Subscribe via feed.
Archive for May, 2016

Adobe Flash ATF Processing Heap Overflow

Posted by deepcore under exploit (No Respond)

Adobe Flash suffers from an image reading / ATF processing heap overflow vulnerability.

Adobe Flash MP4 File Stack Corruption

Posted by deepcore under exploit (No Respond)

A malicious mp4 file can cause stack corruption in Adobe Flash.

Adobe Flash addProperty Use-After-Free

Posted by deepcore under exploit (No Respond)

Adobe Flash suffers from a use-after-free vulnerability in addProperty.

Merit LILIN XSS / CSRF / Credential Issues

Posted by deepcore under exploit (No Respond)

Merit LILIN IP cameras suffer from cross site request forgery, cross site scripting, hard-coded credential, and various other vulnerabilities.

PLANET IP LFI / CSRF / XSS / Authentication Bypass

Posted by deepcore under exploit (No Respond)

Various PLANET IP cameras suffer from local file inclusion, arbitrary file read, information disclosure, cross site request forgery, cross site scripting, and hard-coded credential vulnerabilities.

SAP NetWeaver AS JAVA 7.4 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

SAP NetWeaver AS JAVA version 7.4 suffers from a cross site scripting vulnerability.

SAP MII 15.0 Directory Traversal

Posted by deepcore under exploit (No Respond)

SAP MII version 15.0 suffers from a directory traversal vulnerability.

TP-Link SC2020n Authenticated Telnet Injection

Posted by deepcore under exploit (No Respond)

The TP-Link SC2020n Network Video Camera is vulnerable to OS Command Injection via the web interface. By firing up the telnet daemon, it is possible to gain root on the device. The vulnerability exists at /cgi-bin/admin/servetest, which is accessible with credentials.

Hex: Shard Of Fate 1.0.1.026 Privilege Escalation

Posted by deepcore under exploit (No Respond)

Hex: Shard of Fate version 1.0.1.026 suffers from an unquoted path privilege escalation vulnerability.

Nexon Games Privilege Escalation

Posted by deepcore under exploit (No Respond)

Multiple Nexon games suffer from an unquoted path privilege escalation vulnerability.