Subscribe via feed.
Archive for April, 2016

Totemomail 4.x / 5.x Script Insertion

Posted by deepcore under exploit (No Respond)

Totemomail versions 4.x and 5.x suffer from filter bypass and script insertion vulnerabilities.

Cyberoam Central Console 02.03.1 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Cyberoam Central Console version 02.03.1 suffers from cross site scripting vulnerabilities.

CompuSource Systems Local Privilege Escalation

Posted by deepcore under exploit (No Respond)

CompuSource Systems Real Time Home Banking suffers from a local privilege escalation vulnerability.

i-Tech Nepal Radio CMS 2.0 SQL Injection

Posted by deepcore under exploit (No Respond)

i-Tech Nepal Radio CMS version 2.0 suffers from a remote SQL injection vulnerability.

IrIran Shopping Script 4.1 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

IrIran Shopping Script version 4.1 suffers from a cross site scripting vulnerability.

NationBuilder Cross Site Scripting

Posted by deepcore under exploit (No Respond)

NationBuilder suffers from multiple persistent cross site scripting vulnerabilities.

Yasr 0.6.9-5 Buffer Overflow

Posted by deepcore under exploit (No Respond)

Yasr console screen reader version 0.6.9-5 proof of concept buffer overflow exploit.

Gemtek CPE7000 WLTCS-106 Administrator SID Retriever

Posted by deepcore under exploit (No Respond)

A vulnerability exists for Gemtek CPE7000 model ID WLTCS-106 which allows unauthenticated remote attackers to retrieve a valid Administrative SID.

Gemtek CPE7000 WLTCS-106 sysconf.cgi Remote Command Execution

Posted by deepcore under exploit (No Respond)

A vulnerability exists for Gemtek CPE7000 model ID WLTCS-106 exposing Iperf tool to unauthenticated users. Injecting a command in the perf_measure_server_ip parameter, an attacker can execute arbitrary commands. Since the service runs as root, the remote command execution has the same administrative privileges. The remote shell is obtained uploading the payload and executing it. A […]

http://chiangkiean.go.th/king.htm

Posted by deepcore under Security (No Respond)

http://chiangkiean.go.th/king.htm notified by RxR

Tags: