Subscribe via feed.
Archive for June, 2016

JIRA Artezio Board 1.4 Cross Site Scripting / Information Disclosure

Posted by deepcore under exploit (No Respond)

JIRA Artezio Board plugin version 1.4 suffers from cross site scripting and information disclosure vulnerabilities.

ASUS DSL-N55U 3.0.0.4.376_2736 XSS / Information Disclosure

Posted by deepcore under exploit (No Respond)

ASUS DSL-N55U version 3.0.0.4.376_2736 suffers from cross site scripting and information disclosure vulnerabilities.

Parsijoo Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Parsijoo Search Engine suffers from a cross site scripting vulnerability.

Option CloudGate Insecure Direct Object Reference Auth Bypass

Posted by deepcore under exploit (No Respond)

The CloudGate M2M gateway from Option suffers from an insecure direct object reference that allows for authorization bypass as well as cross site scripting vulnerabilities.

iBilling 3.7.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

iBilling version 3.7.0 suffers from multiple stored and reflective cross site scripting vulnerabilities.

Riverbed SteelCentral NetProfiler / NetExpress 10.8.7 XSS / Code Execution

Posted by deepcore under exploit (No Respond)

Riverbed SteelCentral NetProfiler and NetExpress versions 10.8.7 and below suffer from command injection, privilege escalation, local file inclusion, account hijacking, and remote SQL injection vulnerabilities.

Untangle NGFW 12.1.0 Beta execEvil() Command Injection

Posted by deepcore under exploit (No Respond)

Untangle NGFW versions 12.1.0 Beta and below execEvil() authentication root command injection exploit.

Kagao 3.0 Cross Site Scripting / SQL Injection

Posted by deepcore under exploit (No Respond)

Kagao version 3.0 suffers from cross site scripting and remote SQL injection vulnerabilities.

Windows NtCreateProcessEx NULL Pointer Dereference

Posted by deepcore under exploit (No Respond)

PspInitializeFullProcessImageName does not correctly handle a NULL pointer being passed to it leading to a dereference at NULL for a file object which might be exploitable on 32 bit systems for elevation of privilege.

Armadito Arbitrary File Write / Man-In-The-Middle

Posted by deepcore under exploit (No Respond)

Armadito suffers from a remote arbitrary file write due to a man-in-the-middle issue.