Subscribe via feed.
Archive for April, 2016

Virtual Freer 1.58 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Virtual Freer version 1.58 suffers from a cross site scripting vulnerability.

WordPress Scoreme Theme Cross Site Scripting

Posted by deepcore under exploit (No Respond)

WordPress Scoreme theme suffers from a cross site scripting vulnerability.

WordPress Advanced Video 1.0 Local File Inclusion

Posted by deepcore under exploit (No Respond)

WordPress Advanced Video plugin version 1.0 suffers from a local file inclusion vulnerability.

Xion Audio Player 1.5 Denial Of Service

Posted by deepcore under exploit (No Respond)

Xion Audio Player versions 1.5 build 160 and below local proof of concept crash exploit.

Mautic 1.3.0 CSRF / XSS / User Enumeration / DoS

Posted by deepcore under exploit (No Respond)

Mautic version 1.3.0 suffers from cross site request forgery, denial of service, user enumeration, and cross site scripting vulnerabilities.

MSIE MSHTML!CSVGHelpers::SetAttributeStringAndPointer Use-After-Free

Posted by deepcore under exploit (No Respond)

Microsoft Internet Explorer suffers from a MSHTML!CSVGHelpers::SetAttributeStringAndPointer use-after-free vulnerability.

BugCrowd CSV Injection

Posted by deepcore under exploit (No Respond)

BugCrowd’s file upload allows for CSVs that may have malicious formulas in them.

Techsoft Web Solutions CMS 2016 Q2 SQL Injection

Posted by deepcore under exploit (No Respond)

Techsoft Web Solutions CMS version 2016 Q2 suffers from a remote SQL injection vulnerability.

FortiManager / FortiAnalyzer 5.x Script Insertion

Posted by deepcore under exploit (No Respond)

FortiManager and FortiAnalyzer version 5.x suffer from a client-side malicious script insertion vulnerability.

ManageEngine Password Manager Pro 8.3 CSRF / XSS / Escalation / Bypass

Posted by deepcore under exploit (No Respond)

ManageEngine Password Manager Pro builds 8.1 through 8.3 suffer from bypass, cross site request forgery, privilege escalation, user enumeration, and cross site scripting vulnerabilities.