Subscribe via feed.
Archive for August, 2016

Lepton CMS 2.2.0 / 2.2.1 Directory Traversal

Posted by deepcore under exploit (No Respond)

Lepton CMS versions 2.2.0 and 2.2.1 suffer from a directory traversal vulnerability.

SAP ABAP BASIS 7.4 Hard-Coded Password

Posted by deepcore under exploit (No Respond)

SAP ABAP BASIS version 7.4 suffers from a hard-coded password vulnerability.

Lepton CMS 2.2.0 / 2.2.1 PHP Code Injection

Posted by deepcore under exploit (No Respond)

Lepton CMS versions 2.2.0 and 2.2.1 suffer from a PHP code injection vulnerability.

Microsoft Office Word 2013 / 2016 Denial Of Service

Posted by deepcore under exploit (No Respond)

Microsoft Office Word 2013 and 2016 suffer from a sprmSdyaTop denial of service vulnerability as described in MS16-099.

GitLab Impersonate Privilege Escalation

Posted by deepcore under exploit (No Respond)

GitLab suffers from a privilege escalation vulnerability via the impersonate feature. Versions 8.2.0 through 8.2.4, 8.3.0 through 8.3.8, 8.4.0 through 8.4.9, 8.5.0 through 8.5.11, 8.6.0 through 8.6.7, and 8.7.0 are affected.

Pi-Hole 2.8.1 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Pi-Hole version 2.8.1 with web interface version 1.3 suffers from a persistent cross site scripting vulnerability.

[dos] – Microsoft GDI+ – ValidateBitmapInfo Invalid Pointer Arithmetic Out-of-Bounds Reads (MS16-097)

Posted by deepcore under Security (No Respond)

Microsoft GDI+ – ValidateBitmapInfo Invalid Pointer Arithmetic Out-of-Bounds Reads (MS16-097)

Tags: ,

[dos] – Microsoft GDI+ – DecodeCompressedRLEBitmap Invalid Pointer Arithmetic Out-of-Bounds Write (MS16-097)

Posted by deepcore under Security (No Respond)

Microsoft GDI+ – DecodeCompressedRLEBitmap Invalid Pointer Arithmetic Out-of-Bounds Write (MS16-097)

Tags: ,

[webapps] – SIEMENS IP-Camera CVMS2025-IR, CCMS2025 – Credentials Disclosure

Posted by deepcore under Security (No Respond)

SIEMENS IP-Camera CVMS2025-IR, CCMS2025 – Credentials Disclosure

Tags: ,

ISPconfig v3.0.5.4 p6 – UI Exception & XSS Vulnerability

Posted by deepcore under exploit (No Respond)

No abstract description available in the upcomings!