Subscribe via feed.
Archive for June, 2016

Vicidial 1.4.0.20 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Vicidial version 1.4.0.20 suffers from a reflective cross site scripting vulnerability.

http://lamphun.drr.go.th/index.htm

Posted by deepcore under Security (No Respond)

http://lamphun.drr.go.th/index.htm notified by Fallaga team

Tags:

http://mec.drr.go.th/index.htm

Posted by deepcore under Security (No Respond)

http://mec.drr.go.th/index.htm notified by Fallaga team

Tags:

http://video.drr.go.th/index.htm

Posted by deepcore under Security (No Respond)

http://video.drr.go.th/index.htm notified by Fallaga team

Tags:

http://trafficsafety.drr.go.th/index.htm

Posted by deepcore under Security (No Respond)

http://trafficsafety.drr.go.th/index.htm notified by Fallaga team

Tags:

FortiAnalyzer & FortiManager – CS Cross Site Vulnerability

Posted by deepcore under exploit (No Respond)

The Vulnerability Laboratory Core Research Team discovered a non-persistent web validation vulnerability in the official Fotinet FortiManager & Fortianalyzer appliance product series.

[webapps] – Tiki-Wiki CMS Calendar 14.2, 12.5 LTS, 9.11 LTS, and 6.15 – Remote Code Execution

Posted by deepcore under Security (No Respond)

Tiki-Wiki CMS Calendar 14.2, 12.5 LTS, 9.11 LTS, and 6.15 – Remote Code Execution

Tags: ,

[shellcode] – Linux x86_64 Shellcode Null-Free Reverse TCP Shell

Posted by deepcore under Security (No Respond)

Linux x86_64 Shellcode Null-Free Reverse TCP Shell

Tags: ,

[webapps] – SlimCMS 0.1 – CSRF (Change Admin Password)

Posted by deepcore under Security (No Respond)

SlimCMS 0.1 – CSRF (Change Admin Password)

Tags: ,

[webapps] – ATCOM PBX IP01, IP08 , IP4G, IP2G4A – Authentication Bypass

Posted by deepcore under Security (No Respond)

ATCOM PBX IP01, IP08 , IP4G, IP2G4A – Authentication Bypass

Tags: ,