Subscribe via feed.
Archive for April, 2016

AccelSite Content Manager 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

AccelSite Content Manager version 1.0 suffers from a remote SQL injection vulnerability.

Hikvision Digital Video Recorder Cross Site Request Forgery

Posted by deepcore under exploit (No Respond)

Hikvision Digital Video Recorder versions LV-D2104CS, DS-7316HFI-ST, DS-7216HVI-SV/A, DS-7208HVI-SH, and DS-7204HVI-SH suffer from a cross site request forgery vulnerability.

Android IMemory Native Interface Insecure IPC Use

Posted by deepcore under exploit (No Respond)

The IMemory interface in frameworks/native/libs/binder/IMemory.cpp, used primarily by the media services can be tricked to return arbitrary memory locations leading to information disclosure or memory corruption.

Android IOMX getConfig/getParameter Information Disclosure

Posted by deepcore under exploit (No Respond)

The GET_CONFIG and GET_PARAMETER calls on IOMX are vulnerable to an information disclosure of uninitialized heap memory. This could be used by an attacker to break ASLR in the media server process by reading out heap memory which contains useful address information.

PostgreSQL CREATE LANGUAGE Execution

Posted by deepcore under exploit (No Respond)

Some installations of Postgres 8 and 9 are configured to allow loading external scripting languages. Most commonly this is Perl and Python. When enabled, command execution is possible on the host. To execute system commands, loading the “untrusted” version of the language is necessary. This requires a superuser. This is usually postgres. The execution should […]

ExaGrid Known SSH Key / Default Password

Posted by deepcore under exploit (No Respond)

ExaGrid ships a public/private key pair on their backup appliances to allow passwordless authentication to other ExaGrid appliances. Since the private key is easily retrievable, an attacker can use it to gain unauthorized remote access as root. Additionally, this module will attempt to use the default password for root, ‘inflection’.

http://md-nakhonphanom.go.th/x.txt

Posted by deepcore under Security (No Respond)

http://md-nakhonphanom.go.th/x.txt notified by PaYwand_Defacer

Tags:

http://www.phatthalung.m-society.go.th

Posted by deepcore under Security (No Respond)

http://www.phatthalung.m-society.go.th notified by جبهة التحرير

Tags:

http://www.taladpho.go.th/taladpho/mainfile/x.html

Posted by deepcore under Security (No Respond)

http://www.taladpho.go.th/taladpho/mainfile/x.html notified by Code Breaker

Tags:

http://nikhompattana.go.th/nikhompattana/mainfile/x.html

Posted by deepcore under Security (No Respond)

http://nikhompattana.go.th/nikhompattana/mainfile/x.html notified by Code Breaker

Tags: