerability in the jcow v9.9.1 CE web-application.