Subscribe via feed.
Archive for April, 2016

OpenWGA Content Manager 7.1.9 User-Agent HTTP Header XSS

Posted by deepcore under exploit (No Respond)

OpenWGA Content Manager version 7.1.9 suffers from a cross site scripting vulnerability when input passed via the User-Agent HTTP header is not properly sanitized before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user’s browser session in context of an affected site.

ChitaSoft CMS 3 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

ChitaSoft CMS version 3 suffers from a cross site scripting vulnerability.

Windows Kernel ATMFD.DLL NamedEscape 0x2511 Out-Of-Bounds Read

Posted by deepcore under exploit (No Respond)

The Adobe Type Manager Font Driver (ATMFD.DLL) suffers from a NamedEscape out-of-bounds read.

PHPmongoDB 1.0.0 Cross Site Request Forgery / Cross Site Scripting

Posted by deepcore under exploit (No Respond)

PHPmongoDB version 1.0.0 suffers from cross site request forgery and cross site scripting vulnerabilities.

Django CMS 3.2.3 Filter Bypass / Script Insertion

Posted by deepcore under exploit (No Respond)

Django CMS version 3.2.3 suffers from filter bypass and malicious script insertion vulnerabilities.

Brickcom Network Cameras XSS / CSRF / Insecure Direct Object Reference

Posted by deepcore under exploit (No Respond)

Brickcom Network Cameras suffer from insecure direct object reference, hard-coded credentials, information disclosure, cross site request forgery, and cross site scripting vulnerabilities.

Exim perl_startup Privilege Escalation

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a Perl injection vulnerability in Exim versions prior to 4.86.2 given the presence of the “perl_startup” configuration parameter.

http://pvlo-aty.dld.go.th

Posted by deepcore under Security (No Respond)

http://pvlo-aty.dld.go.th notified by HighTech

Tags:

[local] – Exim "perl_startup" Privilege Escalation

Posted by deepcore under Security (No Respond)

Exim “perl_startup” Privilege Escalation

Tags: ,

[dos] – Internet Explorer 11 – MSHTML!CMarkupPointer::UnEmbed Use After Free

Posted by deepcore under Security (No Respond)

Internet Explorer 11 – MSHTML!CMarkupPointer::UnEmbed Use After Free

Tags: ,