Subscribe via feed.
Archive for July, 2016

Compal CH7465LG-LC Modem / Router Session Management / Command Injection

Posted by deepcore under exploit (No Respond)

The Compal CH7465LG-LC suffers session management, denial of service, unauthenticated configuration changes, and command injection vulnerabilities. Proof of concept included.

PHP 7.0.8 / 5.6.23 / 5.5.37 bzread() OOB Write

Posted by deepcore under exploit (No Respond)

PHP versions 7.0.8, 5.6.23, and 5.5.37 suffers from an out-of-bounds write vulnerability in bzread().

WordPress Paid Memberships Pro 1.8.9.3 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

WordPress Paid Memberships Pro plugin version 1.8.9.3 suffers from a cross site scripting vulnerability.

WordPress WooCommerce 2.6.2 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

WordPress WooCommerce plugin version 2.6.2 suffers from a cross site scripting vulnerability.

Technicolor TC7200 Modem / Router Session Management / Fixed Password

Posted by deepcore under exploit (No Respond)

The Technicolor TC7200 suffers from session management issues and also uses a fixed password for backup file encryption. Proof of concept code included.

UPC Hungary Administrative Password / Insecure Transit

Posted by deepcore under exploit (No Respond)

UPC Hungary devices have the same administrative password for all devices, send it insecurely over the wire, and also use telnetd by default.

Drupal RESTWS Module Remote PHP Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a Remote PHP Code Execution vulnerability in Drupal RESTWS Module. Unauthenticated users can execute arbitrary code under the context of the web server user. RESTWS alters the default page callbacks for entities to provide additional functionality. A vulnerability in this approach allows an unauthenticated attacker to send specially crafted requests resulting […]

http://www.bupholocal.go.th

Posted by deepcore under defacement (No Respond)

http://www.bupholocal.go.th notified by by_dadaş

Tags:

http://wangnuea.go.th/img/

Posted by deepcore under defacement (No Respond)

http://wangnuea.go.th/img/ notified by AR3S

Tags:

[papers] – Novel contributions to the field – How I broke MySQL's codebase

Posted by deepcore under Security (No Respond)

Novel contributions to the field – How I broke MySQL’s codebase

Tags: ,