Subscribe via feed.
Archive for May, 2016

[local] – Multiples Nexon Games – Unquoted Path Privilege Escalation

Posted by deepcore under Security (No Respond)

Multiples Nexon Games – Unquoted Path Privilege Escalation

Tags: ,

[webapps] – eXtplorer 2.1.9 – Archive Path Traversal

Posted by deepcore under Security (No Respond)

eXtplorer 2.1.9 – Archive Path Traversal

Tags: ,

NRSS News Reader 0.3.9-1 Stack Buffer Overflow

Posted by deepcore under exploit (No Respond)

NRSS News Reader version 0.3.9-1 suffers from a buffer overflow vulnerability which allows local attackers to obtain privileged access when exploited.

runAV mod_security Remote Command Execution

Posted by deepcore under exploit (No Respond)

runAV with mod_security suffers from a command injection vulnerability that leads to privilege escalation providing the clamscan binary is setuid.

CakePHP Framework 3.2.4 IP Spoofing

Posted by deepcore under exploit (No Respond)

CakePHP Framework versions 3.2.4 and below suffer from a vulnerability that allows users to spoof the source IP address logged by the server.

eXtplorer 2.1.9 Path Traversal

Posted by deepcore under exploit (No Respond)

eXtplorer version 2.1.9 suffers from a traversal vulnerability.

JVC XSS / CSRF / Header Injection / Weak Credentials

Posted by deepcore under exploit (No Respond)

Various JVC products suffer from having weak and poorly protected credentials, cross site request forgery, cross site scripting, header injection, and information disclosure vulnerabilities.

Aruba Authentication Bypass / Insecure Transport / Tons Of Issues

Posted by deepcore under exploit (No Respond)

Multiple vulnerabilities were identified in Aruba AP, IAP and AMP devices. The vulnerabilities were discovered during a black box security assessment and therefore the vulnerability list should not be considered exhaustive. Several of the high severity vulnerabilities listed in this report are related to the Aruba proprietary PAPI protocol and allow remote compromise of affected […]

Ajaxel CMS 8.0 XSS / CSRF / File Disclosure / SQL Injection

Posted by deepcore under exploit (No Respond)

Ajaxel CMS version 8.0 suffers from cross site request forgery, cross site scripting, file disclosure, and remote SQL injection vulnerabilities.

PHPWebFTP 3.3b Cross Site Scripting

Posted by deepcore under exploit (No Respond)

PHPWebFTP version 3.3b suffers from cross site scripting vulnerabilities.