Subscribe via feed.
Archive for April, 2016

PCMAN FTP Server 2.0.7 Buffer Overflow

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a buffer overflow vulnerability found in the PUT command of the PCMAN FTP server version 2.0.7. This requires authentication but by default anonymous credentials are enabled.

Easy File Sharing HTTP Server 7.2 SEH Overflow

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a SEH overflow in the Easy File Sharing FTP server version 7.2.

Bitcoin/Altcoin Stratum Pool Mass Duplicate Shares

Posted by deepcore under exploit (No Respond)

This particular vulnerability makes it possible to force a Stratum Mining Pool to accept “invalid” shares by the thousands for each mining pool round. It is possible to make pure money from this vulnerability. The exploit is real but affects only a fraction of Stratum Mining Pools.

PQI Air Pen Express CSRF / XSS / Insecure Direct Object Reference

Posted by deepcore under exploit (No Respond)

PQI Air Pen Express router versions 6W51-0000R2 and 6W51-0000R2XXX suffer from cross site request forgery, cross site scripting, and various other vulnerabilities.

Cacti 0.8.8g SQL Injection

Posted by deepcore under exploit (No Respond)

Cacti versions 0.8.8g and below remote SQL injection exploit.

DotCMS 3.3 SQL Injection

Posted by deepcore under exploit (No Respond)

DotCMS version 3.3 suffers from a remote SQL injection vulnerability.

Hexchat IRC Client 2.11.0 Directory Traversal

Posted by deepcore under exploit (No Respond)

Hexchat IRC client version 2.11.0 suffers from a directory traversal vulnerability.

Hexchat IRC Client 2.11.0 CAP LS Handling Buffer Overflow

Posted by deepcore under exploit (No Respond)

Hexchat IRC client version 2.11.0 suffers from a stack buffer overflow vulnerability.

Quanta LTE Router Code Execution / Backdoor Accounts

Posted by deepcore under exploit (No Respond)

Quanta LTE routers suffer from backdoor accounts, remote code execution, weak WPS functionality, arbitrary file reading, and a ridiculous amount of other vulnerabilities.

MeshCMS 3.6 Remote Command Execution

Posted by deepcore under exploit (No Respond)

MeshCMS version 3.6 suffers from a remote command execution vulnerability.