Subscribe via feed.
Archive for April, 2016

ImpressCMS 1.3.9 SQL Injection

Posted by deepcore under exploit (No Respond)

ImpressCMS versions 1.3.9 and below suffer from a remote SQL injection vulnerability.

Exponent CMS 2.3.5 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Exponent CMS version 2.3.5 suffers from multiple cross site scripting vulnerabilities.

Exponent CMS 2.3.5 File Upload Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Exponent CMS version 2.3.5 suffers from a file upload vulnerability that allows for cross site scripting.

Symantec Brightmail 10.6.0-7 LDAP Credential Grabber

Posted by deepcore under exploit (No Respond)

Symantec Brightmail versions 10.6.0-7 and below save the AD password in a place where it can be retrieved.

libgd 2.1.1 Signedness

Posted by deepcore under exploit (No Respond)

A signedness vulnerability exists in libgd version 2.1.1 which may result in a heap overflow when processing compressed gd2 data.

Gemtek CPE7000 WLTCS-106 Authentication Bypass / Code Execution

Posted by deepcore under exploit (No Respond)

Gemtek CPE7000 WLTCS-106 suffers from authentication bypass and remote code execution vulnerabilities.

phpLiteAdmin 1.9.6 Cross Site Request Forgery / Cross Site Scripting

Posted by deepcore under exploit (No Respond)

phpLiteadmin version 1.9.6 suffers from cross site request forgery and cross site scripting vulnerabilities.

Advantech WebAccess 8.0 Dashboard Viewer Arbitrary File Upload

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits an arbitrary file upload vulnerability found in Advantech WebAccess 8.0. This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Advantech WebAccess. Authentication is not required to exploit this vulnerability. The specific flaw exists within the WebAccess Dashboard Viewer. Insufficient validation within the uploadImageCommon function in the UploadAjaxAction […]

http://www.bpp44.go.th

Posted by deepcore under Security (No Respond)

http://www.bpp44.go.th notified by DZ-QTH

Tags:

http://www.phichit.m-society.go.th/ok.html

Posted by deepcore under Security (No Respond)

http://www.phichit.m-society.go.th/ok.html notified by Nofawkx Al

Tags: