Subscribe via feed.
Archive for April, 2016

WPN-XM 0.8.6 Cross Site Request Forgery

Posted by deepcore under exploit (No Respond)

WPN-XM version 0.8.6 suffers from a cross site request forgery vulnerability.

OpenCart 2.2.0.0 Remote PHP Code Execution

Posted by deepcore under exploit (No Respond)

OpenCart version 2.2.0.0 suffers from a remote PHP code execution vulnerability.

CAM UnZip 5.1 Path Traversal / Code Execution

Posted by deepcore under exploit (No Respond)

CAM UnZip version 5.1 suffers from a path traversal vulnerability that allows for code execution.

Novell Service Desk 7.1.0 Code Execution / Information Disclosure

Posted by deepcore under exploit (No Respond)

Novell Service Desk versions 7.1.0 and below suffer from code execution, information disclosure, cross site scripting, remote file upload, HQL injection, and traversal vulnerabilities.

Perl 5.22 VDir::MapPathA/W Out-Of-Bounds Reads / Buffer Over-Reads

Posted by deepcore under exploit (No Respond)

Perl version 5.22 suffers from two out-of-bounds reads and multiple small buffer over-read vulnerabilities in the VDir::MapPathA and VDir::MapPathW functions that could potentially be exploited to achieve arbitrary code execution.

WordPress Robo Gallery 2.0.14 Code Execution

Posted by deepcore under exploit (No Respond)

WordPress Robo Gallery plugin version 2.0.14 suffers from a code execution vulnerability.

RockMongo 1.1.8 Cross Site Request Forgery / Cross Site Scripting

Posted by deepcore under exploit (No Respond)

RockMongo version 1.1.8 suffers from cross site request forgery, cross site scripting, and html injection vulnerabilities.

IBM Java Issue 70 Bad Patch

Posted by deepcore under exploit (No Respond)

The patch for Issue 70 in IBM Java discovered by Security Explorations in 2013 was found to be faulty. Included are the full report and a proof of concept.

ImPAX Agility 1.1074.RC.b122.20150602 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

ImPAX Agility version 1.1074.RC.b122.20150602 suffers from multiple cross site scripting vulnerabilities.

Ovidentia Troubletickets 7.6 Remote File Inclusion

Posted by deepcore under exploit (No Respond)

Ovidentia module Troubletickets version 7.6 suffers from a remote file inclusion vulnerability.